Botnets harvesting host machines’ email content?

One of the most successful approaches to spam is when the sender creates the spam using snippets of text that are unique to each message.  This can make it fairly difficult to mechanically parse what is spam and what’s real email.

I noticed an interesting development recently, though.  While trying to figure out what allowed a recent batch of spam through the filter, I was looking at the snippets; for example:

“i thought id live there forever one day when i was 12 my dad quit his job and we moved to lake tahoe it rocked my stable world”

“i went to the fabric store tonight in search of prints to make some new spring scarves with some will probably end up in the shop too”

In the past, most of the snippets seemed to be from books or articles.  But these seem like they could easily be from a real email (or maybe long-winded IM conversation) … and then I realized:

Might it be that the botnets are actually harvesting the email of their host machines in order to get (effectively) entirely random, completely believable text snippets?


Copyright © 1996-2011 Bill Westerman. All Rights Reserved.