Analysis by: Mark Christian Aquino

A spammed message promoting something called the Google Accredited Pharmacy is seen in the wild. The said email message contains an image that shows a link. When users type in the link into their browsers, it directs them to a rogue Canadian pharmacy website that is hosted in Russia.


This kind of technique is commonly known as 'brand hijacking,' wherein cybercriminals use the names of popular brands to in order to appear legitimate to unsuspecting users. Since Google is famous for their Google Doodles, spammers have also found a creative way of changing the logo by substituting different pharmaceutical tablets for the two 'o's' in the Google logo. Note, however, that there is no legitimate Google Pharmacy at all.


Users are advised to check first the legitimacy of certain email messages even if these come from known sources.

 SPAM BLOCKING DATE / TIME: March 01, 2012 GMT-8
 TMASE INFO
  • ENGINE:
  • PATTERN:8746