Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.
Security Response

Thanksgiving & Black Friday On Spammers’ Radar

Created: 15 Nov 2012 13:22:37 GMT • Updated: 23 Jan 2014 18:11:29 GMT • Translations available: 日本語
Anand Muralidharan's picture
+2 2 Votes
Login to vote

Some events familiar among people in the United States are commencing this month, including: Thanksgiving—a great occasion to thank dear friends and family for their kindness; and Black Friday—a day after Thanksgiving, usually the busiest retail shopping day of the year. Spam messages related to these events have begun flowing into the Symantec Probe Network. Many of the spam samples observed are encouraging users to take advantage of e-cards, clearance sales of cars and trucks, products bidding to get the best deals, replica watches. Clicking the URL will automatically redirect the user to a fake offer website.
 

Figure 1: An e-card for Thanksgiving day
 

Figure 2: Fake bidding deals for Black Friday

A new tactic is being observed whereby domains attempt to convince users to bid for good deals. In such cases users should be careful and avoid clicking on the links. The domains being used in the attack are registered for one year and its servers were located in United States of America. Below are some examples of the spam domains that we have thus far identified:

  • http://www.GetSignedxxxxx[REMOVED]idding.com
  • http://www.BidQuickxxx[REMOVED].com
  • http://www.BidOnlinexxxx[REMOVED]GreatDeals.com

In one spam sample of Black Friday, the spammers invite users to purchase the product (Rolex watches) with a price reduction of 25% – 50% along with some false promises, such as:

  • Hand-crafted, high-end watch copies
  • Made using identical parts and materials
  • No difference between these watches and the originals

Users should be wary of such bogus offers. The spam domain used in the above attack taking advantage of the Black Friday holiday is:

http://www.xxxBlackFridayWatch[REMOVED].com
 

Figure 3: Replica watches for sale

Some of the Subject Lines observed for these spam attacks include:

  • Bake Mini Pumpkin and Blueberry Pies For Thanksgiving!
  • xxx@xxx.com: Someone sent you a Thanksgiving Message
  • Get your Pinhooks! Thanksgiving is coming
  • BLACK FRIDAY PRE-SALE!!! iPads, Digital Cameras, iPhones & PlayStations All For Less Than $20!!!
  • Dont wait till 23rd November, Black Friday; Huge Discounts are already ON!
  • Black Friday Pricing on ALL INSTOCK inventory
  • Early Black Friday Auction

Symantec advises our readers to be cautious when handling unsolicited or unexpected emails. We at Symantec are monitoring spam attacks 24x7 to ensure that readers are kept up-to-date with information on the latest threats.