RSS feed of TRACElabs Blog from M86 Security

Product Spam is the New King

 

May 6, 2008

Move over Herbal King and Canadian Pharmacy, enter Prestige Replicas and Exquisite Footwear … spam recently is more likely to be pushing designer gear of some kind than enlargement pills.

 

 

Trend

 

 

Early in the year Health Spam, primarily Enlargement Spam, accounted for around three quarters of all spam. Health Spam had been the dominant type for the previous two years. Steadily though, Product Spam has been on the rise, and finally overtook Health Spam this week as the single biggest genre of spam being sent worldwide.

In the past the vast majority of products on offer were fake watches … replica Rolex, Patek Philippe, Bvlgari and Tag Heuer watches were the order of the day. The spammers have branched out a little of late … the fake watches are still on offer, but now we also have designer handbags, shoes, pens and accessories, most likely knock-offs of brands like Ugg, Prada, Versace and Dior.

The messages being sent are generally unexceptional. The domains used as URLs in the messages are invariably registered in China, and link through to sites with names like Prestige Replicas, King Replica or Exquisite Footwear.

Most of the major botnets are getting in on the action. Currently Pushdo, Mega-D and Srizbi are all sending out huge volumes of garbage pushing all these imitation products. One exception is the Rustock botnet, which remains totally focused on enlargement spam. Below are some examples of Product Spam from three botnets: Srizbi, Pushdo and MegaD.

 

Example 1: Srizbi Product Spam

 

Srizbi

 

 

Example 2: MegaD Product Spam

 

MegaD

 

 

Example 3: Pushdo Product Spam

 

Pushdo

 


Last Reviewed: May 9, 2008 by Jarlath Corbett