The Next Evolution – GFI Uncovers MP3 Spam

The New Acunetix V12 Engine


If you remember a while back we mentioned PDF & Image Attachment Spam – The New Problem with E-mail, now we have another ‘innovation’ in spamming..

MP3 spam!

It seems they are using it for the same old pump and dump tactics (Microcap stock fraud) to artificially inflate stock prices then sell out fast.

Spammers are back with a new trick, this time round sending messages with MP3 attachments that contain the latest pump-and-dump stock scams.

One sample identified this morning by GFI, was a heavily distorted 30-second MP3 file. A synthetic female voice was used to promote a particular stock. This voice is distorted to avoid filtering approaches based on the file signature.


Once again, spammers are taking advantage of the fact that the MP3 format is one of the most common in use today, another attempt at social engineering.

I wonder what they are going to come out with next, really?

The spam is a short, 30-second MP3 file recorded at low bit-rate with a synthetic female voice promoting a particular stock; the voice heavily distorted to avoid signature-based anti-spam approaches (click here [MP3] to listen to an edited sample of MP3 spam).

“MP3 spam is a natural progression from PDF and Excel spam whereby spammers are exploiting a new file format to be able to send spam. This is their latest attempt to evade anti-spam filters. There is also a social engineering aspect to this tactic because people frequently share MP3 files,” David Vella, Director of Product Management, said.

Another thing to look out for anyway, perhaps start filtering mp3 attachments on the mail gateway, then they’ll start putting them in passworded zip files I guess..

Source: GFI

Posted in: Advertorial, Phishing, Spammers & Scammers

, , , , , ,


Latest Posts:


dcipher - Online Hash Cracking Using Rainbow & Lookup Tables dcipher – Online Hash Cracking Using Rainbow & Lookup Tables
dcipher is a JavaScript-based online hash cracking tool to decipher hashes using online rainbow & lookup table attack services.
HTTP Security Considerations - An Introduction To HTTP Basics HTTP Security Considerations – An Introduction To HTTP Basics
HTTP is ubiquitous now with pretty much everything being powered by an API, a web application or some kind of cloud-based HTTP driven infrastructure. With that HTTP Security becomes paramount and to secure HTTP you have to understand it.
Cangibrina - Admin Dashboard Finder Tool Cangibrina – Admin Dashboard Finder Tool
Cangibrina is a Python-based multi platform admin dashboard finder tool which aims to obtain the location of website dashboards by using brute-force, wordlists etc.
Enumall - Subdomain Discovery Using Recon-ng & AltDNS Enumall – Subdomain Discovery Using Recon-ng & AltDNS
Enumall is a Python-based tool that helps you do subdomain discovery using only one command by combining the abilities of Recon-ng and AltDNS.
RidRelay - SMB Relay Attack For Username Enumeration RidRelay – SMB Relay Attack For Username Enumeration
RidRelay is a Python-based tool to enumerate usernames on a domain where you have no credentials by using a SMB Relay Attack with low privileges.
NetBScanner - NetBIOS Network Scanner NetBScanner – NetBIOS Network Scanner
NetBScanner is a NetBIOS network scanner tool that scans all computers in the IP addresses range you choose, using the NetBIOS protocol.


4 Responses to The Next Evolution – GFI Uncovers MP3 Spam

  1. Sandeep Nain October 24, 2007 at 10:49 am #

    uffff…. now its gonna be a headache to actually identify the legitimate emails… I usually ask my frnds to send me mp3 files through emails and wont expect it to be banned :( by my sys admin

    whats next???? probably emails containing small video clips…

  2. Derek R October 24, 2007 at 1:20 pm #

    This is also being used by the storm worm variants in an attempt to get the user to visit a infected website. Only education of users is going to stop some of these techniques from working. Chasing spammer’s methods is a futile attempt.

  3. Bogwitch October 24, 2007 at 6:57 pm #

    I’ve received one of these, nearly 60k in size is going to make it difficult to really get the widest distribution possible. Also, the quality of the mp3 is abysmal, virtually unintelligible.
    I can’t see this lasting long, BICBW!

  4. fazed October 30, 2007 at 5:15 pm #

    yay :S
    maybe we should just block .mp3 extensions..
    unless your a record label or something you don’t
    usually recieve mp3 via email, most voice is recorded
    in .wav (windows <= XP) and .wma (Windows vista)
    the only real use for recieving mp3’s through email
    is if your signed up for pirate radio news letters..