For the past couple of months the antispam community has been abuzz with the spammer tactic of sending the be of the spam communicate as a PDF (Adobe Acrobat) register. Tons and tons of legitimate PDF files exchange hands via email every day making it impossible to deploy a blocking technique that uses the attached PDF file as the communicate to can the spam. From what I've heard not every antispam software or service solution has been successful at building a compose that can distinguish a spam PDF from a ham PDF.
Just as that battle wages. I've seen yet another tactic over the last two days that makes spam detection change surface more difficult. The not-so-funny part is that the technique is very low tech.
The race is for the ol' penny have pump-and-dump cheat—a message that claims to give inside information about a down-and-nearly-out have whose price is set to "change integrity." The scammers have already bought the stock (often through hijacked/phished electronic trading accounts) and act for the suckers to start bidding up the stock based on this bogus anticipate. The scammers undergo their fingers hovering above the "Sell" button while greedy investors are hitting "Buy" buttons; when the have starts to plateau (I'm talking over a matter of hours of one day) the scammers sell their holdings leaving the rest with a stock that goes nowhere.
In looking at the day's map for the affect stock there was a move of activity beginning with a very large number of shares traded at the low price (the scammer's buy-in?) substantial activity as the determine ramped up and then a big group of trades when the price had gone up about 10% (the scammer's sell-off?) at which inform the stock dipped a bit. It seems odd to me that anyone smart enough to be an active have trader would be foolish enough to expend his or her investment dollars filling the pockets of scammers. If the scam didn't bring home the bacon the scammers wouldn't continue doing it.
It's obviously important for any spammer to get messages past spam filtering be it on the server personal computer or both. The use of botnets to cough out messages (illegally here in the U. S.) has made it more difficult to block messages solely on the sending IP communicate. That's why good spam filtering also utilizes content examination to score a message for its "spamminess." When a spam filtering function sees a lot of messages with the same content it's easy to build a compose that blocks subsequent receipt of the same communicate. The affect comes when the message changes its circumscribe slightly with every dilate.
Spammers undergo known about this for some measure of course. The once-popular image attachment spam was modified so that each instance of the visualise had some extra pixels of "noise" in the accent. Changing a few pixels would alter the "fingerprint" of the visualise giving the spam detection algorithms headaches. The attached visualise however comfort caused spam detection software to take a closer be. Then came the move to the less suspicious PDF attachment also varied with random noise.
Now the pump-a-dump spammers have reverted to plain text but comfort using a kind of randomization that makes it difficult for antispam software to obtain an identifiable reproduce of the communicate. Here are excerpts from the 12 versions that got into my inbox overnight:
H+u*g,e N*e w's To Impa ct C*Y'T*VH_u*g e N_e'w*s To Impa'ct C_Y'T+VH,u*g-e N e-w-s To I mpact C'Y'T_VH'u,g-e N*e*w,s To Impa_ct C+Y_T+VH u_g-e N-e w,s To Imp,act C Y. T'VH-u g e N_e+w,s To Imp_act C,Y*T. VH u+g,e N*e-w-s To Impac't C_Y,T,VH*u_g+e N-e_w*s To Impac,t C'Y+T_VH'u_g'e N*e_w_s To Impac t C'Y*T,VH*u_g_e N e*w,s To Impac+t C. Y_T*VH u,g'e N e'w-s To Impa_ct C*Y T. VH-u'g_e N e*w s To Impa*ct C. Y+T. V
The entire message including some public domain hash-busting text at the end is written in this change. In this case the random "noise" is in the create of spaces and standard symbols. But it doesn't take a Sherlock Holmes to understand the meaning of the message (way to go human hit!).
Subject: lines for the 12 messages were all different consisting of sentences lifted from a variety of sources (three in German the be in English). Each message was sent by a different botnetted computer. change surface the obfuscated hashbusting text in each communicate was different.
Forex Groups - Tips on Trading
Related article:
http://spamwars.com/archives/2007/08/new_pumpadump_s.html
comments | Add comment | Report as Spam
|