Next wave of Image Spam

Discussion in 'Computer Security' started by zebulebu, Jun 27, 2007.

  zebulebu

    zebulebu

    Today our mail filters were hit with the first significant tranche of image spam hidden in .pdf documents.

    We've had a few in the past couple of weeks, but today was the first time we saw significant activity around this type of image spam. It isn't very sophisticated as yet (all the images are the same, so are easily blocked) but I'm sure we can expect to see dynamically-generated pdf spam soon.

    The bastids just keep getting sneakier! :x

    Interestingly, the pattern of the spam shows how well my ironMail appliance is working - we received about thirty in the first fifteen minutes, then, presumably as the bayesian filters kicked in, it dropped off significantly until, an hour later, it was non-existent. I checked the logs and they showed lots of the spam was being sent from either new bots, or hitherto-unlisted IP ranges, mainly in Poland, Ukraine and Russia.
  nugget
    nugget

    nugget Junior toady

    Thanks for the heads-up Zeb. :thumbleft
  Bambino1506

    Bambino1506

    Thanks for the update fella.

    What is the advantage of them sending spam in image format ? Just that the firewall etc isn't looking for them ?
  Sparky
    Sparky

    Basically yeah, some more details here...


    Also I've noticed that some people who send short emails with a email signature which has a grpahic in it get caught up in our spam filter. The graphics are generally too big to be in a email sig to be honest so I blame the users! :biggrin
  nXPLOSi

    nXPLOSi

    Pretty much mate, our blocking system wasnt picking them up, luckily enough I got one of the first one's so I managed to change it before it was unleashed on the users!

    Alot of the one's im getting say something like;

    "A Friend has sent you can e-card, attached"

    I hate to say it, but most of my users wouldn't think twise and just open it.. no matter how many times i've gone over the whole dont open any emails from unknown senders spill....:eek:
  Theprof

    Theprof

    Happened to us too, luckily the spam filter did pick up and safely blocked the email.
