Advertisement - Your Ad Here!

Malware Mass-Mailer Attacks coming from disguised Twitter, Amazon, Hallmark and Hi5 Emails

June 15, 2009 – 5:43 pm
Advertisement - Your Ad Here!

A new spam campaign was discovered as a mass-mailer attack that sends email disguised as being from popular sites such as Hallmark, Twitter, Hi5 and Amazon.

CA Security Advisor Research Blog has warned computer users of a new mass-mailer spam campaign that sends out messages including a .ZIP file attachment which contains malware. Spreading through an older method via P2P (peer to peer) networks, is an onslaught of fictitious emails asking computer users to either join a social network or appear to be an invitation card.

The spam emails that were discovered to be currently circulating over the internet can be very deceiving. The messages actually look legitimate as if they were sent by well-known websites.

  • The fake Twitter emails appear to be an invitation to join Twitter but it is fake and contains a malicious .ZIP file attachment. See Figure 1.
  • The fake Hallmark email appears to be a postcard. This email also has a malicious .ZIP file attached to it. See Figure 2.
  • A fake Amazon email comes in the form of a shipping conformation but it is fake as well. It contains virtually the same malicious .ZIP file. See Figure 3.
  • A fake Hi4 email has an invitation card and message with an “Invitation Card.zip” file which is malicious. See Figure 4.

Figure 1.
Figure 1.

Figure 2.
Figure 2.

Figure 3.
Figure 3.

Figure 4.
Figure 4.

[images source: community.ca.com]

Users should take warning to these fake email messages. You should limit the download of attachments from email messages unless you are 100% sure of the source. Usually e-cards, initiations and social network emails do not contain attachments especially in the form of a .ZIP file.

Ever seen any of these emails in your inbox?

Post a Comment

*
To prove you're a person (not a spam script), type the security word shown in the picture.
Anti-Spam Image