Feeds

Return of MP3 spam punts penis pill sites

When Harry Met Spammy

Top 5 reasons to deploy VMware with Tegile

MP3 spam has made an unwelcome return, two years after the tactic was first used to spamvertise products and services.

The audio track file type briefly appeared in junk mail messages in October 2007 to tout pump and dump stock scams, before quickly dying out. Now junk MP3s have begun reappearing in messages touting Canadian Pharmacy websites, mail security services outfit MessageLabs reports.

When audio file spam first appeared it looked as if junk mailers were exploring the use of new attachment types in a bid to keep their junk mail output varied and shifting. PDF spam, for example, made its first appearance later in 2007 and has hung around ever since.

MP3 spam was more like a failed experiment, a demo tape that no-one cares to remember, so its reappearance two years on is a bit of a puzzler. Spammers have moved towards using a hyperlink that leads to spammers' websites more than any kind of attachment, much less a bulky audio file.

A recent MP3 spam run intercepted by MessageLabs features a voice-synthesized MP3 clip - just five seconds long - giving the name of a site flogging Viagra. Adding spice to the mix, spammers have added an imitation of Meg Ryan's infamous coffee-shop scene in When Harry Met Sally in the background.

The MP3 filenames are seemingly changed for each message... but the properties of the files reveal that the title of each MP3 recording is the same, "WWW.77557.NET - CHEAP VIAGRA".

The latest MP3 spam run features random characters in the lyrics tag, possibly so that each file is slightly different, in a possible attempt to bypass rudimentary signature based spam detection based on noting MD5 file hashes.

The unidentified spammers behind the MP3 run are not without a sense of humour. "The "Genre" of the MP3 recording is set to "Blues," presumably in a reference to the famous blue pill the spammers were touting," MessageLabs adds.

The MP3 spam run began on the afternoon of 16 December 2009 and ended by mid-morning on 17 December, it accounted for 1.2 per cent of all spam during its overnight peak. MessagLabs reckons as many as 500 million MP3 spam messages were distributed during the run.

"This could be the most frequently "downloaded" MP3 track in the world... whether its recipients want it or not," MessageLabs adds.

The MP3 spam was sent out from machines compromised by the "Climbot" botnet – estimated to be between 10,000 and 20,000 zombie PCs strong - a week after an image spam run, also touting penis pill sites. Climbot, whose zombie machines tend to be located in either continental Europe or South Korea, was last active as a source of spam back in June.

A write-up of the return of MP3 spam, containing audio clips (NSFW), can be found on MessageLabs website here. ®

Internet Security Threat Report 2014

More from The Register

next story
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
BitTorrent's peer-to-peer chat app Bleep goes live as public alpha
A good day for privacy as invisble.im also reveals its approach to untraceable chats
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.