Too Much Free Time

Too Much Free Time

by Mike Masnick




Bunkum Splotched, Spatula Seethed And The Creativity Of Spammer Naming

from the it's-that-time-of-the-year dept

Yes, we're reaching that time of the year when the news slows down and we get a combination of predictions (again?) and bizarre filler stories. Count this next one among the latter. Jack Kapica of the Globe and Mail apparently has been keeping track of the bizarre (yet creative) names that spammers choose in emailing him. If you've never noticed, it seems that spammers tend to come up with some of the most bizarre names: "Ovaries Secreter, Emm Zcacsog, Bella Pxolc, Candida Outlaw, Capote Dogie, Macon Expel, Exhibitionism Phoneys, Tillman Unscrew, Nuptials Overgenerous, Letdowns Gastritis, Dionysius Swindall, Slugged Shindig, Concessions Burgles, Fikriyya Gurney and Shea Snay." It makes you wonder why they bother. Do these names get through spam filters better? Are they more convincing to make people buy from them? Or are the spammers just bored out of their minds, and this is an outlet? Or, most likely of all, they just use some program to grab two words at random off the internet somewhere.

7 Comments | Leave a Comment..

 
 

Reader Comments

(Flattened / Threaded)

  • Dec 21st, 2005 @ 10:03pm

    Spammers suck...

    by Mark Shanson

    ...and they should be beaten inside a burlap bag xD

    Seriously though, before I started using GMail, I used HoTMaiL. Every single day I'd clear out at least 10-20 spam emails. Even AFTER I'd check them as spam, they would STILL get through. I'm sure M$ sells @hotmail.com accounts to spammers. I'm never using hotmail again...(well, except for my X360 account...)

    (reply to this comment) (link to this comment)

  • Dec 22nd, 2005 @ 7:02am

    Spam filters

    by Bernard

    My understanding is that spammers use these random words to defeat the spam filters by diluting the "spam" keywords that may trigger the filter with a bunch of essentially white noise.

    (reply to this comment) (link to this comment)

  • Dec 22nd, 2005 @ 7:05am

    No Subject Given

    i got some spam from "monkey sex" once. that made my day.

    (reply to this comment) (link to this comment)

  • Dec 22nd, 2005 @ 7:07am

    Looks familiar

    by WollyHood

    We should all remember playing the two word juxtaposition game before. Apparently the spammers have gotten hold of the random password engine that generated the wonderful binymials found in everyone's favorite real world spam, the AOL mailings. Think AOL will to sue over the trademark infringement?

    (reply to this comment) (link to this comment)

  • Dec 22nd, 2005 @ 11:20am

    No Subject Given

    by haggie

    I'll stick with the classics: Craven Moorehead, Heywood Giblome, Hugh Jass, Mike Hunt, Harry Butz, Fonda Cox, etc...

    (reply to this comment) (link to this comment)

  • Dec 22nd, 2005 @ 5:34pm

    No Subject Given

    by TJ

    Yeah, some spammers use not just random 'friendly names' and subjects, but random excerpts of text in the message body too. Here is an example of a weird spam wave we've been seeing at the office. The only consistent thing about the messages is the hard to read 'ad':

    From: "Gladwyn Orick" gladwyna@khnp.co.kr
    To: "Jarvis Jacox" [a fake name with no relation to the e-mail adddress]
    Subject: Re: runin cornflower

    www.--------.com
    =20
    Vl
    Xa
    Va
    Cl
    A
    So
    Le
    AGRA (30)
    nax (30)
    LlUM (30)
    ALlS (30)
    mbien (30)
    ma (30)
    vitra (30)
    - $135
    - $124
    - $86
    - $170
    - $120
    - $76
    - $166
    =20
    David, what happened? Alex mentioned Medusa- Its a mess and hes right,
    he has to go higher up with it. Him, not us. We stay out. Far away out.
    What happened? repeated Marie. Whats the old Medusa got to do with
    anything? Theres a new Medusa-an extension of the old one, actually-and
    its big and ugly and it kills, they kill. I saw that tonight; one of
    their guns tried to kill me after thinking hed killed Cactus and
    murdering two innocent men. Good God! Alex told me about Cactus when he
    called me back, but nothing else. How is your Uncle Remus? Hell make it.
    The Agency doctor came out and took him and the last brother away.

    (reply to this comment) (link to this comment)

    • Dec 28th, 2005 @ 10:27am

      Re: No Subject Given

      by Graham Fan

      You know, it's quite easy to make a *very* effective spam filter that catches things like this extremely well. It's called Bayesian filtering.

      Step 1: Take a corpus of spam and legitimate mail.

      Step 2: Break the entire corpus into tokens, breaking along whitespace. Include every part of a message, including headers, into the token list.

      Step 3: Analyze the relative frequency of each word, and assign it a probably of appearing in a spam mail vs. legitimate mail.

      Step 4: Whenever a new mail comes in, tokenize it and assign probabilities to each mail based on the corpus data.

      Step 5: Grab the 20 or so 'most interesting' tokens, defined as the tokens that are most strongly spam or non-spam.

      Step 6: Average the probabilities of the interesting tokens, and if it's above a certain limit, label the mail as spam.

      Step 7: Update the spam probabilities based on this new mail.

      There you go! Spam trigger words become very highly indicative of spam (a probability very near 1) while words that often appear in your legitimate mail become very indicative of the opposite (probability very near 0). Since only the 'interesting' words are taken into consideration, trying to dilute the probability with white noise won't have any effect (and will only make the words used in white noise be rated as more likely spammy). Weird spellings and such that spammers use to try to get around blacklists are even better, because they'll almost certainly not appear in legitimate mail, and become an automatic flag for spam after you see them once.

      Trials with the process show a highly effective filter that produces virtually zero false positives.


      Given this, that mail you just posted would have been caught automatically.

      (reply to this comment) (link to this comment)

Add Your Comment

Have a Techdirt Account? Sign in now.
Get Techdirt’s Daily Email
Plain Text HTML
Save me a cookie
  • Plain Text: A CRLF will be replaced by break <br> tag, all other allowable HTML is intact
  • HTML: No formatting of any kind is done without explicitly being written in
  • Allowed HTML Tags: <b> <i> <p> <a> <em> <br> <strong> <blockquote> <hr> <tt>
Close
Have a Techdirt Account? Sign in now.
Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie

Search Techdirt
And now, a word from our Sponsors..



Subscribe to Techdirt's Daily Email Newsletter

Techdirt's Daily Email Newsletter

Related Stories
Close
E-mail It