Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: REDACTED on October 19, 2017, 10:52:06 AM

Title: email address used for Avast now receiving spam
Post by: REDACTED on October 19, 2017, 10:52:06 AM
The email address that I use for Avast has only ever been used for that purpose.  This morning I have received a 'Mens Health' spam message to that address.  So, how did the spammers get hold of that email address?

I won't go into details about how the addresses I use are formed, suffice it say that there are potentially tens of thousands and the Avast one is the only one in the past few months to receive spam.
Title: Re: email address used for Avast now receiving spam
Post by: Pondus on October 19, 2017, 11:21:59 AM
Email address harvesting
https://en.wikipedia.org/wiki/Email_address_harvesting

Directory Harvest Attack
https://en.wikipedia.org/wiki/Directory_Harvest_Attack



Title: Re: email address used for Avast now receiving spam
Post by: REDACTED on October 19, 2017, 02:21:17 PM
I wouldn't put it past them.  Years ago this would surprise me, but not anymore.  Like many people, I use 1 junk address for installing software, etc., but then it's hard to tell if 1 company is a culprit.  That was a good test you did, so now you know.  Yes it's possible that there's some small malware on your computer that monitors your keystrokes or Internet traffic, but it's equally as possible that Avast really does sell the address list, or that their servers have malware on them.

If Avast does it intentionally, then of course they're not going to tell you, but hopefully they'll at least check their servers for any malware.
Title: Re: email address used for Avast now receiving spam
Post by: Pondus on October 19, 2017, 03:34:15 PM
D'oh! ... @Todd_NC did you read my post above?

Title: Re: email address used for Avast now receiving spam
Post by: REDACTED on October 19, 2017, 06:48:24 PM
Email address harvesting
https://en.wikipedia.org/wiki/Email_address_harvesting

Directory Harvest Attack
https://en.wikipedia.org/wiki/Directory_Harvest_Attack

The email address in question shouldn't appear in any public location and so should not be accessible to any 'harvester'.  The variant suggested of using a dictionary attack (or even a brute force attack) would surely  have resulted in many of my potential tens of thousand addresses receiving the spam - and the address used for Avast is the only one.