
Cutting Edge Spam Elimination
SpamButcher is a spam email program that works by evaluating the content of each message before you download it into you email client. Messages that have content suggesting they are unsolicited are relocated to a holding area for your review.
Free Anti-Spam Download - Click Here!
More Spammers Jump on the PDF Spam Bandwagon
07/07/07
As reported earlier, a new wave of spam is invading inboxes throughout the globe. In these messages the content the spammer wants to deliver is embedded within a PDF file.
Often the messages contain no text at all. Other times it may include a short segment of what appear to be randomly generated words. More recently messages containing a "teaser" in an effort to get the user to open the PDF file have appeared.
Placing message content inside a PDF file offers many advantages to spammers. Almost all of them are related to, "deliverability" or the prospect of the message being delivered as opposed to being deleted by a program designed to filter spam in Outlook.
PDF files are commonly used in business and are frequently attached to emails. A business user may see a message with an attached PDF and assume it contains an important business document - because they often do.
Most programs intended to deal with unwanted email don't see a message containing a PDF as being any more likely to be junk. It's not practical to just block all messages with attached PDF files.
PDF files can contain images or text embedded within images. Because of this, all the standard ploys using images to hide text from spam filters work just as well with PDF files.
Even many of the best anti-spam programs lack optical character recognition (OCR) technology. The ones that have it likely don't know how to look inside PDF files for potentially offending content.
In fact, it seems that text stored inside a PDF file can be encoded. This means that even without special obfuscation efforts, most PDF files pass through antispam systems unexamined.
Alarmingly, the trend seems to be spreading. Up until now - all the PDF spam we've encountered at SpamButcher has been related to promoting certain stocks. These emails clearly were sent by the same individual or organization as they all contained a readily identifiable, "signature." We developed new routines within SpamButcher to detect and delete such messages.
Yesterday we received a PDF spam email that promoted certain "performance enhancement" products. The message clearly had no relation to the previously identified campaign. As a result, the new routines we developed to cope with the first campaign didn't work. SpamButcher's development team is investigating what steps to take next.
Back
|