[Be warned; this E-mail mentions one of our programs several
times. However, if you have your server properly locked down, you can be
safe from these attacks without running our software.]
After developing our Declude Hijack program (which is designed to allow
legitimate E-mail through without having to lock down your server with SMTP
AUTH or IP address restrictions), we waited almost 2 months for a spammer
to try to hijack our server. Although there were a number of spammers that
"sniffed" our server (sent out a few E-mails to make sure that they could
relay, and to see what headers were used), they must have all noticed the
Declude headers and looked for an easier target.
Anyways, this weekend, there were 6 different (but related) attacks on our
server (which fortunately Declude Hijack caught; not a single spam went out)!
These attacks were unusual in that they averaged only about 600 E-mails at
a time, which is very low for a spammer. Usually, they find one server and
send out 50,000 to 100,000's of E-mails (or more). It appears that some
spammers are now sending out smaller amounts of mail through larger numbers
of servers, to minimize the chances of them getting caught. In fact, this
attempted hijacking would have gone unnoticed if we hadn't been running our
new program.
All of the E-mails were addressed to AOL users. AOL has effective spam
controls, so it may be that this spammer is trying to bypass some of the
AOL spam controls by having their E-mails sent from a larger set of IP
addresses.
#1: HTML E-mail for a viagra alternative, 315 E-mails attempted.
#2: text E-mail for bodybuilding pills; 1,680 E-mails attempted.
#3: text E-mail for gambling web site; 357 E-mails attempted.
#4: HTML E-mail for Internet Investigations (personal); 294 E-mails attempted.
#5: HTML E-mail for female viagra; 420 E-mails attempted.
#6: HTML E-mail for Internet Investigations (business); 63 E-mails attempted.
These came from 6 different E-mail addresses. We believe they all came
from the same spamming company (likely a "spammer for hire" sending E-mails
for others), because all 6 E-mails had random text at the very end that
appears to be designed to bypass spam filtering (making it look like a
legitimate E-mail).
None of the 6 IP addresses that sent these E-mails has a reverse DNS
entry. None of them sent any "Received:" headers (a dead giveaway that the
E-mail is spam). They all had different headers, but each one had headers
that aren't normally found in spam (such as "Replyto" headers).
It appears that some spammers are now being very creative in ways of
avoiding spam detection, as well as avoiding getting noticed by the servers
they are leeching off of.
-Scott
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/