« Zheng Technology update
Paperghost gets angry at ex-Direct Revenue employees’ comments »

Strange e-mail

January 15th, 2009

Yesterday, whilst perusing one of our spam traps, I came across a strange email. The body of it consisted of this:

“hey
call me when you get this mail.
I can not reach you.

bye”

No request to send money to the prince of Nigeria, no offer to purchase breast implants (they never seem to get the gender right!) or fake Rolexes, just that cryptic request to call. Some web research produced very little hits. After some cogitating, I’ve come to the conclusion that this is a form of “list validation” that relies on social engineering.

The spammers have a list. They want to see which email addresses are used, and current. They send this weird email to the whole list. Some of the recipients reply asking something along the lines of: “Who is this?”

Now the spammers have a much smaller targeted list of live targets, distilled from the original list.
That list is much more likely to yield better results. The spammers then mount a new campaign, this one only sending emails to the people who replied, knowing that the list they are using has been validated.

This is the only valid explanation I can come up with for this strange email. When I researched the “from” field in this email, I received confirmation that many other people had received the same e-mail.

Pretty smart.

The lesson to take away from this is not to reply to strange email from unknown people, even if the social engineering aspect is very strong. (unknown woman asking you to call…)

Hey, at least they got the gender right this time…

Addendum:

I further discussed this tactic with Co-workers, who happen to read our blog, and I have come to the conclusion that this “validation” technique is more effective against males.
Random email from unknown woman = I wonder who this could be?
Random email from some guy = creepy!

Jean “TinFoilHatMan” Taggart

    This entry was posted on Thursday, January 15th, 2009 at 11:07 am and is filed under Research. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.