The primary mode of support here is peer-to-peer, meaning users helping other users. (please remember this at all times!)
Another try:
This forum is composed of people who have used spamcop and those who are learning about anti-spam efforts.
| Farelf |
Jul 29 2008, 09:30 PM
Post
#1
|
|
T-shirt wearing out Group: Membersph Posts: 4312 Joined: 23-February 04 From: Western Australia Member No.: 491 |
For several weeks I have been seeing an increasing volume of 'news' spam with curiously mismatched subject and body - like http://www.spamcop.net/sc?id=z2108631583za...48196decd4d9b1z
"Subject: Steve Jobs' vital signs show weakening" Body "Arnold Schwarzenegger quits as Governer" The payload URLs are unrelated to either - Googling shows the single-line webpage descriptor "Watch Free Movie - Update Every Hour!". Some of these carried one (at least) of several exploits (fake CODEC being the most common). Hokay - botnet recruiting, understood. Many returned blameless scans (LinkScanner Online). Which is a worry. (Decoy or undetected exploit?) [Incidentally - many of the spam claim to be "Using Opera's revolutionary e-mail client:" and kudos to SC for pulling the parser away from the Opera URL quite quickly - after a day or two at most the parser ignored it.] Today's batch (larger than yesterday's) all scanned clean. Which is a real worry. What is going on? The payload URLs all seem to be different so it's not simple SEO. Googling "Watch Free Movie - Update Every Hour!" produces pages and pages of hits with the same single line webpage descriptor (about 254 out of 537 hits and rising). So, I'm assuming these are all related. CastleCops notes a malware connection to spam in the "Free Movie" sites case - http://www.castlecops.com/p1107673-Watch_F...ur.html#1107673 (CAUTION - live links there). So, clean scans or not, it is probably still 'just' a malware distribution thing in which case the variation in exploits is a worry, as is the ability to effortlessly keep in front of/avoid LinkScanner. Browsers (on some networks) can be redirected 'mid stream' using DNS exploits to malicious sites and maybe the utilization of that might require a whole army of different URLs (to avoid blocking) and none of those websites actually needs to be an exploit site in its own right (it would not even be seen when the redirection works), which is another possibility. Ah well, paranoia shared is paranoia divided as many times. Or is that multiplied? I always get confused on that point. (IMG:style_emoticons/default/biggrin.gif) -------------------- Plus ça change, plus c’est la même chose
|
Farelf Watch Free Movie - Update Every Hour! Jul 29 2008, 09:30 PM
dra007 I have been getting a dozen of these daily, you ha... Jul 31 2008, 02:10 PM
craigt
Maybe I have to use my magic wand?
Personally I... Jul 31 2008, 05:33 PM
Farelf I have been getting a dozen of these daily, you ha... Jul 31 2008, 05:38 PM
Farelf These seem to have been replaced on 5 August by th... Aug 8 2008, 12:00 AM
dra007 I don't even let the images load when I see th... Aug 8 2008, 10:39 AM
Farelf Fear not Dr. A, you are not suffering alone. Typ... Aug 8 2008, 03:13 PM
Farelf No reports re the exploit/infector site in http://... Aug 10 2008, 11:18 PM
btech As I recall, the rash of these exploited sites is ... Aug 12 2008, 04:01 PM
Farelf ...I believe the html based links are from passwor... Aug 12 2008, 07:32 PM
Farelf Is there no end to their iniquity? Latest version... Aug 12 2008, 08:49 PM
Farelf Keen haters of this botnet recruiting 'genre... Aug 17 2008, 08:36 PM
Farelf And then they were gone. Folded their tents in th... Aug 19 2008, 11:36 PM
Farelf Aagh. Another CNN one over the weekend. But just... Aug 25 2008, 12:12 AM
Farelf Well, yes, one way or another, botnets have increa... Sep 2 2008, 05:14 PM![]() ![]() |
|
Lo-Fi Version | Time is now: 9th September 2010 - 02:30 AM |