Last week, Symantec posted a blog on an increase in spam messages with .pw URLs. Since then, spam messages with .pw URLs have begun showing up even more.
Figure 1. .pw TLD spam message increase
Symantec conducted some analysis into where these attacks are coming from in terms of IP spaces. As expected, Symantec observed a large quantity of mail being sent from an IP range and then moving to another IP range. While this is an expected behavior, there was an interesting twist. There were multiple companies (with different names) hosting .pw spammers using the same physical address in Nevada.
Examining messages found in the Global Intelligence Network, Symantec researchers have found that the vast majority of spam messages containing .pw URLs are hit-and-run (also known as snowshoe) spam. The top 25 subject lines from .pw URL spam from May 1, 2013 were:
Subject: For all the moms in your life on Mother’s Day.
Subject: Tax Relief Notification
Subject: Remove IRS Tax Penalties
Subject: Save on the most beautiful bouquets for Mom
Subject: Reusable K Cup for Keurig or single-brew coffee maker
Subject: Garden Today says, “By far the easiest hose to use”
Subject: HOME: Amazingly Strong water hose you can fit anywhere.
Subject: The LAST water hose you’ll ever need
Subject: No Hassle Pricing on Ford Vehicles
Subject: Own a NEW Ford for the Summer
Subject: May 1st Ford Clearance Event
Subject: Lasik- Safe, Easy, and Affordable
Subject: Safe, Easy, and Affordable Lasik
Subject: We work with the Biggest and Best Brands in Fashion
Subject: Whos the hottest? Post . Vote . Win
Subject: Are You and Your Business seen at a global scale?
Subject: Power your entire House, Pool and more with Solar Energy
Subject: Most EFFECTIVE way to treat Hypertension
Subject: Solar power slashes your electric bill in half
Subject: Global Business Registry for Networking Professionals
Subject: Finally, an EFFECTIVE fat shredding solution
Subject: Register with other professionals
Subject: Easiest Way To Lower Blood Pressure
Subject: Secret To Lowering Blood Pressure Naturally
Subject: Refinance Today, Save Tomorrow
In addition to creating anti-spam filters as needed, Symantec has been in contact with Directi and working with the registrar to report and take down the .pw domains associated with spam. Symantec believes that collaborating with the registrar is a more progressive and holistic approach to solving this problem.
I was given a suspicious website link pointing to the website belonging to Board of Regents of State of Louisiana. This link points to the main website hxxp://regents.la.gov/, followed by /wp-content/upgrade/<numbers>.exe, where <numbers>.exe represents several random numbers, followed by EXE extension. A link looking like the following one hxxp://regents.la.gov/wp-content/upgrade/<some_numbers>.exe seems suspicious at first glance. Websites […]
Here’s a late night infomercial for you: How’s that burger flipping going? That cubicle working out ok? Anyway, I’m sure your boss is such a nice guy. Guess what! If you’re interested in a career in criminal hacking, you don’t even need a computer! This special, one-time offer comes to you right now from the Read more…
Revision Note: V1.0 (May 3, 2013): Advisory published.
Summary: Microsoft is investigating public reports of a vulnerability in Internet Explorer 8. Microsoft is aware of attacks that attempt to exploit this vulnerability.
“In the cross hairs of anonymous” The hacktivist group Anonymous announced phase one of a massive cyberattack, called Op USA, on U.S government and banking websites scheduled for next Tuesday, May 7. The White House, the NSA, and the FBI are included on a list of high profile government targets, and 133 financial institutions including the […]
For that past several days, Symantec has observed an increase in spam messages containing hexadecimal obfuscated URLs. Hexadecimal character codes are simply the hexadecimal number to letter representation for the ASCII character set. To a computer, he…
Bugs. Creepy, crawly, never-really-know-where-they’re-hiding, infestations of bugs. If we could just see them all, we would rid our lives of bug infestations with doses of (environmentally friendly) spray. But what about the bugs that we can’t see? What about the bugs that have snuck past, and infiltrated the hidden corners of our lives, then quietly Read more…
Certificados SSL: cómo y cuándo utilizar OpenSSL
A la hora de proteger los sistemas de una empresa, el protocolo SSL (Secure Sockets Layer) se ha convertido en un arma esencial, pues cifra los datos que se transmiten por Internet y …
SSL Zertifikate (Secure Sockets Layer) gehören zur Grundausstattung jedes Unternehmens für den Schutz seiner Systeme. Das Protokoll mit integrierter Datenverschlüsselung ist die Standar…