Monday 17 September 2012

Spam with numbers and "hi" in it..

There seems to be a lot of this about today..

Date:      Mon, 17 Sep 2012 08:39:16 -0300
Subject:      Re: 89898877282500

The numbers vary in each email, from single digits to quite long sequences. The body text is always "Hi", nothing appears to be hidden or malicious in any way. One characteristic is that the recipient is not usually the one in the "To" field as the spam is using the BCC field to suppress recipients.

The emails are not harmful, but obviously there is something going on. One possibility is that this is a probing attack, where an outside source is attempting to enumerate live mailboxes or collate server responses for further use. A short email like this will get passed through many spam filters, so (for example) it could be that the attacker is looking for SMTP responses that indicate a real mailbox to spam again later rather than a dead one.

If you have any other ideas, then please share them in the Comments :)

