Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cloud
    • Cybersecurity
    • Networking

    Spammers Using Own URL-Shortening Services for Pharmacy Spam

    Written by

    Fahmida Y. Rashid
    Published October 27, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Spammers have found a way to circumvent security measures at URL-shortening Websites that detect and remove malicious links. They are creating their own services on the .info domain, Symantec researchers found.

      Symantec has identified more than 80 sites set up by spammers to shorten Website addresses, according to its latest “Intelligence Report” released Oct. 25. The services have been built using an open-source URL-shortening script that is publicly available.

      Shortened URLs pose a security risk since users can’t tell if the link they are clicking on would direct them to a legitimate site or a malicious one. Besides the well-known sites such as bit.ly, many companies have launched their own URL shorteners, making it a challenge for users to keep track of the various services.

      Sites like Twitter, which impose a character limit on what users post, have made these services popular, making it even more likely that users will click on a link without stopping to thinking about its potential destination. Most services would disable a link once notified that it was malicious, and Twitter has introduced its own shortening service, which checks the actual Website to see if it is potentially dangerous or included on various blacklists before generating a link.

      “It is possible that spammers are setting up their own URL-shortening sites since legitimate URL-shortening sites, [which] have long suffered with abuse, have slightly improved their detection of spam and other malicious URLs,” Symantec researchers wrote in the October “Intelligence Report.”

      All the Websites identified by Symantec so far appear to be hosted on several different IP addresses owned by a United Kingdom-based subsidiary of a large hosting company, which Symantec declined to name. All the domain names followed a similar naming pattern and were registered with contact information in Russia.

      At the moment, the shortened links from these services appear to be included only in pharmaceutical spam. The subject lines vary, or may even be blank, but the message body generally always contained a shortened link generated by the spammer’s service. The link would then direct users to a pharmaceutical spam site, according to Symantec.

      This new tactic is most likely in response to vast improvements in spam detection by popular URL-shortening sites. This was “yet another example” of cyber-criminals adopting new technology to bypass traditional security measures, Bradley Anstis, vice-president of technical strategy at M86, told eWEEK.

      Spammers have switched to putting in shortened links, either generated by malicious or legitimate services, in spam messages to bypass anti-spam filters, which may have difficulty detecting which of the links are actually dangerous, according to Anstis.

      “A lot of the traditional anti-spam engines were developed before Twitter, so they are not geared up to recognize embedded URLs as seen in blended email threats in spam, let alone shortened URLs that link to malicious, or compromised Web pages,” Anstis said.

      Despite these new tactics, spam levels have been declining. Symantec reported in its monthly report that the global ratio of spam in email traffic was 74 percent, or one in 1.35 messages, a 0.6 percent dip since September. Nearly one in 236 emails contained malware, a 0.11 percent decline since last month, but phishing attempts were slightly up (about 0.07 percent), to one in 343 emails.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.