{"id":13386,"date":"2018-09-19T08:10:04","date_gmt":"2018-09-19T16:10:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/09\/19\/news-7153\/"},"modified":"2018-09-19T08:10:04","modified_gmt":"2018-09-19T16:10:04","slug":"news-7153","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/09\/19\/news-7153\/","title":{"rendered":"A month of giveaway spam on Twitter"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Wed, 19 Sep 2018 15:00:48 +0000<\/strong><\/p>\n<p>We&#8217;ve observed a low level spam campaign working its way through Twitter, with just under 2,000 posts visible on public search since September 1.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/giveaway.jpg\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"25538\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/month-giveaway-spam-twitter\/attachment\/giveaway\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/giveaway.jpg\" data-orig-size=\"479,47\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"giveaway posts\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/giveaway-300x29.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/giveaway.jpg\" class=\"aligncenter size-medium wp-image-25538\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/giveaway-300x29.jpg\" alt=\"giveaway posts\" width=\"300\" height=\"29\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/giveaway-300x29.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/giveaway-470x47.jpg 470w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/giveaway.jpg 479w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center;\">Click to enlarge<\/p>\n<p>The posts promote what appears to be CBD oil. For those who don&#8217;t know (And I was one of them\u2014still not sure if this oil is supposed to be inhaled or consumed, but anyway), CBD is short for\u00a0Cannabidiol, which is a chemical found in cannabis thought to have pain-relieving properties. It is often distilled into oil that can be used in many different ways for various ailments.<\/p>\n<p>The posts follow one of two formats. The first is a large image splash attached to each Tweet:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-pic.jpg\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"25539\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/month-giveaway-spam-twitter\/attachment\/spam-with-pic\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-pic.jpg\" data-orig-size=\"666,660\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Twitter post with image\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-pic-300x297.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-pic-600x595.jpg\" class=\"aligncenter size-medium wp-image-25539\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-pic-300x297.jpg\" alt=\"Twitter post with image\" width=\"300\" height=\"297\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-pic-300x297.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-pic-150x150.jpg 150w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-pic-600x595.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-pic.jpg 666w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center;\">Click to enlarge<\/p>\n<p>It says:<\/p>\n<blockquote>\n<p><em>Have you entered into the giveaway yet for a bottle of [product name]?<\/em><\/p>\n<p><em>They are giving it away for FREE<\/em><\/p>\n<p><em>Follow these simple steps:<\/em><br \/> <em>Step 1: RE-TWEET this post!<\/em><br \/> <em>Step 2: Click the &#8220;Link&#8221; below to get your FREE [product name] for the last step!<\/em><\/p>\n<\/blockquote>\n<p>The second post format we&#8217;ve seen is just text with a referral link:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-text.jpg\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"25540\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/month-giveaway-spam-twitter\/attachment\/spam-with-text\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-text.jpg\" data-orig-size=\"588,785\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Twitter posts, text only\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-text-225x300.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-text-449x600.jpg\" class=\"aligncenter size-medium wp-image-25540\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-text-225x300.jpg\" alt=\"Twitter posts, text only\" width=\"225\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-text-225x300.jpg 225w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-text-449x600.jpg 449w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/spam-with-text.jpg 588w\" sizes=\"auto, (max-width: 225px) 100vw, 225px\" \/><\/a><\/p>\n<p style=\"text-align: center;\">Click to enlarge<\/p>\n<p>In both cases, the Tweets lead the curious clicker to a site located at<\/p>\n<p>cbdhive(dot)com<\/p>\n<p>This website&#8217;s Whois data is listed as domains by proxy, and it offers an email sign up for users to be the &#8220;first to know&#8221; about&#8230;well, no idea. It doesn&#8217;t say. I assumed the product was some sort of energy boost tablet, or maybe some kind of juice, and only learned of the medicinal oil connection after several bouts of Googling. All the visitor knows at this point is he has to sign up for something via email.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/frontpage.jpg\" data-rel=\"lightbox-3\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"25542\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/month-giveaway-spam-twitter\/attachment\/frontpage\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/frontpage.jpg\" data-orig-size=\"885,675\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"frontpage of site\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/frontpage-300x229.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/frontpage-600x458.jpg\" class=\"aligncenter size-medium wp-image-25542\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/frontpage-300x229.jpg\" alt=\"frontpage of site\" width=\"300\" height=\"229\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/frontpage-300x229.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/frontpage-600x458.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/frontpage.jpg 885w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center;\">Click to enlarge<\/p>\n<p>Once an email address has been handed over, the visitor will be taken to a second page that claims to offer various bundles depending on how many friends make use of the referral\/sign-up links. The options available are sharing it via Facebook, Twitter, and email.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/after-sign-up.jpg\" data-rel=\"lightbox-4\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"25543\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/month-giveaway-spam-twitter\/attachment\/after-sign-up\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/after-sign-up.jpg\" data-orig-size=\"1022,886\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"post sign up&#8230;\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/after-sign-up-300x260.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/after-sign-up-600x520.jpg\" class=\"aligncenter size-medium wp-image-25543\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/after-sign-up-300x260.jpg\" alt=\"post sign up...\" width=\"300\" height=\"260\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/after-sign-up-300x260.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/after-sign-up-600x520.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/after-sign-up.jpg 1022w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center;\">Click to enlarge<\/p>\n<p>If you refer five friends, you get one month of free supplies. Ten friends, two months. If you can summon 50 friends, then they claim you&#8217;ll receive a full year&#8217;s supply.<\/p>\n<p>On our sign-up page, we were told &#8220;one friends [sic] have joined&#8230;keep checking.&#8221;<\/p>\n<p>I don&#8217;t know who that friend is, because I certainly didn&#8217;t invite anyone (much less have them join).<\/p>\n<p>We haven&#8217;t seen any evidence of the posts being automated, so it&#8217;s likely people are firing them off manually in the hopes of a freebie or 12.<\/p>\n<p>I can&#8217;t say we advise jumping on the free stuff bandwagon; it&#8217;s never actually certain if the people participating will receive their desired games, ringtones, or other gifts. In this case, there&#8217;s also zero information we can see on the site about what the product is, what it does, how you use it, or if it&#8217;s even allowed in whatever region you happen to live.<\/p>\n<p>Factoring CBD into the picture further complicates the matter because <a href=\"https:\/\/www.royalqueenseeds.com\/blog-where-in-the-world-is-cbd-legal-n950\" target=\"_blank\" rel=\"noopener\">CBD is only legal in certain regions (globally)<\/a>, and under certain conditions. For example, CBD is legal in all 50 US states if it&#8217;s derived from the hemp plant. But if derived from marijuana, it&#8217;s legal in only eight US states. If prescribed by a doctor, it&#8217;s legal in 46 states. That&#8217;s not confusing at all.<\/p>\n<p>Same deal for shipping, come to think of it. Is it targeted to one area only? Is International shipping possible with CBD?<\/p>\n<p>I have no idea, and most likely neither does anyone else firing the links everywhere.<\/p>\n<p>Always be cautious around sets of identical posts promising you free gifts in return for performing specific tasks. Most of the time, you&#8217;re doing little more than acting as free brand promotion for someone else&#8217;s SEO team taking the day off. I&#8217;m all for boosting the brand and increasing the verticals, but that&#8217;s taking things a little too far.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/month-giveaway-spam-twitter\/\">A month of giveaway spam on Twitter<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/month-giveaway-spam-twitter\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Wed, 19 Sep 2018 15:00:48 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/month-giveaway-spam-twitter\/' title='A month of giveaway spam on Twitter'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2016\/04\/twitter-iphone-smartphone-mobile-app-feature.jpeg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>We&#8217;ve observed a low level spam campaign working its way through Twitter, with just under 2,000 posts visible on public search since September 1. What&#8217;re they trying to sell this time? Some CBD oil!<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/privacy\/\" rel=\"category tag\">Privacy<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/free-cbd-oil\/\" rel=\"tag\">free CBD oil<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/giveaway-spam\/\" rel=\"tag\">giveaway spam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/invite\/\" rel=\"tag\">invite<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/spam\/\" rel=\"tag\">spam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/tweets\/\" rel=\"tag\">tweets<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/twitter\/\" rel=\"tag\">twitter<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/month-giveaway-spam-twitter\/' title='A month of giveaway spam on Twitter'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/month-giveaway-spam-twitter\/\">A month of giveaway spam on Twitter<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[4503,19538,19539,19540,5897,10518,19541,454],"class_list":["post-13386","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cybercrime","tag-free-cbd-oil","tag-giveaway-spam","tag-invite","tag-privacy","tag-spam","tag-tweets","tag-twitter"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=13386"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13386\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=13386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=13386"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=13386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}