Re: [Asrg] 2. Spam Analysis - Vectors

Raymond S Brand <rsbx@rsbx.net> Fri, 22 August 2003 01:20 UTC

Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA12819 for <asrg-archive@odin.ietf.org>; Thu, 21 Aug 2003 21:20:57 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19q0bL-0003Of-4t for asrg-archive@odin.ietf.org; Thu, 21 Aug 2003 21:20:32 -0400
Received: (from exim@localhost) by www1.ietf.org (8.12.8/8.12.8/Submit) id h7M1KRpJ013051 for asrg-archive@odin.ietf.org; Thu, 21 Aug 2003 21:20:27 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19q0bL-0003OQ-0f for asrg-web-archive@optimus.ietf.org; Thu, 21 Aug 2003 21:20:27 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA12773; Thu, 21 Aug 2003 21:20:21 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19q0bI-0004Wo-00; Thu, 21 Aug 2003 21:20:24 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19q0bH-0004Wl-00; Thu, 21 Aug 2003 21:20:23 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19q0Zx-0003Jg-D6; Thu, 21 Aug 2003 21:19:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19q0ZA-0003Iy-BY for asrg@optimus.ietf.org; Thu, 21 Aug 2003 21:18:12 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA12682 for <asrg@ietf.org>; Thu, 21 Aug 2003 21:18:06 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19q0Z7-0004Vw-00 for asrg@ietf.org; Thu, 21 Aug 2003 21:18:09 -0400
Received: from 226.48.93.66.in-addr.rsbx.net ([66.93.48.226] helo=mail.rsbx.net) by ietf-mx with esmtp (Exim 4.12) id 19q0Z6-0004VW-00 for asrg@ietf.org; Thu, 21 Aug 2003 21:18:08 -0400
Received: from rsbx.net (localhost [127.0.0.1]) by mail.rsbx.net (8.9.3p2/8.9.3) with ESMTP id VAA03678 for <asrg@ietf.org>; Thu, 21 Aug 2003 21:17:50 -0400
Message-ID: <3F456F3A.497AE724@rsbx.net>
From: Raymond S Brand <rsbx@rsbx.net>
X-Mailer: Mozilla 4.76 [en] (X11; U; Linux 2.2.17.crypt i686)
X-Accept-Language: en
MIME-Version: 1.0
To: asrg@ietf.org
Subject: Re: [Asrg] 2. Spam Analysis - Vectors
References: <6.0.0.14.0.20030821190428.02731788@solidmatrix.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/mail-archive/working-groups/asrg/>
Date: Thu, 21 Aug 2003 21:17:46 -0400
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

Yakov Shafranovich wrote:
> 
> There is an interesting story from Reuters
> (http://www.reuters.com/newsArticle.jhtml?type=technologyNews&storyID=3315668)
> about the possible motive behind Sobig.F virus - spam. Here are some quotes:
> 
> ----------snip---------
> Sobig.F drops software onto infected Windows computers that open them to be
> used later for distributing Internet spam -- unwanted e-mails and product
> promotions, experts said. It also represents a new trend in converging
> e-mail spamming and virus software writing, they said.
> 
> "We believe (Sobig.F) has been written by a spammer or spammers" looking
> for ways to get past spam filters, said Mikko Hypponen, manager of
> anti-virus research for Finnish security firm F-Secure. "For once, we have
> a clear motive for a virus -- money."
> ----------snip---------
> 
> This raises the issue of infected computers used for spam and how to deal
> with them once again.

DRIP? http://www.ietf.org/internet-drafts/draft-brand-drip-01.txt


Raymond S Brand

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg