Endpoint Protection

 View Only

Chinese Christmas Gift Shopping Options 

Dec 16, 2009 06:09 PM

We’ve monitored a great deal of Christmas sales spam (in English) for the upcoming holiday. Compared to English holiday spam, Chinese spammers seem to have fewer activities for Christmas, most likely because it is not a major holiday in the Chinese calendar. The Christmas holiday is popular among younger Chinese generations, however, and shopping for gifts is still expected. We have observed a couple of notable Chinese samples covering the topic of Christmas shopping. In the first sample, a spammer has sent a random Christmas sales ad, and we found that the spammer purposely set the promotion text background color in gray (<FONT style="BACKGROUND-COLOR: gray" color=gray>); you have to highlight the gray line in order to see the promotion text. In the header we observed a forged and randomized “From” alias. They used a shortened URL service in the body image, which led to an actual business website.

Sample Header:
    

From: "Randomized username" < Randomized email alias>
Subject: [Details Removed]百款創意T恤聖誕禮!甜蜜送禮不煩惱!只要333元!

Translation:

Subject: [Details Removed] hundreds of creative T-shirt style for Christmas gift! Don’t worry about picking up a sweet gift! Only costs 333 dollars!

Screen shot 2009-12-16 at 10.50.48 PM.png


*Note: You can see hidden randomization and promotion text in the highlighted area.


 Screen shot 2009-12-16 at 10.51.14 PM.png


 
Body Translation:

Randomized numbers.

Taiwanese entrepreneur has set factory in mainland china, most product sales apply in China, but it also became competitive pressure in Taiwan. Taiwanese entrepreneur has set factory in mainland china, most product sales apply in China, but it also became competitive pressure in Taiwan. Taiwanese entrepreneur has set factory in mainland china, most product sales apply in China, but it also became competitive pressure in Taiwan.


--------------------------------

Below is another Chinese holiday promo sample. This spammer has randomized characters hidden in the background. You can see the randomization when you highlight the body. The Chinese promotion text line takes you to a replica product site.

Sample Header:

From: [Details Removed]  Randomization <[Details Removed] >
Subject: [Details Removed]您還在為送甚麼禮物傷腦筋嗎?? :Randomization

Translation:

Subject: [Details Removed] Are you still worried about picking up a Christmas gift?? :Randomization

Screen shot 2009-12-16 at 10.51.37 PM.png


*Note: You can see randomized characters hidden in the background when you highlight the body.


Screen shot 2009-12-16 at 10.51.59 PM.png

Body Translation:

Randomized invisible text.

Are you still worried about picking up a Christmas gift for your boyfriend/girlfriend/customer??

Randomized invisible text.

I am interested and go to

Randomized invisible text.

----------------------------------------------

These two samples both use randomization in the header and body in an attempt to bypass spam filters. The promotion is still recognizable from the body image and main advertising text. We hope users can spot spam based on our analysis above and shop carefully online. Enjoy a happy holiday!

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Related Entries and Links

No Related Resource entered.