TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: What is this spam email's motive?

3 点作者 erdaniels超过 1 年前
For the past four years, I&#x27;ve been getting unauthenticated spam in the guise of amazon.co.jp (yes I like to look through my spam folder). I get emails daily that always lead to almost legit looking .com&#x27;s that 302 to 7 character .cn&#x27;s that then 302 back to google (while setting a PHP session cookie). They all lead to the same IP address that is also SSH accessible.<p>Taking all of this at face value, what&#x27;s their game here?<p>* Collect data on IP addresses as silly as me to click through links?<p>* Hope someone tries to access their SSH?<p>* Wait for someone to load an image in their email that has some 0-day?

3 条评论

repelsteeltje超过 1 年前
Suppose that beyond confirmation that you actually received and looked at the email, they don&#x27;t learn a lot. Might be they aren&#x27;t even interested in identifying the receiver, just some rough estimate on whether they&#x27;re able to pierce through spam filters.<p>More interesting hints might be in the accompanying text. What kind of content was used to lure you into amazon.co.jp? What was the sent-from &#x2F; reply-to info?<p>My impression is that spam is usually unsophisticated and amateur. They intentionally <i>raise</i> transaction costs by looking inauthentic, to weed out wary victims because those will just be a pain when they finally need to trick them into believing they should pay $10,000 to receive a million.
评论 #37726756 未加载
gus_massa超过 1 年前
&gt; <i>* Hope someone tries to access their SSH?</i><p>Never attribute to malice that which is adequately explained by stupidity.
tamimio超过 1 年前
Most likely to know if that email was opened and the user was indeed tricked to click the link, so maybe later “promoting” your email into the actual phishing email list.