02 Nov 2006
A sudden increase in spam has been identified in the latest security report issued today, as cyber-criminals gear up for a pre-Christmas blitz.
Spammers are using new weapons to evade detection by conventional security software and increase their success rate, according to the October 2006 Intelligence report from security firm MessageLabs.
One of these is a 'dropper' variant of the Warezov virus, which instructs the infected computer to download a second component, an executable file, from an IP address.
Usually the .exe file downloads a spam message and email addresses, turning the infected computer into a spam production house, MessageLabs senior analyst Paul Wood told vnunet.com.
Using a dropper technique means that Warezov does not have to deliver all its code in the initial infection, making it harder to detect using conventional antivirus software.
Furthermore, variations of Warezov have been issued in batches. Conventional antivirus software works by identifying the virus signature, the string of code which makes up the virus.
By altering the code subtly with each variation, the virus can evade detection until antivirus firms identify the new variation and issue an update.
Warezov variations have been released over weekends when staffing levels at antivirus firms are lowest, which means that security firms have struggled to issue patches in time, according to Wood.
Large computer systems which use heuristic, or rules-based, filters can weed out these variations, but such tools are not viable for single PCs as they would sap too much processing power.
Another weapon in the spammers' new arsenal is a spam-sending Trojan dubbed SpamThru which employs the "spam cannon" technique. This uses a template for each spam and combines it with a list of email addresses, similar to a mail merge.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
A leading global provider of critical information to...
Playstations and table football in the kitchen? Standard...
Systems Engineer - 2nd/3rd Line Support - Microsoft OS...
A leading global provider of critical information to...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
If no one used your service, you would'nt offer it.
Why can't we go after the business that hirer spammers and hold them responsible both financially and legally?
Posted by: James Nelmes 04 Nov 2006