In the latest Report from MessageLabs [PDF] they have observed that...
When seeing shortened web addresses, the user does not really know which website they are going to be directed to. For some time now, security solutions have employed their own techniques to detect potential malware in these shortened addresses. Therefore, now spammers have decided to create their own system, in order to try to also deceive spam filters, which they may consider to be a real URL and not a suspicious one.In the latest report from MessageLabs [PDF] they have observed that a new evasion technique emerges, which works by incorporating a short legitimate URL, which in turn points to a short address system created by spammers. This eventually redirects to the target website, adding an extra layer to beat the filters.
To make sure, spammers have even started creating strings from these sites to make links harder and harder to analyze. They even start the registration of domains months before their use to obtain the analysis of the entire domain (since fake domains are usually very recent creation, while legitimate ones have been active for a longer time). Currently, most of these spammer pages create their own url shorteners have the .ru ending.
Complete content in original IDG source

