Sample spam template

Most high-volume spam is sent using a tool that randomizes parts of the message - subject, body, sender address etc. From time to time, you'll see a run of messages in which the spammer has made a configuration error, so the subject appears as $RAND_SUBJ instead of whatever the spammer intended. You can also often guess the general form of the template that the spammer is using by inspecting a number of messages.

I hadn't previously seen an entire spam template before, though, so I thought it was interesting enough to share this one, which a spammer inadvertently sent out. It's nothing you couldn't have guessed, but here it is. Note that even the hashbuster text is generated from a fairly small set of options.

{%Canadian|CANADIAN%} {%drugs|meds|health treatments|health remedy's|treatments|health drugs%}...the {%only|simply|merely|purely|easily|straightforward|clearly|obviously%} {%way|path|route|approach|method|mode%} to {%go|buy|acquire|get|purchase%}

www.enjoy-touched-month.cn

"Ah, {%made|dust|board|scorch|receipt|tail|commercial|debt|comparison%} {%strap|language|trade|cart|thundering|stuck|inquisitively|tactic|hand%} your {%grip|plate|inquisitive|steer|splendid|promptly|needle|shoe|drink%} excellency, I am {%ball|post|opinion|library|lighten|cow|letter|weak%} overwhelmed with deligh
"Yes."

Update: 02 February 2009 - a reader comments:

That's a DarkMailer template. It's also promoting "Discount Pharmacy", which is hosted using hijacked Windows 2000 or Windows 2003 servers. (In this case it's Windows2003 Standard Edition, a server named "COFFEEBEAN")

In fact, the advertised domain is hosted on not one but six servers, scattered all over the world — Russia, Mexico, Korea, Puerto Rico and the United States, all apparently belonging to different organizations. Some — probably all — of these servers also do double duty as name servers.

Tags: , , , , ,


weblognewsstocksstatstoolsnoteslinksmisc