Mar 19 2008
The RBN Antivirus Trophy
I received a couple of the following message today. The greeting differs, but the basic text (other than the randomized bits at the end) is the same:
Ahn nyeong, +-------------------------------------------+ Warning! This letter contains a virus which has been successfully detected and cured. We strongly recommend deleting this letter and avoid clicking any links. +-------------------------------------------+ [RBN Networks Antivirus] Days after the interview with mrs. Hammond, found born under a mad moon with some wild humor in hari as deserving of the first worship. Amongst a member or otherwise. The neighboring church gratified with dharma's son yudhishthira, imparted opere miror) would not eulogise himself quite couldn't have done any rupert was not given to intelligence, while they were being thus smitten to live deprived of thy company. o king, if thou the king of rakshasas, that descendant of ikshwaku's of the last word of the last line of the last of great strength, and accordingly pursued with them talking to each other in the dew. A galaxy also handed him a note that he had written toof will be theirs? I do not seek the accomplishment.
What makes it interesting is the hidden code at the end of the HTML version of the spam message:
in the dew. A galaxy also handed him a note<br> that he had written toof= will be theirs? I do not seek the<br> accomplishment.</p> <a href=3D"http://aaaahosting.com/.xkhafeedmaaabgehd.php"></a></body></html> ------------CFA6ED93730CD2--
online pharmacycialislevitrapropeciaviagra
I’m not sure what the goal of it is, but something is probably meant to have lurked behind the link. I just got a Page Not Found, so either it’s got some logic to tell whether a Windows machine is hitting it, or someone had already sanitized it. I changed the link before pasting it here, so clicking it yourself won’t help.
Other news: I played around with relay_recipient_maps today in postfix. They’re a nice way to move the bounces to the edge of my infrastructure, but I don’t know if they’re worth the work on a big scale. It seems even Google has decided for backscatter these days. I’m probably better off writing blocking rules for stuff like the RBN message.

