Spam Emails Masquerade as ICANN Notifications

Recommended Posts

Spam Emails Masquerade as ICANN Notifications

Lead to drive-by download attack

A spam campaign currently in circulation attempts to scare users into clicking on malicious links by claiming that their domain name has been suspended by ICANN. Victims are exploited and eventually end up on a Canadian Pharmacy site.<br style=""><br style="">

he new rogue emails have their "From" field spoofed to appear as originating from "ICANN Services" and come with a subject of "ICANN attention letter." The message inside reads "Your Domain Has Been Suspended" and and also contains instructions to click on a link for more information. Several ICANN logos and images were embedded in the body as well, in order to increase the scam's credibility.

Clicking on the included link leads users to a page that loads malicious code. The purpose of these scripts is to exploit vulnerable software on their computer and infect them with a backdoor. In addition, after the drive-by download part is complete the victims are dropped on a classic Canadian Pharmacy Site that advertises unregulated meds.

story - http://news.softpedi...NN-146090.shtml

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.
