Post by Cher on Aug 11, 2006 20:09:17 GMT -5
I noticed I've been getting these emails ...
You've got an e-card from Egreetings
Alot of them several times a day so decided it was time to look around to see if I had an urban legend or what. It seems the problem is, you don't have an e-card but an invitation to download a nasty trojan. I found this info ...
*************
CRITICAL ALERT!!!! New Email Malware - you got an e-card - HIGHLY DANGEROUS (16:05 GMT+01)
UPDATE: This NASTY piece of Malware disables many applications, including new installs, AV, even the running of Windows Explorer etc. Message: Any executable is disabled: the instruction 0x00000 pointsto memory location 0x00000, read or write instruction has failed THIS IS A HIGHLY DANGEROUS PIECE OF MALWARE!!!! Original Alert: HEADS-UP - Trojan and backdoor malware in new scam email - You’ve got an "e-card" at ’greeting-cards’ Some of our subscribers in New Zealand and Australia have received this email, claiming to contain an e-card. We recevied same in our honeypot and analysed it. This email is fooling recipients to download fake flash player upgrade. Instead infects with trojan and backdoor. trojan is hanlo.t variant backdoor is haxdoor.jy variant Infected files: dYmp.207.exe and dYmp.204.exe avupdate2.sys install_flash_player.exe
-----Original Message-----
From: Geneticists T. Feebly [mailto:michelle_no_replay@greeting-cards.com]
Sent: Thu 10/08/06 13:50
To: XXXX (E-Secure-IT Honey Pot)
Cc:
Subject: You’ve got an "e-card" at ’greeting-cards’
Dear recipient.
Sender at Michelle sent you an "e-card" "Here’s the Rub" from ’greeting-cards’. To see your card, click here This "ecard" will be stored for one week, so print or save the card as soon as possible. Hope you enjoy our "e-cards". Spread the love and send one of our "e-cards". Brought to you by ’greeting cards’ - a better way to greet.
****************
I've also noticed that they are coming from lots of other names so no matter who it's from, just delete it and save yourself some problems.
You've got an e-card from Egreetings
Alot of them several times a day so decided it was time to look around to see if I had an urban legend or what. It seems the problem is, you don't have an e-card but an invitation to download a nasty trojan. I found this info ...
*************
CRITICAL ALERT!!!! New Email Malware - you got an e-card - HIGHLY DANGEROUS (16:05 GMT+01)
UPDATE: This NASTY piece of Malware disables many applications, including new installs, AV, even the running of Windows Explorer etc. Message: Any executable is disabled: the instruction 0x00000 pointsto memory location 0x00000, read or write instruction has failed THIS IS A HIGHLY DANGEROUS PIECE OF MALWARE!!!! Original Alert: HEADS-UP - Trojan and backdoor malware in new scam email - You’ve got an "e-card" at ’greeting-cards’ Some of our subscribers in New Zealand and Australia have received this email, claiming to contain an e-card. We recevied same in our honeypot and analysed it. This email is fooling recipients to download fake flash player upgrade. Instead infects with trojan and backdoor. trojan is hanlo.t variant backdoor is haxdoor.jy variant Infected files: dYmp.207.exe and dYmp.204.exe avupdate2.sys install_flash_player.exe
-----Original Message-----
From: Geneticists T. Feebly [mailto:michelle_no_replay@greeting-cards.com]
Sent: Thu 10/08/06 13:50
To: XXXX (E-Secure-IT Honey Pot)
Cc:
Subject: You’ve got an "e-card" at ’greeting-cards’
Dear recipient.
Sender at Michelle sent you an "e-card" "Here’s the Rub" from ’greeting-cards’. To see your card, click here This "ecard" will be stored for one week, so print or save the card as soon as possible. Hope you enjoy our "e-cards". Spread the love and send one of our "e-cards". Brought to you by ’greeting cards’ - a better way to greet.
****************
I've also noticed that they are coming from lots of other names so no matter who it's from, just delete it and save yourself some problems.