| View previous topic :: View next topic |
| Author |
Message |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2884
|
Posted: Fri May 02, 2008 9:53 pm Post subject: Evidence Required |
|
|
A request for evidence from law enforcement. Perhaps Knujon may have some examples in their archives
Herbal King Spam from your archives?
Do you have any samples of spam sent to Hong Kong
(with a ".hk address). I only need approx 10 samples in total of
Herbal King Spam sent from 12 October 2007 to 16 December 2007.
Full headers please, unobfuscated. They will not be published electronically, just produced in court evidence.
|
|
| Back to top |
|
 |
ahoier
SIRT Handler
 Joined: Jan 14, 2006 Posts: 1033 Location: USA
|
Posted: Sat May 03, 2008 5:07 am Post subject: |
|
|
May want to try the contact at knujon address, Knujon doesn't appear too active on the forums as of late....but I'm sure they could come up with some samples. 
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2705
|
Posted: Wed May 07, 2008 8:58 pm Post subject: |
|
|
| ahoier wrote: | May want to try the contact at knujon address, Knujon doesn't appear too active on the forums as of late....but I'm sure they could come up with some samples.  |
...only if Knujon has participants with "@domain.hk" email addresses. There are lots of spamtraps, but the .hk address is the element that may not be so easy to come up with after the fact.
|
|
| Back to top |
|
 |
Knujon
Captain
 Premium Member
 Joined: May 25, 2006 Posts: 585 Location: USA
|
Posted: Wed May 21, 2008 2:04 pm Post subject: |
|
|
Here's the problem with the herbal king. We've got lots of data on them but my guess is that they are distributed and deployed by kits. What we have may not match the specific incident in question. This situation requires some higher level planning and coordination since the whole picture is going to stretch across jurisdictions.
|
|
| Back to top |
|
 |
ahoier
SIRT Handler
 Joined: Jan 14, 2006 Posts: 1033 Location: USA
|
Posted: Wed May 21, 2008 3:33 pm Post subject: |
|
|
As AC rephrased, samples of Herbal King spam sent to .hk (hong kong) addresses is what's requested
Now.....I can understand, with all the data you guys are processing, pin-pointing ALL spam that contains a .hk address in the To: or Delivered-To area of the headers, could take a long time, depending on how advanced your search/data queries can be.
And even then, how would that affect evidence if a .hk address was forged/munged into the To:
If your system isn't this advanced, to create a query, and display the results of something like this, perhaps it might be something to look into expanding on, as I feel it could greatly help.
Overall, I don't think the problem here is anything with jurisdictions. But perhaps could lead to a greater investigation if evidence that matches this criteria has been submitted 
|
|
| Back to top |
|
 |
Knujon
Captain
 Premium Member
 Joined: May 25, 2006 Posts: 585 Location: USA
|
Posted: Wed May 21, 2008 3:40 pm Post subject: |
|
|
We looked, we can find things pretty quickly. The issue is that herbal king is a moving target with lots of affiliates. The whole things needs to be taken out at the same time.
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2705
|
Posted: Wed May 21, 2008 3:47 pm Post subject: |
|
|
Red's not looking for things mailed from Hong Kong, just things with a recipient who is a resident of Hong Kong (or uses a HK mail service). It doesn't matter which affiliates, as we aren't being told whose head is in the noose yet.
All you need to filter is the "To" line, which isn't going to be forged like a "From" line. It all depends whether you have any submitters in Hong Kong -- if so, you'll have a lot of Elite Herbal spam, if you don't have a submitter in HK, you won't have any of their spam mailed to HK.
|
|
| Back to top |
|
 |
Knujon
Captain
 Premium Member
 Joined: May 25, 2006 Posts: 585 Location: USA
|
Posted: Wed May 21, 2008 3:57 pm Post subject: |
|
|
Understood, I believe that is the case since we don't have any .hk clients.
|
|
| Back to top |
|
 |
ahoier
SIRT Handler
 Joined: Jan 14, 2006 Posts: 1033 Location: USA
|
|
| Back to top |
|
 |
|
|