Sample Pornography Spam - Online Webcams
Pornography spam are probably some of the most dangerous messages not only because of their reach to minors, but also because they offer the perfect bait of free porn. In order to view the porn, the recipient has to download and install a program. These programs are trojan horses designed to open a backdoor, enabling information stored on the PC to be stolen. Also very common, the trojan program opens a back door to turn control of PC over to the spammer without the victim's knowledge. In such cases, it becomes a gray area bordering on hacking.
These types of spam operates using all kinds of dubious methods. From registering your profile on bogus adult dating sites, to downloading free porn or enticing the visitor to download special software to participate in virtual sex. We examined a few in our study, and found that none of them actually delivered any of their promises, but had instead aim to deliver their payload via trojan programs.
In the interest of originality, the body of the message is left unaltered as much as possible. But for security reasons, and to protect the reputation of our own website from being seen as linking to bogus websites, the links in the spam message have been disabled. Placing your mouse over them will show the original url it intended to link to, but clicking on them will bring you to spamhaus.org, a non-profit organization for combating spam.
From: "Carey Taylor" <aeufw@cxp.com.br>
To: blkrsvp@yahoo.com
Date: Fri, 01 Sep 2006 14:31:24 -0700
Subject: just got this web-cam and I can't help stripping
See why millions of horny singles voted us the best.
Women and Men in your area are looking to hook up with you tonight.
View our extensive and revealing picture batabase free of charge.
Get hooked up here: http://umblemished.cam-singles.net/abb/
|
This message was sent by a hardcore spammer. The message is so short and simple, but yet so harmful as we will see.
Points to note :-
- Forged from email aeufw@cxp.com.br
- The domain cam-singles.net was registered on 9th Aug 2006, and by 31st Aug, it had already been blacklisted as one of the most prolifically spammed website. The url it links to http://umblemished.cam-singles.net/abb/ uses a subdomain, presumably to fool less sophisticated blacklist systems. The /abb/ at the end of the url is used for tracking purposes.
- Although we cannot positively assert, but the email header looks to have been forged. The email originated either from Brazil or New Jersey, USA.
- Clicking on the link then forwards to yet another bogus website http://www.scorch-dating.com
- The bogus website scorch-dating.com uses loads of nudity to entice the visitor to signup for a free account. It claims to be around since 1996 and claims to be one of the largest adult dating websites with 4830 members currently online, 25180 registrations this week and a total of 5.5 million members. The truth is, the website has been around for less than six months, with zero members online or offline. The website is only a front to capture visitor details and entice them to download their trojan program, which brings us to the next point.
- In order to deliver its payload of a trojan horse program, the "Member Search" function claims to work only if the installer program is downloaded and installed. Clicking on it prompts for a download, which we aborted at this stage.
- None of the links work in the way they should. Clicking on any of them either presents a registration page requesting for personal information or to download the installer program in order to be able to use the feature.
- The spammer appears to be promoting an affiliate program by http://www.iwantu.com It pays $10 per signup and $1 for every visitor to click on the registration page. The registration page we explained earlier is the iwantu.com registration page.
- All of the spammer's domains uses private registrations, so its not possible to tell who the websites are registered to.
- All the websites are hosted in China.