22 Feb 2010

Amazon and Greeting cards to distribute malware

We want to inform you of two different email messages we’ve been receiving lately in the lab in order to distribute malware designed to steal information.

One of them seems to have been sent by Amazon and informs you that they have received your payment and your order has been already sent. In order to check your tracking number, have a look at the attached document.

These messages have the following characteristics:

* Subject:
Amazon Shop! Your order has been paid! Parcel NR.XXXX (XXXX are random digits)

* Message:
The content of the message is always the same, except for the item that has been ordered. We’ve detected emails using the following gadgets among many others: Sony VAIO VGC-JS230J, Apple iPhone 3G and Nokia E65.

The following is an example:
Hi! Thank you for shopping at Amazon.com We have successfully received your payment. Your order has been shipped to your billing address. You have ordered ” Sony VAIO VGC-JS230J “ You can find your tracking number in attached to the e-mail document. Print the postal label to get your package. We hope you enjoy your order! Amazon.com

* Attachment: Postal_package_NRXXX.zip (XXX stands for random digits)

The attached file contains a copy of the malware, which has been detected as Sinowal.WVI.

For full atricle see here > http://bit.ly/cIlG8N

No comments:

Post a Comment