"Amazon Order Cancelled": Weight Loss Spam Campaign via Obfuscated JavaScript

Date: June 9, 2017
Source: Email Spam
From: “order-update@amazon[.]com”
Subject: Your order 12-2385-8791 has been successfully canceled
Here is the full spam chain:

  • First email href redirect
  • hxxp://hutforeverwest[.]com/spaniardizes[.]php

  • Obfuscated href JS redirect
  • hxxp://mind-brains[.]world/?a=401336&c=cpcdiet&s01062017

  • Third-layer PHP redirect
  • hxxp://mind-brains[.]world/us/xxrr/clanew-tmz?bhu=3cMnEa2X97RGXu9jwQsJegZiZHBadNzjjiV9

  • Final landing page
  • hxxps://cla-extract-portal[.]com/cla_list/cla_improved3/?click_id=06_41055726_71b340f6-3122-4a01-9fef-f945e4e6e8d7&subid1=313491&netid=3&ver=old&ad=1gPA


    II. Review the copied PHP page via the curl command 
    curl hxxp://hutforeverwest[.]com/spaniardizes[.]php

    III. JavaScript function resolves to hxxp://mind-brains[.]world/?a=401336&c=cpcdiet&s01062017, viewed by simply printing an alert box to the screen via the alert() JavaScript function.



    III. Encoded JavaScript href() redirect -> 

    hxxp://mind-brains[.]world/us/xxrr/clanew-tmz?bhu=3cMnEa2X97RGXu9jwQsJegZiZHBadNzjjiV9

    IV. The landing page leads to the “CLA Safflower Oil” weight loss product landing.



    V. Final landing product page (id: 313491) -> 

    hxxps://cla-extract-portal[.]com/cla_list/cla_improved3/?click_id=06_41055726_71b340f6-3122-4a01-9fef-f945e4e6e8d7&subid1=313491&netid=3&ver=old&ad=1gPA


    Here is the full spam chain:
    • First email href redirect
    • hxxp://hutforeverwest[.]com/spaniardizes[.]php

    • Obfuscated href JS redirect
    • hxxp://mind-brains[.]world/?a=401336&c=cpcdiet&s01062017

    • Third-layer PHP redirect
    • hxxp://mind-brains[.]world/us/xxrr/clanew-tmz?bhu=3cMnEa2X97RGXu9jwQsJegZiZHBadNzjjiV9

    • Final landing page
    • hxxps://cla-extract-portal[.]com/cla_list/cla_improved3/?click_id=06_41055726_71b340f6-3122-4a01-9fef-f945e4e6e8d7&subid1=313491&netid=3&ver=old&ad=1gPA

        p.p1 {margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px ‘Andale Mono’; color: #28fe14; background-color: #000000; background-color: rgba(0, 0, 0, 0.9)} span.s1 {font-variant-ligatures: no-common-ligatures}

        Leave a Reply

        Fill in your details below or click an icon to log in:

        WordPress.com Logo

        You are commenting using your WordPress.com account. Log Out /  Change )

        Google photo

        You are commenting using your Google account. Log Out /  Change )

        Twitter picture

        You are commenting using your Twitter account. Log Out /  Change )

        Facebook photo

        You are commenting using your Facebook account. Log Out /  Change )

        Connecting to %s