| PC Security A place to discuss new threats, firewalls, virus scanners, and all other aspects of keeping your computer secure from threats. Learn how to stop spyware... hackers ... identity thieves... and more! |  |
11-16-2006, 06:16 PM
|
#1 | | Head Mistress
Join Date: Oct 2005 Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7  | WARNING - Invoice email containes a virus! Howdy!
I just got this email at PC101's mail box... Dear Customer,
Thank you for ordering from our internet shop. If you paid with a
credit card, the charge on your statement will be from name of our shop.
This email is to confirm the receipt of your order. Please do not
reply as this email was sent from our automated confirmation system.
Date : 06 Nov 2006 - 12:40
Order ID : 37679041
Payment by Credit card
Product : Quantity : Price
WJM-PSP - Sony VAIO SZ370 C2D T7200 : 1 : 2,449.99
Subtotal : 2,449.99
Shipping : 32.88
TOTAL : 2,482.87
Your Order Summary located in the attachment file (self-extracting
archive with "37679041.pdf" file ).
PDF (Portable Document Format) files are created by Adobe Acrobat
software and can be viewed with Adobe Acrobat Reader. If you do not already have this viewer configured on a local drive, you may download it for free from Adobe's Web site.
We will ship your order from the warehouse nearest to you that has your items in stock (NY, TN, UT & CA). We strive to ship all orders the same day, but please allow 24hrs for processing.
You will receive another email with tracking information soon.
We hope you enjoy your order! Thank you for shopping with us!
When I first saw this email I thought "OMG, someone must have gotten ahold of my credit card!" I scanned the PDF file ("self-extracting" gave me pause!) that was attached and found Infostealer.Snifula.B virus. This the first of this kind that I've seen so I thought I'd share! Be careful!
Lyte
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|
| |
11-16-2006, 08:10 PM
|
#2 | | Sophomore
Join Date: Oct 2006 Location: USA! USA! USA!
Posts: 141
Rep Power: 3  | stupid phishers!!! i hate these kinds of people! Viruses are coming new every day.
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. |
| |
11-16-2006, 10:41 PM
|
#3 | | Freshman
Join Date: Nov 2006 Location: Iowa USA
Posts: 10
Rep Power: 0  | Quote: |
stupid phishers!!! i hate these kinds of people! Viruses are coming new every day.
| this isn't a phishing scheme.
this is a backdoor trojan designed to take any and all personal information (e.g. credit cards, passwords, bank account number, etc...) and send it to the creator. It is also a self propagating worm, it will use your email address book to send the same email to anyone in your address book, using it's own IP Proxy tha is packed with it.
This is a very dangerous virus, if you open it, you need to contact your credit card companies, your bank, and any other place that you may have listed in the computer.
__________________
******************************************** Registered Linux User #400602 |
| |
11-16-2006, 11:26 PM
|
#4 | | Sophomore
Join Date: Oct 2006 Location: USA! USA! USA!
Posts: 141
Rep Power: 3  | Thats phishing Quote: |
to send ruse e-mail with a link to a replica of an existing web page, designed to fool users into submitting personal, financial, or password information; to defraud someone using this method; also, to create a website replica for fooling unsuspecting Internet users into submitting personal or financial information or passwords
|
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. |
| |
11-16-2006, 11:34 PM
|
#5 | | Head Mistress
Join Date: Oct 2005 Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7  | Quote: |
Originally Posted by Dragon This is a very dangerous virus, if you open it, you need to contact your credit card companies, your bank, and any other place that you may have listed in the computer. | Well, I opened the email but not the PDF file. Am I still in trouble?!
Lyte
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|
| |
11-16-2006, 11:38 PM
|
#6 | | Sophomore
Join Date: Oct 2006 Location: USA! USA! USA!
Posts: 141
Rep Power: 3  | no, they cant take any info from you, i think... What e-mail provider you use?
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. |
| |
11-17-2006, 12:30 AM
|
#7 | | Head Mistress
Join Date: Oct 2005 Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7  | Well, this was coming straight through PC101's server (hosting company) because it came to info.at.pc101.dot.com It didn't come through my yahoo account. So, someone snatched it off the site.
I've got the email addy from which it came but I'm sure it's either bogus or it's a legitimate site and the evil doer is just using their name as a cover.
Lyte
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|
| |
11-17-2006, 09:44 AM
|
#8 | | Freshman
Join Date: Nov 2006 Location: Iowa USA
Posts: 10
Rep Power: 0  | Quote: |
Originally Posted by Lyte Well, I opened the email but not the PDF file. Am I still in trouble?!
Lyte | as long as the email is readable by bots they can get it. I encode all my email addresses on my site to confuse the bots.
your info is safe as long as you dont' open the PDF file.
__________________
******************************************** Registered Linux User #400602 |
| |
11-17-2006, 02:58 PM
|
#9 | | Head Mistress
Join Date: Oct 2005 Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7  | How would I go about encoding PC101's email??
I'm suddenly getting a LOT of spam. Grr!
Thanks!
Lyte
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|
| |
11-19-2006, 07:53 PM
|
#10 | | Freshman
Join Date: Nov 2006 Location: Iowa USA
Posts: 10
Rep Power: 0  | as long as you are able to change the actual code, you can replace your email info with unicode.
you can go here and it will do it all for you.
just put your email address there in top box. click on convert and then copy and paste the new code from the lower box in place of what is there currently.
I don't know if this will work in the profiles of forum software or not.
to make this work it would be taking the information like the following line in your html Code: <h ref=:"mailto:you@yourserver.com">you@yourserver.com</a> and replacing it with the unicode from that site as shown. Code: <a href="mailto:{place unicode here}>{place unicode here}</a> the browser will make it look like ![[email address]](http://www.pc101.com/forum/?emailimage=94d096f0e95bf3da736cd374609bdc5e) but to the bots it will look like a bunch of garbage.
__________________
******************************************** Registered Linux User #400602 |
| |
11-20-2006, 11:43 AM
|
#11 | | Head Mistress
Join Date: Oct 2005 Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7  | Thanks Dragon,
I'll replace the code and give it a test. Thanks!
Lyte
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|
| |
11-20-2006, 01:52 PM
|
#12 | | Senior
Join Date: Nov 2005 Location: Northern Arizona
Posts: 660
Rep Power: 4  | Hey Lyte,
Next time you get these "phishing" scam e-mails......just forward them to: ![[email address]](http://www.pc101.com/forum/?emailimage=66da23d6b350f34bcc03cf39c8a2e663)
These addresses are very important to cut down on "phishing scams".
__________________ May Your Wishes Come True !! DR911 Goverment Grant & Loan Infomation To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. |
| |
11-20-2006, 05:17 PM
|
#13 | | Head Mistress
Join Date: Oct 2005 Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7  | Doc, kewl... when I get home I'll see if I can't find that email addy. You know I got another at one of my yahoo emails!
Lyte
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|
| |  | | Thread Tools | | | | Display Modes | Linear Mode |
Posting Rules
| You may not post new threads You may not post replies You may not post attachments You may not edit your posts HTML code is Off | | |
All times are GMT -5. The time now is 07:17 AM.
Powered by vBulletin Version 3.7.0 Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0 RC5
|