Sponsored by..

Saturday 6 April 2013

"Updated information" spam / accooma.org / classic-pharmacy.com

This scary looking spam is nothing more than an attempt to get you to click through to a fake pharmacy site:

Date:      Mon, 9 Feb 2004 13:00:35 +0000 (GMT)
From:      "Account Info Change" [info@virtualregistrar.com]
Subject:      Updated information

    Updated information

Hello,

The following information for your ID [redacted] was updated on 02/09/2012: Date of birth, Security question and answer.

If these changes were made in error, or if you believe an unauthorized person accessed your account, please reset your account password immediately.

This is an automated message. Please do not reply to this email. If you need additional help, visit our Support Center.

Thanks,
Customer Support

The link in the email goes to a landing page on accooma.org (184.82.155.18 - HostNOC, US) which clicks through to classic-pharmacy.com (184.82.155.20 - also HostNOC). These two IPs are very close together which indicates a bad block.

There does not appear to be any malware involved (see here and here) and of course nobody has changed any details on your account. You can safely ignore these emails.

A closer examination shows that HostNOC have suballocated 184.82.155.16/29 (184.82.155.16 - 184.82.155.23) to an unknown party. The following fake pharma sites are active in this range:
accooma.org
classic-pills.net
fdapharmacy.net
iorderpills.net
justpills-com.com
pill-max.net
fdapharmacy-com.com
internetpharmacyreview.com
iorderpills-com.com
just-pills.net
pharmacyfinder.net
pillmax-com.com
classic-pharmacy.com
comparedrugprices-com.com
emedsource-com.com
justmypills-com.com
l-md.info
pharmacheap-com.com
pills-md.net
clinicmeds.info
kamagrafast2.info
pillorder-com.com
zpharmacy-com.com
buymeds-com.com
generics4u.info
rx-cs.info

No comments: