Jul20
10:03 pm (UTC-7)   |   by Roderick Ordoñez (Technical Communications)

At first glance, these spam emails look like the usual spam, but closer inspection proves otherwise:

According to our Antispam Engineers, “This is tricky, it’s just like the usual replica-image spam, but looking into the details, there’s no image at all!” Spammer’s tactical capabilities seems to have reached new artistic heights. By spanning HTML rows and columns together, an “image” comes out as TD and TR tags come into play, being extensively used to create spam without inserting any character. It’s just a complex table design with extended columns and rows across other multiple rows and columns.

This kind of spam mail is already detected in AS Pattern 6034. Below is the mail’s source code:

King Replica, the Web site advertised by the spam, has long been reputed as a spamming and scamming site in the Internet community. The site is rather well-known for spam mails, thus the need for new ways to enter user’s inboxes, as other types of spam (eg, text, image, links, and attachments) are filtered by newer anti-spam engines.

The site itself has a legitimate feel to it, but its spam routine has caused it to be flagged as a fake watch site. In any case, mail that tries to deceive the end user -spam or not- cannot be trusted, and that’s a lesson that spans both worlds – either virtual or real.

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!




Comments are closed.



© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice