I H8TE SPAM!
Wednesday, July 20th, 2011I’ve been thinking about, I’ve been working on an anti-spam guide for blogs and other systems. The answer is simple and can be implemented anywhere….
Do we like spam?

Guide to follow…
I’ve been thinking about, I’ve been working on an anti-spam guide for blogs and other systems. The answer is simple and can be implemented anywhere….
Do we like spam?

Guide to follow…
The F-Secure Security Labs has released information of a new Malware running around the net. The legitimate name is Trojan.Win32.Buzus.bjyo. This Trojan is currently known aas a high risk Trojan because it was recently detected (June 18th to 30th, 2009)! That means, for everyone who likes to update their malware/spyware/virus scaners once a month will not have the remedy handy for this guy. A lesson is, you should update your software before you run it every time.
The goal of this Trojan is to get you infected and here’s how it tries to do it: “There has been a couple of malware attacks that have tried to use the news coverage of the death of Michael Jackson as the lure to get people infected.
Last night we saw this one: a file called Michael-www.google.com.exe. This file was distributed through a site called photos-google.com and possibly also through photo-msn.org, facebook-photo.net and orkut-images.com. Do not visit these sites.
When executed, Michael-www.google.com.exe drops files called reptile.exe and winudp.exe. These are IRC bots with backdoor capability. The file also shows this fake error message:
Ok this ip address hits lots of blogs with hundreds of spam! You never saw it on my site because I have my settings to await moderation!.
I BLACKLISTED through my routers and website servers:
ip address: 83.233.30.32
ip address range: 83.233.30.0 - 83.233.30.255
My investigation and research tells me these addresses belong to:
SERVERCONNECT.SE
somehow affiliated with:
Labs2 Routingregistry, Sodra tullgatan 4, S-211 40 Malmoe, Sweden
phone: +46 771 518500
bredband2.se, skycom.se, labs2.com, abs2.se
WHAT THEY DID:
Enrolled to my site under the user name, 83.233.30.32 and attempt to SPAM my servers with HUNDREDS of messages about Viagra, male enhancement and other sexual content.