These spam messages appear to be promoting the underground websites
kidala.info and
hack-sell.su, both of which appear to be engaged in hacking, crimeware and fraud. But is there something else going on here?
Date: Tue, 2 Apr 2013 18:07:48 +0700 [07:07:48 EDT]
Subject: Russian hackers has you neo!
Russian hackers has you neo!
kidala dot info
or this kidala.info
==========================
Date: Tue, 2 Apr 2013 17:17:29 +0700 [06:17:29 EDT]
Subject: Russian hackers has you neo!
Need buy some shells?
http://kidala.info
==========================
Date: Tue, 2 Apr 2013 16:27:24 +0700 [05:27:24 EDT]
Subject: Russian hackers has anything you need.
World Best hack conference hereurl here: kidala.info
==========================
Date: Tue, 2 Apr 2013 12:30:09 +0530 [03:00:09 EDT]
Subject: World Interesting hack site here
Hi Manurl here: http://hack-sell.su
==========================
Date: Tue, 2 Apr 2013 02:58:24 +0200 [04/01/13 20:58:24 EDT]
Subject: Russian hackers mafia OWNS YOU!
Russian mafia has you...
hack-sell.su
or this hack-sell dot su
==========================
Subject: Russian bad boys forum here, come join!
World baddest hackers join us hereurl here: hack-sell .su
==========================
Date: Mon, 1 Apr 2013 16:01:59 -0400 [04/01/13 16:01:59 EDT]
Subject: Russian hackers has anything you need.
Prime hack portal here!
hack-sell dot su
or this hack-sell dot su
(Note that the emails may appear to be "from" your own account or someone in your own organisation. Don't worry, you have not been hacked.. forging an email address is trivially easy (described here).
But there's something unusual because these spams are being sent repeatedly to SpamCop.net email addresses, and I haven't seen them anywhere else. So why send spam emails to people who are very likely to file an abuse complaint.. unless you
want the recipient to file an abuse complaint, that is.
This sort of attack pattern looks like a
Joe Job, perhaps from a rival to these two underground forums. Targeting addresses that will likely file a complaint is a sort of reverse
listwashing, and the pattern of repeated emails to the same address is also a Joe Job characteristic. And the thing about underground forums.. well, they don't tend to spam at all because they like to remain under the radar.
The sites don't appear to be hosting malware, if you've accidentally clicked through then there you are probably OK, although both sites look like they are down at the moment. There may well be more Joe Jobs after this one though, so don't be surprised if more rubbish floods your inbox.
Update: these subject lines are in use at the moment..
Best crack phorum so far!
Best hack conference so far!
Need buy some abuseimmune servers?
Need buy some injects?
Need buy some loads?
Need buy some socks?
Need buy some traffic?
Russian bad boys forum here, come join!
Russian hackers has anything you need.
Russian hackers has you neo!
Russian mafia has you...
Russian hackers mafia OWNS YOU!
Superior crack site so far!
World baddest hackers join us here
World Best hack website here
World Superior hack conference here