<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>The Spam Cryer</title>
	
	<link>http://www.thespamcryer.com</link>
	<description>Intelligent Discussion on Anti-Spam</description>
	<lastBuildDate>Mon, 26 Oct 2009 16:16:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/TheSpamCryer" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>Postini Delivery Problems Vex Users</title>
		<link>http://feedproxy.google.com/~r/TheSpamCryer/~3/dh63C72-UNE/</link>
		<comments>http://www.thespamcryer.com/2009/10/16/postini-suffers-delays/#comments</comments>
		<pubDate>Fri, 16 Oct 2009 15:33:19 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Postini Problem]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/2009/10/16/postini-suffers-delays/</guid>
		<description><![CDATA[Users of email security and archiving service Postini were frustrated last week when the service began experiencing significant delivery problems.]]></description>
			<content:encoded><![CDATA[<p>(October 13, 14 &#038; 15, 2009)</p>
<p>Users of email security and archiving service Postini were frustrated last week when the service began experiencing significant delivery problems.</p>
<p>Users were particularly angered by Postini&#8217;s lack of communication about the problem.  Postini was acquired by Google in 2007.  Similar to our <a href="http://www.CudaMail.com" title="CudaMail Spam and Virus Filtering Service">CudaMail Anti-Spam Service</a>, the service scans emails for malware.  The problem seems to have been caused by a combination of a bad email filter update and &#8220;a power-related hardware failure.&#8221; </p>
<ul>
<li><a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=220600859" rel="nofollow" target="_blank">http://www.informationweek.com/news/showArticle.jhtml?articleID=220600859</a></li>
<li><a href="http://news.cnet.com/8301-30684_3-10374344-265.html" rel="nofollow" target="_blank">http://news.cnet.com/8301-30684_3-10374344-265.html</a></li>
<li><a href="http://www.theregister.co.uk/2009/10/15/google_postini_snafu/" rel="nofollow" target="_blank">http://www.theregister.co.uk/2009/10/15/google_postini_snafu/</a></li>
<li><a href="http://www.computerworld.com/s/article/9139316/Postini_trouble_stymies_U.S._e_mail_users?taxonomyId=1" rel="nofollow" target="_blank">http://www.computerworld.com/s/article/9139316/Postini_trouble_stymies_U.S._e_mail_users?taxonomyId=1</a></li>
<p>[Editor's Note (Pescatore): We used to call the telecommunications infrastructure "the cloud," and we had very high expectations of reliability. We even had required service levels for things like dial tone. Internet-based web services are today's cloud - boy, are they far from achieving dial-tone like reliability.]</p>
<p>-  Shaun</p>
</ul>
<img src="http://feeds.feedburner.com/~r/TheSpamCryer/~4/dh63C72-UNE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/2009/10/16/postini-suffers-delays/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thespamcryer.com/2009/10/16/postini-suffers-delays/</feedburner:origLink></item>
		<item>
		<title>Gmail users are reporting a huge spam surge</title>
		<link>http://feedproxy.google.com/~r/TheSpamCryer/~3/DuSEEOfiDdc/</link>
		<comments>http://www.thespamcryer.com/2009/06/26/gmail-users-are-reporting-a-huge-spam-surge/#comments</comments>
		<pubDate>Fri, 26 Jun 2009 19:46:24 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[GMail]]></category>
		<category><![CDATA[spam surge]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=223</guid>
		<description><![CDATA[A lot of GMail users have been angered by a lot more spam reaching their inboxes, than they were used to.]]></description>
			<content:encoded><![CDATA[<p>A lot of GMail users have been angered by a lot more spam than they were used to &#8211; reaching their inboxes.</p>
<p>It seems to have been going on for several weeks, but in the recent few days it&#8217;s apparently been getting much worse.   Our <a href="http://www.CudaMail.com" title="CudaMail Managed Spam and Virus Filtering Service">CudaMail </a>service has seen an increase in that type of spam recently as well.  We&#8217;ve put some filters in place fortunately, but there has definitely been an increase.</p>
<p>A lot of it was the &#8220;SEO Google first page rankings&#8221; type.</p>
<img src="http://feeds.feedburner.com/~r/TheSpamCryer/~4/DuSEEOfiDdc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/2009/06/26/gmail-users-are-reporting-a-huge-spam-surge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thespamcryer.com/2009/06/26/gmail-users-are-reporting-a-huge-spam-surge/</feedburner:origLink></item>
		<item>
		<title>Swine Flu Phishing Attacks and Email Scams</title>
		<link>http://feedproxy.google.com/~r/TheSpamCryer/~3/FRxd12THKWo/</link>
		<comments>http://www.thespamcryer.com/2009/04/27/swine-flu-phishing-attacks-and-email-scams/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 21:37:22 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Barracuda Networks]]></category>
		<category><![CDATA[Online Scams]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam Firewall]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Barracuda]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=219</guid>
		<description><![CDATA[US-CERT is aware of public reports of email scams circulating related to the Swine Flu. The attacks arrive via an unsolicited email message typically containing a subject line related to the Swine Flu. These email messages may contain a link or an attachment. If users click on this link or open the attachment, they may be directed to a phishing website or exposed to malicious code.]]></description>
			<content:encoded><![CDATA[<p><strong>US-CERT</strong> is aware of public reports of email scams circulating related to the Swine Flu. The attacks arrive via an unsolicited email message typically containing a subject line related to the Swine Flu. These email messages may contain a link or an attachment. If users click on this link or open the attachment, they may be directed to a phishing website or exposed to malicious code.</p>
<p>US-CERT encourages users to take the following measures to protect themselves:</p>
<ul>
<li>Do not follow unsolicited web links or attachments in email messages.</li>
<li>Maintain up-to-date antivirus software.</li>
<li>Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.</li>
<li>Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.</li>
</ul>
<p>Maintaining up-to-date anti-virus is vital. Some appliances, like the <a href="http://www.BarracudaNetworks.ca" target="_blank">Barracuda Spam &amp; Virus Firewalls</a> that are used by <a title="CudaMail Managed Spam &amp; Virus Filtering Service" href="http://www.CudaMail.com" target="_blank">CudaMail.com</a> to filter mail are updated on a constant basis.</p>
<p><strong>US-CERT</strong> will provide additional details as they become available.</p>
<h3>Relevant Url(s):</h3>
<p><a href="http://www.us-cert.gov/cas/tips/ST04-014.html" target="_blank">http://www.us-cert.gov/cas/tips/ST04-014.html</a></p>
<p><a href="http://www.avertlabs.com/research/blog/index.php/2009/04/27/swine-flue-spam/" target="_blank">http://www.avertlabs.com/research/blog/index.php/2009/04/27/swine-flue-spam/</a></p>
<p><a href="http://www.us-cert.gov/reading_room/emailscams_0905.pdf" target="_blank">http://www.us-cert.gov/reading_room/emailscams_0905.pdf</a></p>
<img src="http://feeds.feedburner.com/~r/TheSpamCryer/~4/FRxd12THKWo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/2009/04/27/swine-flu-phishing-attacks-and-email-scams/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thespamcryer.com/2009/04/27/swine-flu-phishing-attacks-and-email-scams/</feedburner:origLink></item>
		<item>
		<title>US-CERT: Waledac Trojan Horse Spam Campaign Circulating</title>
		<link>http://feedproxy.google.com/~r/TheSpamCryer/~3/l-2sfhDjZOU/</link>
		<comments>http://www.thespamcryer.com/2009/04/09/us-cert-waledac-trojan-horse-spam-campaign-circulating/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 16:17:31 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Bulletins]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Online Scams]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[US-CERT]]></category>
		<category><![CDATA[waledac]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=217</guid>
		<description><![CDATA[US-CERT is aware of public reports of malicious code circulating via spam email messages related to bogus terror attacks in the recipient's local area.]]></description>
			<content:encoded><![CDATA[<p><strong>Original release date</strong>: March 17, 2009 at 9:08 am Last revised: March 17, 2009 at 9:08 am</p>
<p>US-CERT is aware of public reports of malicious code circulating via spam email messages related to bogus terror attacks in the recipient&#8217;s local area. These messages use subject lines implying that a fatal bomb attack has occurred near the recipient and contain a link to &#8220;breaking news.&#8221;</p>
<p>Users who click on the link will be taken to a site posing as a Reuters news article that contains a bogus news story about the fatal bomb attack. The systems serving the bogus news story check a visiting user&#8217;s IP address to obtain a geographical location to insert a nearby placename into the bogus article. The articles also contain links to video content, claiming that the latest Flash Player is required to view the video.</p>
<p>If users attempt to update or install the Flash Player from the link provided in the article, their systems may become infected with malicious code.</p>
<p><strong>US-CERT</strong> encourages users and administrators to take the following preventative measures to help mitigate the security risks:<br />
  * Install antivirus software, and keep the virus signatures up to<br />
    date.<br />
  * Do not follow unsolicited links and do not open unsolicited email<br />
    messages.<br />
  * Use caution when visiting untrusted websites.<br />
  * Use caution when downloading and installing applications.<br />
  * Obtain software applications and updates directly from the<br />
    vendor&#8217;s website.<br />
  * Refer to the Recognizing and Avoiding Email Scams (pdf) document<br />
    for more information on avoiding email scams.<br />
  * Refer to the Avoiding Social Engineering and Phishing Attacks<br />
    document for more information on social engineering attacks.</p>
<p>Relevant Url(s):<br />
<http ://www.us-cert.gov/cas/tips/ST04-014.html></p>
<p></http><http ://www.us-cert.gov/reading_room/emailscams_0905.pdf></p>
<p>====<br />
This entry is available at<br />
<a href="http://www.us-cert.gov/current/index.html#waledac_trojan_horse_spam_campaign">http://www.us-cert.gov/current/index.html#waledac_trojan_horse_spam_campaign</a></http></p>
<img src="http://feeds.feedburner.com/~r/TheSpamCryer/~4/l-2sfhDjZOU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/2009/04/09/us-cert-waledac-trojan-horse-spam-campaign-circulating/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thespamcryer.com/2009/04/09/us-cert-waledac-trojan-horse-spam-campaign-circulating/</feedburner:origLink></item>
		<item>
		<title>Stimulus packages, stock brokers and Trojans, Oh My!</title>
		<link>http://feedproxy.google.com/~r/TheSpamCryer/~3/s69ZNheavDM/</link>
		<comments>http://www.thespamcryer.com/2009/03/03/stimulus-packages-stock-brokers-and-trojans-oh-my/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 18:06:16 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Online Scams]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[fortinet]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=210</guid>
		<description><![CDATA[Malware called Tigger/Syzor which is a safe mode rootkit password stealing Trojan that targets day traders.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.thespamcryer.com/wp-content/uploads/2009/03/stocks.jpg" alt="Day Trading" title="stocks" style="float:right;margin: 5px 5px 5px 10px;" /></p>
<p>‘<strong>Follow the money’ </strong> With the recent stock market volatility creating interest and opportunity for a savvy investor the lure of all that money is attracting the attention of malware writers.</p>
<p>Michael Kassner the Manager of IT for Getinge LaCalhene and a well certified IT Professional recently ran into a piece of malware with a twist. Called <strong>Tigger/Syzor</strong> it appeared on the PC of a friend of Michael’s who is a day trader and deals with companies like E-Trade, ING Direct, Vanguard, Options Xpress, TD Ameritrade and Scottrade.</p>
<p><strong>Guess what</strong>? Tigger/Syzor likes the same friends as it is a safe mode rootkit password stealing Trojan that <strong>targets day traders</strong>. Michael was able to use tools like Malware Bytes Anti-Malware (MBAM) to find and remove some files that were identified as malware but ultimately he went with a full clean re-install of the operating system and all applications just to be sure.</p>
<p>The day trader does keep his computer up to date with patches and program updates so what else could he have done? How about running in a virtual environment? With tools like VMWare Server being offered for free and giving you the ability to run an isolated second complete copy of the operating system and programs he could have run the tools that are critical to his job in one and done his research (web browsing) in a second. This isolates the whole system so that if one aspect of his system get’s infested he can just roll back to a previous version or snapshot without the infection and continue running with only a few minutes downtime and not a whole panic filled weekend.</p>
<p>He would even be able to turn off the day trading virtual system after the markets close and let his kids (I don’t know if he has any – just speculating) use a separate dedicated kids only virtual machine that was locked down and set to clear all changes when it was rebooted. This may require that a few additional licenses of Windows be purchased and a little discipline to not get lazy and browse from his critical virtual machine but as they say an ounce of prevention is worth a pound of cure. The day trading tools that he uses also have to be able to run in a virtualized environment and be supported by the vendor when running in such a way.</p>
<p>A second thing this day trader should do is run his home network like a corporate network with similar hardware (<a href="http://www.firewallshop.com" target="_blank" title="FirewallShop.com Fortinet, Barracuda, SonicWall, WatchGuard, Wedge">http://www.firewallshop.com</a>) and protective measures in place. I’d hazard a guess that he is running a consumer level firewall (with unprotected wireless on too I’d bet) that acts as a one way valve using Network Address Translation (NAT) and very little else.</p>
<p>He makes his living by day trading so treat this network like the office it is and  install a corporate level firewall like a <strong>FortiGate</strong> that does layer 7 anti-virus scanning at the edge. With the recent introduction of the <a href="http://www.firewallshop.com/detail.aspx?ID=283" target="_blank" title="Fortinet FortiGate 30B Bundle">FortiGate 30B Bundle</a> the price of a very capable corporate level firewall has dropped to the $500.00 range with one year of updates and basic support. When your living depends on your trading thousands of dollars daily doesn’t it make sense to protect your investment and passwords with an enterprise level firewall?</p>
<p><strong>Tigger.A</strong>: Sophisticated trojan that likes stockbrokers<br />
<a href="http://blogs.techrepublic.com.com/security/wp-trackback.php?p=960" target="_blank">http://blogs.techrepublic.com.com/security/wp-trackback.php?p=960</a></p>
<p><strong>Michael Kassner</strong><br />
<a href="http://techrepublic.com.com/5213-6257-0.html?id=4730583" target="_blank">http://techrepublic.com.com/5213-6257-0.html?id=4730583</a></p>
<p><strong>FortiGate 30B</strong><br />
<a href="http://www.firewallshop.com/detail.aspx?ID=283" target="_blank" title="Fortinet FortiGate 30B Firewall">http://www.firewallshop.com/detail.aspx?ID=257</a></p>
<img src="http://feeds.feedburner.com/~r/TheSpamCryer/~4/s69ZNheavDM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/2009/03/03/stimulus-packages-stock-brokers-and-trojans-oh-my/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thespamcryer.com/2009/03/03/stimulus-packages-stock-brokers-and-trojans-oh-my/</feedburner:origLink></item>
		<item>
		<title>MS09-002 exploit in the wild</title>
		<link>http://feedproxy.google.com/~r/TheSpamCryer/~3/47LdCF47F8M/</link>
		<comments>http://www.thespamcryer.com/2009/02/19/ms09-002-exploit-in-the-wild/#comments</comments>
		<pubDate>Thu, 19 Feb 2009 18:57:51 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Bulletins]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[ISC]]></category>
		<category><![CDATA[MS09-002]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=201</guid>
		<description><![CDATA[The Internet Storm Center is reporting that several AV vendors have confirmed that the recently patch IE 7 vulnerability (MS-09-002 Uninitialized Memory Corruption) has been reverse engineered by the malware writers (so quickly!)]]></description>
			<content:encoded><![CDATA[<p>The <strong>Internet Storm Center</strong> is reporting that several AV vendors have confirmed that the recently patched IE 7 vulnerability (MS-09-002 Uninitialized Memory Corruption) has been reverse engineered by the malware writers (so quickly!) and that we can expect them to be trying to infect your PC’s and get you to join in their zombie army any time now.</p>
<p>What does this have to do with spam? Spam is one way that they try to infect your PC so be on the lookout for simple, hard to block e-mail’s with a catchy subject line and a simple link to a website. </p>
<p>The <a href="http://www.CudaMail.com" target="_blank">CudaMail System</a> has been seeing and blocking a rise in emails with simple links to malware sites, and even the occasional iframe.  They&#8217;re definitely trying various ways to sneak malicious links into your inbox.</p>
<p>It bears repeating that if you don’t know where the e-mail came from or if you weren’t expecting it and can’t confirm that the supposed sender really sent it to you be very careful opening the website or better yet don’t open it at all.</p>
<p>MS09-002 exploit in the wild (via Sans)<br />
<a href="http://isc.sans.org/diary.html?storyid=5884" target="_blank">http://isc.sans.org/diary.html?storyid=5884</a></p>
<p>- Shaun</p>
<img src="http://feeds.feedburner.com/~r/TheSpamCryer/~4/47LdCF47F8M" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/2009/02/19/ms09-002-exploit-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thespamcryer.com/2009/02/19/ms09-002-exploit-in-the-wild/</feedburner:origLink></item>
		<item>
		<title>IRS stimulus Phishing scam</title>
		<link>http://feedproxy.google.com/~r/TheSpamCryer/~3/qJC_KCmMhQI/</link>
		<comments>http://www.thespamcryer.com/2009/02/06/irs-stimulus-phishing-scam/#comments</comments>
		<pubDate>Sat, 07 Feb 2009 00:09:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam Firewall]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[stimulus package]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=193</guid>
		<description><![CDATA[
US-CERT Current Activity
IRS Stimulus Package Phishing Scam
Original release date: February 6, 2009 at 10:03 am Last revised: February 6, 2009 at 10:03 am
US-CERT is aware of public reports indicating that phishing scams are circulating via fraudulent U.S. Internal Revenue Service emails offering users stimulus package payments. These emails include text that attempts to convince users [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.thespamcryer.com/wp-content/uploads/2009/02/phishing.jpg" alt="Phishing" width="129" height="116" class="size-medium wp-image-196" style="float:right;" /></p>
<h2>US-CERT Current Activity</h2>
<h3>IRS Stimulus Package Phishing Scam</h3>
<p>Original release date: February 6, 2009 at 10:03 am Last revised: February 6, 2009 at 10:03 am</p>
<p><b>US-CERT</b> is aware of public reports indicating that phishing scams are circulating via fraudulent U.S. Internal Revenue Service emails offering users stimulus package payments. These emails include text that attempts to convince users to follow a link to a website or to complete an attached document. The website and document request that the user provide personal information.</p>
<p>US-CERT encourages users to do the following to help mitigate the risks:</p>
<p>  * Do not follow unsolicited web links received in email messages.<br />
  * Refer to the Recognizing and Avoiding Email Scams (pdf) document<br />
    for more information on avoiding email scams.<br />
  * Refer to the Avoiding Social Engineering and Phishing Attacks<br />
    (pdf) document for more information on social engineering attacks.</p>
<p>Relevant Url(s):<br />
<http ://www.us-cert.gov/cas/tips/ST04-014.html><br />
</http><http ://www.us-cert.gov/reading_room/emailscams_0905.pdf></http></p>
<p>====</p>
<p>This entry is available at: http://www.us-cert.gov/current/index.html#irs_stimulus_package_phishing_scam</p>
<img src="http://feeds.feedburner.com/~r/TheSpamCryer/~4/qJC_KCmMhQI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/2009/02/06/irs-stimulus-phishing-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thespamcryer.com/2009/02/06/irs-stimulus-phishing-scam/</feedburner:origLink></item>
		<item>
		<title>Are you ready to see your spam volume Jump 10 times?</title>
		<link>http://feedproxy.google.com/~r/TheSpamCryer/~3/B_y_9vttyOs/</link>
		<comments>http://www.thespamcryer.com/2009/01/26/are-you-ready-to-see-your-spam-volume-jump-10-times/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 20:41:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Barracuda Networks]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Bulletins]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Spam Firewall]]></category>
		<category><![CDATA[Barracuda Central]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=185</guid>
		<description><![CDATA[It took less than 3 months for the Spammers to ramp up their production to 90% of where it was pre-McColo takedown in November 2008 according to a number of reports and graphs available online.]]></description>
			<content:encoded><![CDATA[<p>It took less than 3 months for the Spammers to ramp up their production to 90% of where it was pre-McColo takedown in November 2008 according to a number of reports and graphs available online.</p>
<p>The first report is from Message Labs and it reports that with spam volume up another 5% so far in January 2009 the top 10 Botnets, while consisting of between 10 thousand to 1 Million bots (estimated), were capable of sending out between 131 Million to almost 40 BILLION Spam messages PER DAY per Botnet. Total Volume from just the top 10 Botnets totalled almost 65 Billion messages per day! Are you getting your fair share?</p>
<p>It is interesting to see that the largest Botnet Cutwail/Pandex placed second behind Mega-D/Ozdok in spam volume per day category (7 Billion to 38 Billion) even though it had more compromised PC’s (1 Million bots to 660,000). This is double interesting as the latest estimates for the recent Conflicker/Downadup botnet size is at 10 million PC’s and they are not sending any spam yet. &nbsp;With 10 million bots and assuming an aggressive and efficient spam engine Conflicker/Downadup could be capable of sending over half a Trillion (575 Million) messages per day by itself. Are you ready to see your spam volume jump to 10 times its current volume or even higher?</p>
<p>According to Barracuda Central Pharmacy spam still leads with almost 50% of the total volume while Gambling, Illegal Advertizing, ‘Amazing Deals on Software’ and ‘Genuine Replica’s’ round out the top 5 spots and over 90% of the total volume of spam.</p>
<p>If you don’t know how effective your anti-spam measures are or how close they are to running at capacity (out of sight = out of mind) then now is the time to take a serious look at these solutions in your organization and how they are going to handle the new surge of spam that is waiting on the horizon.</p>
<p>It might just be time to invest in a new <a href="http://www.FirewallShop.com" title="FirewallShop" target="_blank">firewall solution</a> and <a href="http://www.BarracudaNetworks.ca/spam-firewall.aspx" target="_blank" title="Barracuda Spam Firewall">anti-spam</a> solution.</p>
<p>Don’t say we didn’t warn you!</p>
<h3>Other Graphs and reports.</h3>
<p><b>MessageLabs Intelligence: January 2009</b><br />
<a href="http://www.messagelabs.com/mlireport/MLIReport_2009.01_Jan_Final.pdf" title="http://www.messagelabs.com/mlireport/MLIReport_2009.01_Jan_Final.pdf">http://www.messagelabs.com/mlireport/MLIReport_2009.01_Jan_Final.pdf</a></p>
<p><strong>Conficker</strong> botnet at 10m infections<br />
<a href="http://www.theregister.co.uk/2009/01/26/conficker_botnet/" title="http://www.theregister.co.uk/2009/01/26/conficker_botnet/">http://www.theregister.co.uk/2009/01/26/conficker_botnet/</a></p>
<p><strong>DCC</strong> e-mail and spam volume graph last 12 months.<br />
<a href="http://www.dcc-servers.net/dcc/graphs/" title="http://www.dcc-servers.net/dcc/graphs/">http://www.dcc-servers.net/dcc/graphs/</a></p>
<p><strong>SpamCop</strong> – last 12 months spam volume.<br />
<a href="http://www.spamcop.net/spamgraph.shtml?spamyear" title="http://www.spamcop.net/spamgraph.shtml?spamyear">http://www.spamcop.net/spamgraph.shtml?spamyear</a></p>
<p><strong>Barracuda Central</strong> – Spam data last 24 hours<br />
<a href="http://www.barracudacentral.org/data/spam" title="http://www.barracudacentral.org/data/spam">http://www.barracudacentral.org/data/spam</a></p>
<p><b>Shaun Sturby</b></p>
<img src="http://feeds.feedburner.com/~r/TheSpamCryer/~4/B_y_9vttyOs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/2009/01/26/are-you-ready-to-see-your-spam-volume-jump-10-times/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thespamcryer.com/2009/01/26/are-you-ready-to-see-your-spam-volume-jump-10-times/</feedburner:origLink></item>
		<item>
		<title>Don’t lose your life savings to false ‘MySpace’ friend</title>
		<link>http://feedproxy.google.com/~r/TheSpamCryer/~3/MfW8pbvhdP4/</link>
		<comments>http://www.thespamcryer.com/2009/01/16/dont-lose-your-life-savings-to-false-myspace-friend/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 21:50:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Bulletins]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[419]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=181</guid>
		<description><![CDATA[They say you can be a dog on the Internet and no one would ever know. That sad truth has bleed Shane Symington out of almost $200,000 USD (£130,000) – all of his life savings ]]></description>
			<content:encoded><![CDATA[<p>They say you can be a dog on the Internet and no one would ever know.</p>
<p>That sad truth has bled Shane Symington out of almost $200,000 USD (£130,000) – all of his life savings – in a <strong>Nigerian 419 scam </strong>where they came after him not once but <strong>twice </strong>– the second time posing as a victim of the original scam to get him to shell out money to hire ‘ex-FBI agents’ in an attempt to ‘recover’ some of the original £100,000 taken by ‘Angela Gates’.</p>
<p>I guess you can be a dog and impersonate an FBI agent on the Internet.</p>
<p><i>More information on the Daily Mail website along with pictures of ‘Angela Gates’</i><br />
<a href="http://www.dailymail.co.uk/news/article-1116067/Postman-loses-130-000-savings-Nigerian-internet-scam-duped-friend-met-MySpace.html" title="Fake Myspace Friends Story on DailyMail" target="_blank">http://www.dailymail.co.uk/news/article-1116067/Postman-loses-130-000-savings-Nigerian-internet-scam-duped-friend-met-MySpace.html</a></p>
<p>The warning to take from this is that no matter where you meet someone – in person or online – <strong>any deal that sounds too good to be true probably is</strong>.</p>
<p>-  Shaun</p>
<img src="http://feeds.feedburner.com/~r/TheSpamCryer/~4/MfW8pbvhdP4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/2009/01/16/dont-lose-your-life-savings-to-false-myspace-friend/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thespamcryer.com/2009/01/16/dont-lose-your-life-savings-to-false-myspace-friend/</feedburner:origLink></item>
		<item>
		<title>Lance Atkinson only fined $63,400 USD by New Zealand because he ‘co-operated with authorities</title>
		<link>http://feedproxy.google.com/~r/TheSpamCryer/~3/EXwoh6CHYTI/</link>
		<comments>http://www.thespamcryer.com/2008/12/23/lance-atkinson-fined/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 19:22:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Bulletins]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Lance Atkinson]]></category>
		<category><![CDATA[ROKSO]]></category>
		<category><![CDATA[Spamhaus]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=176</guid>
		<description><![CDATA[Lance Atkinson, a prolific spammer since 2005 as part of 'HerbalKing' the
'#1 worst spam gang of 2007, 2008' according to the Spamhaus ROSKO list has been fined only $92,715 AUS (about $63,400 USD) by authorities because, according to Justice Christine French of the High Court in Christchurch, of the co-operation and candor of Lance in the early stages of the investigation.]]></description>
			<content:encoded><![CDATA[<p>Lance Atkinson, a prolific spammer since 2005 as part of &#8216;HerbalKing&#8217; the &#8216;<em><strong>#1 worst spam gang of 2007, 2008&#8242; </strong></em>according to the Spamhaus ROKSO list has been fined only $92,715 AUS (about $63,400 USD) by authorities because, according to Justice Christine French of the High Court in Christchurch, of the co-operation and candor of Lance in the early stages of the investigation.</p>
<p>This is in contrast to the 2.2 Million dollar USD fine assessed against Atkinson by the FTC in 2005.</p>
<p>The Spamhaus article points out that Australia has very strict anti-spam laws<br />
(<a href="http://scaleplus.law.gov.au/html/ems/0/2003/0/2003092501.htm" target="_blank">http://scaleplus.law.gov.au/html/ems/0/2003/0/2003092501.htm</a>) and the maximum fines for a &#8216;body corporate with a prior record&#8217; could be as high as 1.1 million (AUS) or $220,000 (AUS) for &#8216;a individual with prior record&#8217;, just for sending the spam messages.</p>
<p>If you add in the maximum fines for not including accurate sender information ($550,000 corporate / $110,000 personal) for not having a functional unsubscribe facility ($550,000 corporate / $110,000 personal) and supplying, acquiring and using address-harvesting software or harvested-address lists ($550,000 corporate / $110,000 personal) these fines could have been much higher for Lance.</p>
<p>Sydney Morning Herald.<br />
<a href="http://www.smh.com.au/news/technology/security/kiwis-nail-big-time-spammer/2008/12/22/1229794316883.html" target="_blank">http://www.smh.com.au/news/technology/security/kiwis-nail-big-time-spammer/2008/12/22/1229794316883.html</a></p>
<p>Herbal King<br />
<a href="http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK7802" target="_blank">http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK7802</a></p>
<p>While this is great that Lance has been fined if we take a step back and look at the bigger picture we have to ask. If fines worked why didn&#8217;t Lance and the whole Herbal King group stop spamming in 2005?</p>
<p>While the laws applied in this particular case are very strict they have not stopped the flow of spam. It looks like one solution may be to add confinement in addition to the monetary fines for repeat spammers with additional time for repeat offences similar to how other criminals are treated.</p>
<p>While the botnets are very automated and will continue for a while after the masters are incarcerated eventually with no new commands the botnets will go dark.</p>
<p>But what do I know? Your thoughts on this issue?</p>
<p>- Shaun</p>
<img src="http://feeds.feedburner.com/~r/TheSpamCryer/~4/EXwoh6CHYTI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/2008/12/23/lance-atkinson-fined/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thespamcryer.com/2008/12/23/lance-atkinson-fined/</feedburner:origLink></item>
	</channel>
</rss>
