Facebook Scam Spam
We are seeing reports of Facebook Scam Spam trickle in. Rene provided us with a detailed anecdote that includes the following image. The url provided in the image was investigated a bit. TinyURL has since taken down the redirect and classified it as Spam. However, the image (and others like it) still propagate by FB users clicking on the link.
This type of scam is used mostly without the permission of the vendor noted, in this case Costco. The idea is to entice the user to click so they get redirected to a site where the business model depends on traffic volume. If the Facebook user count has hit 1 billion yet, (not something I'm keeping track of.. :) ) then even a small percentage of that makes the Facebook population an easy target, with an easy payout.
If you are a Facebook user, then please be wary of any offers that entice you to "click" to receive. It's a really bad practice. The holiday shopping season is beginning and these vectors are going to be heavily used by the scammers in the coming months.
-Kevin
--
ISC Handler on Duty
Comments
Spelling, capitalization, and punctuation errors. And it seems too good to be true. All the earmarks of spam. But I could buy many gallons of salsa with the $500. Tempting - NOT!
Alan
Oct 10th 2012
1 decade ago
Jason R
Oct 10th 2012
1 decade ago
New #Facebook credential stealer: Subj: :Hey friends got a $500 Gift Card from COSTCO!" URL: hxxp://bit.ly/Pi1X8O IP: 46.21.151.148 Blocked
ThreatSTOP
Oct 10th 2012
1 decade ago
More details below.
Subject: "Hey friends got a $500 Gift Card from COSTCO! "
URL: hxxp://bit.ly/Pi1X8O, redirects through Google Translate to
hxxp://www.google.com/translate?hl=en&ie=UTF8&sl=auto&tl=en&u=hxxp://bit
.ly/UvLPCO
Which goes to:
hxxp://ooyah.info/costco.php?bfxhpJ3X
IP: 46.21.151.148
Old RBN IP.
ThreatSTOP
Oct 10th 2012
1 decade ago
var country = geoip_country_code(); if (country == 'US' || country == 'GB' || country == 'AU' || country == 'USA') { window.top.location = "https://mirro rgo[.]info/costco/"; } else { window.top.location = "https://google.com"; }
Peter Kruse
Oct 11th 2012
1 decade ago
RosieRed
Oct 11th 2012
1 decade ago