Well now that the election is over I’m already getting spam to watch an “amazing viedo of Barack Obama”. No clever tricks here just the old “click on this link”. The link is not masked in any way, just points to a url a person would not identify with anything. An example of the email content is:
From: "Elections center" Subject: USA Election Results Barack Obama Elected 44th President of United States Barack Obama, unknown to most Americans just four years ago, will become the 44th president and the first African-American president of the United States. Watch His amazing speech at November 5! Proceed to the election results news page>> 2008 American Government Official Website This site delivers information about current U.S. Foreign policy and about American life and culture.
If you get one of these pay attention to the link, viewing source is actually a better way to tell. The url your taken to when clicking on “Proceed to the election results news page>>”, which you should NOT do, is associated with wconlinenrue.com. If we check the registration info for that domain we can see it’s not legit.
Domain Name: WCONLINENRUE.COM Registrar: BIZCN.COM, INC. Whois Server: whois.bizcn.com Referral URL: http://www.bizcn.com Name Server: NS1.SPRITSONLINE.NET Name Server: NS2.SPRITSONLINE.NET Status: clientDeleteProhibited Status: clientTransferProhibited Updated Date: 04-nov-2008 Creation Date: 04-nov-2008 Expiration Date: 04-nov-2009
A little to obvious, the domain was created yesterday and will expire next year. If we check Spam Trackers we find a wiki entry for bizcn and if we go to the Uribi Blacklist for bizcn we find wconlinenrue number 2 on the list. At least that is as of my typing this.
So if your spam filter doesn’t catch these delete them, better yet don’t open an email if you don’t recognize the sender. If you do recognize the sender pay attention to the links you will be clicking on.
Update: since typing this just 20 minutes ago I’ve gotton a few more emails but with a different domain, lopbiuemis.com. In all cases though the body of the message was the same as above. No doubt their will be many domains associated with the links.