Help Understanding Spammer's Aim

Discussion in 'other security issues & news' started by baumgrenze, Sep 10, 2012.

Thread Status:
Not open for further replies.
  1. baumgrenze

    baumgrenze Registered Member

    Joined:
    Feb 24, 2005
    Posts:
    12
    Below I will post the "View Source" of a spam message. Viewed normally, it shows no subject line and the body only contains a putative link. I've gotten 4, 2 with the same link and 2 others (and 2 with slightly more complex messages, but ones where the root link appears to be fully legitimate. In all cases, the apparent link in the message and the link in the "View Source" appear identical, the real link is not a redirect of what is seen in the message body. All have allegedly been sent from a friend's aol email account. Here are the messages:

    -www.stimulusgrantoffer.com-

    -www.ewebinarmeeting.com-

    -www.seizedvehiclesonline.org-

    -www.ewebinarmeeting.com-

    I could barely afford groceries anymore everyone was worried that I would amount to nothing I thought this would intrigue you.
    -http://srvmanagementservices.com/RichardSullivan22.html- this is proof that miracles do exist think about it

    lately ive been distancing myself from everyone despite the circumstances I remained hopeful because of this im always one step ahead.
    -http://www.1001annonces.com/1/redir.php?vomyzag=msn.com&kefimo=mail.com&u=the-career-news.net/esubmit/bizopp_main.php- this is proof that miracles do come true its so easy to learn
    You owe me one!

    What is this spammer attempting to accomplish? If I open the link is he informed that mine is an email address worth harvesting?

    View Source

    Code:
    From - Mon Sep 10 12:59:13 2012
    X-Account-Key: account2
    X-UIDL: 11e1-fb7c-e56c3130-915d-002128140a66
    X-Mozilla-Status: 0001
    X-Mozilla-Status2: 00000000
    X-Mozilla-Keys:                                                                                 
    Status:  U
    Return-Path: <-redacted->
    Received: from mx-pigeons.atl.sa.earthlink.net ([207.69.195.28])
    	by mdl-quaff.atl.sa.earthlink.net (EarthLink SMTP Server) with SMTP id 1tb9zd3zY3Nl3421; Mon, 10 Sep 2012 15:22:43 -0400 (EDT)
    Received: from oms-mc01.r1000.mx.aol.com ([64.12.81.66])
    	by mx-pigeons.atl.sa.earthlink.net (EarthLink SMTP Server) with ESMTP id 1tb9zd6N3Nl34g0
    	for <-redacted->; Mon, 10 Sep 2012 15:22:43 -0400 (EDT)
    Received: from mtaout-db02.r1000.mx.aol.com (mtaout-db02.r1000.mx.aol.com [172.29.51.194])
    	by oms-mc01.r1000.mx.aol.com (AOL Outbound OMS Interface) with ESMTP id 24ABA380001B1
    	for <-redacted->; Mon, 10 Sep 2012 15:22:43 -0400 (EDT)
    Received: from -www.cassinohotel.com- (100.254.93.77.host.static.ip.kpnqwest.it [77.93.254.100])
    	by mtaout-db02.r1000.mx.aol.com (MUA/Third Party Client Interface) with ESMTPA id 77120E0000A4
    	for <-redacted->; Mon, 10 Sep 2012 15:22:42 -0400 (EDT)
    Date: Mon, 10 Sep 2012 21:21:46 +0200
    To: -redacted-
    From: -redacted-
    Reply-to: -redacted-
    Subject: 
    Message-ID: <af6e713b37cff379dcf1b83840ae594b@www.cassinohotel.com>
    X-Priority: 3
    X-Mailer: PHPMailer 5.2 (-http://code.google.com/a/apache-extras.org/p/phpmailer/-)
    MIME-Version: 1.0
    Content-Type: multipart/alternative;
    	boundary="b1_af6e713b37cff379dcf1b83840ae594b"
    x-aol-global-disposition: S
    X-SPAM-FLAG: YES
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mx.aol.com;
    	s=20110426; t=1347304963;
    	bh=0RTw8GG3hgpOhdB7y8KQAATIiHCjFddCkIq8qz26P9M=;
    	h=From:To:Subject:Message-ID:Date:MIME-Version:Content-Type;
    	b=mroUHKldPJWOfge2+6sSwG+GenTXmWkc7YbYQZ9fL5gKX4TY4Wf/vNv76ZvM5qWuw
    	 zD9JBsochaE5UasxqQDsb4gIyMjZkhdU/OyPhW3nqAq2OZ1eHp2j9amWlauyBzOZtI
    	 BE09Ni3SmPQFIYUcga9MAXadESu0UIny3LGRmadY=
    X-AOL-SCOLL-SCORE: 0:5:62070456:93952408  
    X-AOL-SCOLL-URL_COUNT: 0  
    X-AOL-REROUTE: YES 
    x-aol-sid: 3039ac1d33c2504e3e026c28
    X-AOL-IP: 77.93.254.100
    X-ELNK-Received-Info: spv=1;
    X-ELNK-AV: 0
    X-Antivirus: avast! (VPS 120910-0, 09/10/2012), Inbound message
    X-Antivirus-Status: Clean
    
    
    --b1_af6e713b37cff379dcf1b83840ae594b
    Content-Type: text/plain; charset="iso-8859-1"
    Content-Transfer-Encoding: 8bit
    
    -www.stimulusgrantoffer.com-
    
    
    --b1_af6e713b37cff379dcf1b83840ae594b
    Content-Type: text/html; charset="iso-8859-1"
    Content-Transfer-Encoding: 8bit
    
    <p><a href="http://www.stimulusgrantoffer.com">www.stimulusgrantoffer.com</a></p>
    
    
    
    --b1_af6e713b37cff379dcf1b83840ae594b--

    thanks,

    baumgrenze
     
    Last edited by a moderator: Sep 10, 2012
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.