FYI...

Fake 'Forskolin' SPAM - using spoofed email addresses
- https://myonlinesecurity.co.uk/anoth...ail-addresses/
22 Sep 2017 - "... malspam campaign again today pushing the crappy, scummy, useless 'Forskolin weight loss' junk... Some subjects in the original emails include (there are hundreds of variants): These pretend to be Facebook notifications about missed private messages or pending notifications:
You photos that will be deleted in 1 days
You have notification that will be removed in 5 hours
For You new message that will be removed in 6 days
Private message that will be deleted in 3 hours
You friend that will be deleted in 5 hours
You have notification that will be deleted in 7 days


The Hotmail emails look like:
- https://myonlinesecurity.co.uk/wp-co...ects_email.png

The original emails look like these:
- https://myonlinesecurity.co.uk/wp-co.../support_3.png

- https://myonlinesecurity.co.uk/wp-co.../support_2.png

- https://myonlinesecurity.co.uk/wp-co.../support_1.png

The links go to a multitude of -compromised- sites but all eventually end today on
http ://weight4forlossdiet-4tmz .world/en/caus/forskolin/?bhu=8mczFswKd5ZrUCttf15dChmqRGCWobCch
(with a different random reference number) where you see a page looking like this:
> https://myonlinesecurity.co.uk/wp-co...tloss-scam.png
This shows the importance of having correct authentication set up on your email server with DMARC* reporting, so you know when your email address is being spoofed and used in a mass malspam campaign:
> https://myonlinesecurity.co.uk/wp-co...c_rejects2.png

* https://myonlinesecurity.co.uk/anoth...uld-use-dmarc/ "

weight4forlossdiet-4tmz .world: 192.254.79.249: https://www.virustotal.com/en/ip-add...9/information/
> https://www.virustotal.com/en/url/5b...ec06/analysis/