Sponsored by..

Thursday 26 April 2012

Facebook spam / bioldrugstore.com

This fake Facebook spam leads to a fake pharma site, but it could easily be adapted for malware.

Date:      Thu, 26 Apr 2012 09:33:46 -0700
From:      "Facebook" [notification+xxxxxxxxxxx@facebookemail.com]
Subject:      Welcome back to Facebook


The Facebook account associated with xxxxxxxxxxx was recently reactivated.

If you were not the one who reactivated this account, please visit our Help Center to cancel the request.


The Facebook Team

The payload is a pharma site at bioldrugstore.com hosted on and in China (two IPs that are full of fake pharma stores) and in Spain.

This type of spam run can easily be adapted for malware, so keep an eye out for unexpected Facebook notifications.

No comments: