All the latest UK technology news, reviews and analysis

Spammers gear up for pre-Christmas blitz

by Andrew Charlesworth

02 Nov 2006

Comment: 1

  • Tweet this
Spam
Spammers are using new weapons to evade detection by conventional security software

A sudden increase in spam has been identified in the latest security report issued today, as cyber-criminals gear up for a pre-Christmas blitz.

Spammers are using new weapons to evade detection by conventional security software and increase their success rate, according to the October 2006 Intelligence report from security firm MessageLabs

One of these is a 'dropper' variant of the Warezov virus, which instructs the infected computer to download a second component, an executable file, from an IP address.

Usually the .exe file downloads a spam message and email addresses, turning the infected computer into a spam production house, MessageLabs senior analyst Paul Wood told vnunet.com.

Using a dropper technique means that Warezov does not have to deliver all its code in the initial infection, making it harder to detect using conventional antivirus software.

Furthermore, variations of Warezov have been issued in batches. Conventional antivirus software works by identifying the virus signature, the string of code which makes up the virus.

By altering the code subtly with each variation, the virus can evade detection until antivirus firms identify the new variation and issue an update.

Warezov variations have been released over weekends when staffing levels at antivirus firms are lowest, which means that security firms have struggled to issue patches in time, according to Wood.

Large computer systems which use heuristic, or rules-based, filters can weed out these variations, but such tools are not viable for single PCs as they would sap too much processing power.

Another weapon in the spammers' new arsenal is a spam-sending Trojan dubbed SpamThru which employs the "spam cannon" technique. This uses a template for each spam and combines it with a list of email addresses, similar to a mail merge.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Web Graphic Designer

A leading global provider of critical information to...

Midweight UI Designer

Playstations and table football in the kitchen? Standard...

Systems Engineer - 2nd/3rd Line Support - Microsoft + Citrix OR VMware

Systems Engineer - 2nd/3rd Line Support - Microsoft OS...

Senior Network Engineer

A leading global provider of critical information to...

To send to more than one email address, simply separate each address with a comma.