Site Statistics
 
Threads: 4,062
Posts: 17,767
Members: 3,097
Users Online: 16
Newest Member: ronjohnson715


Go Back   PC101 > Computer Related Forums > PC Security

PC Security A place to discuss new threats, firewalls, virus scanners, and all other aspects of keeping your computer secure from threats. Learn how to stop spyware... hackers ... identity thieves... and more!


Reply
 
LinkBack Thread Tools Display Modes
Old 11-16-2006, 06:16 PM   #1
Head Mistress
 
Lyte's Avatar
 
Join Date: Oct 2005
Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7 Lyte is on a distinguished road
Send a message via MSN to Lyte Send a message via Yahoo to Lyte Send a message via Skype™ to Lyte
WARNING - Invoice email containes a virus!

Howdy!

I just got this email at PC101's mail box...

Dear Customer,

Thank you for ordering from our internet shop. If you paid with a
credit card, the charge on your statement will be from name of our shop.

This email is to confirm the receipt of your order. Please do not
reply as this email was sent from our automated confirmation system.

Date : 06 Nov 2006 - 12:40
Order ID : 37679041

Payment by Credit card

Product : Quantity : Price
WJM-PSP - Sony VAIO SZ370 C2D T7200 : 1 : 2,449.99

Subtotal : 2,449.99
Shipping : 32.88
TOTAL : 2,482.87

Your Order Summary located in the attachment file (self-extracting
archive with "37679041.pdf" file ).

PDF (Portable Document Format) files are created by Adobe Acrobat
software and can be viewed with Adobe Acrobat Reader. If you do not already have this viewer configured on a local drive, you may download it for free from Adobe's Web site.

We will ship your order from the warehouse nearest to you that has your items in stock (NY, TN, UT & CA). We strive to ship all orders the same day, but please allow 24hrs for processing.

You will receive another email with tracking information soon.

We hope you enjoy your order! Thank you for shopping with us!


When I first saw this email I thought "OMG, someone must have gotten ahold of my credit card!" I scanned the PDF file ("self-extracting" gave me pause!) that was attached and found Infostealer.Snifula.B virus. This the first of this kind that I've seen so I thought I'd share! Be careful!

Lyte
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Lyte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-16-2006, 08:10 PM   #2
Sophomore
 
crafterz's Avatar
 
Join Date: Oct 2006
Location: USA! USA! USA!
Posts: 141
Rep Power: 3 crafterz is on a distinguished road
Send a message via AIM to crafterz Send a message via MSN to crafterz Send a message via Yahoo to crafterz
stupid phishers!!! i hate these kinds of people! Viruses are coming new every day.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
crafterz is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-16-2006, 10:41 PM   #3
Freshman
 
Dragon's Avatar
 
Join Date: Nov 2006
Location: Iowa USA
Posts: 10
Rep Power: 0 Dragon is on a distinguished road
Quote:
stupid phishers!!! i hate these kinds of people! Viruses are coming new every day.
this isn't a phishing scheme.

this is a backdoor trojan designed to take any and all personal information (e.g. credit cards, passwords, bank account number, etc...) and send it to the creator. It is also a self propagating worm, it will use your email address book to send the same email to anyone in your address book, using it's own IP Proxy tha is packed with it.

This is a very dangerous virus, if you open it, you need to contact your credit card companies, your bank, and any other place that you may have listed in the computer.
__________________
********************************************
Registered Linux User #400602
Dragon is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-16-2006, 11:26 PM   #4
Sophomore
 
crafterz's Avatar
 
Join Date: Oct 2006
Location: USA! USA! USA!
Posts: 141
Rep Power: 3 crafterz is on a distinguished road
Send a message via AIM to crafterz Send a message via MSN to crafterz Send a message via Yahoo to crafterz
Thats phishing

Quote:
to send ruse e-mail with a link to a replica of an existing web page, designed to fool users into submitting personal, financial, or password information; to defraud someone using this method; also, to create a website replica for fooling unsuspecting Internet users into submitting personal or financial information or passwords
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
crafterz is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-16-2006, 11:34 PM   #5
Head Mistress
 
Lyte's Avatar
 
Join Date: Oct 2005
Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7 Lyte is on a distinguished road
Send a message via MSN to Lyte Send a message via Yahoo to Lyte Send a message via Skype™ to Lyte
Quote:
Originally Posted by Dragon
This is a very dangerous virus, if you open it, you need to contact your credit card companies, your bank, and any other place that you may have listed in the computer.
Well, I opened the email but not the PDF file. Am I still in trouble?!

Lyte
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Lyte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-16-2006, 11:38 PM   #6
Sophomore
 
crafterz's Avatar
 
Join Date: Oct 2006
Location: USA! USA! USA!
Posts: 141
Rep Power: 3 crafterz is on a distinguished road
Send a message via AIM to crafterz Send a message via MSN to crafterz Send a message via Yahoo to crafterz
no, they cant take any info from you, i think... What e-mail provider you use?
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
crafterz is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-17-2006, 12:30 AM   #7
Head Mistress
 
Lyte's Avatar
 
Join Date: Oct 2005
Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7 Lyte is on a distinguished road
Send a message via MSN to Lyte Send a message via Yahoo to Lyte Send a message via Skype™ to Lyte
Well, this was coming straight through PC101's server (hosting company) because it came to info.at.pc101.dot.com It didn't come through my yahoo account. So, someone snatched it off the site.

I've got the email addy from which it came but I'm sure it's either bogus or it's a legitimate site and the evil doer is just using their name as a cover.

Lyte
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Lyte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-17-2006, 09:44 AM   #8
Freshman
 
Dragon's Avatar
 
Join Date: Nov 2006
Location: Iowa USA
Posts: 10
Rep Power: 0 Dragon is on a distinguished road
Quote:
Originally Posted by Lyte
Well, I opened the email but not the PDF file. Am I still in trouble?!

Lyte
as long as the email is readable by bots they can get it. I encode all my email addresses on my site to confuse the bots.

your info is safe as long as you dont' open the PDF file.
__________________
********************************************
Registered Linux User #400602
Dragon is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-17-2006, 02:58 PM   #9
Head Mistress
 
Lyte's Avatar
 
Join Date: Oct 2005
Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7 Lyte is on a distinguished road
Send a message via MSN to Lyte Send a message via Yahoo to Lyte Send a message via Skype™ to Lyte
How would I go about encoding PC101's email??

I'm suddenly getting a LOT of spam. Grr!

Thanks!

Lyte
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Lyte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-19-2006, 07:53 PM   #10
Freshman
 
Dragon's Avatar
 
Join Date: Nov 2006
Location: Iowa USA
Posts: 10
Rep Power: 0 Dragon is on a distinguished road
as long as you are able to change the actual code, you can replace your email info with unicode.

you can go here and it will do it all for you.

just put your email address there in top box. click on convert and then copy and paste the new code from the lower box in place of what is there currently.

I don't know if this will work in the profiles of forum software or not.

to make this work it would be taking the information like the following line in your html
Code:
<h ref=:"mailto:you@yourserver.com">you@yourserver.com</a>
and replacing it with the unicode from that site as shown.
Code:
<a href="mailto:{place unicode here}>{place unicode here}</a>
the browser will make it look like [email address] but to the bots it will look like a bunch of garbage.
__________________
********************************************
Registered Linux User #400602
Dragon is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-20-2006, 11:43 AM   #11
Head Mistress
 
Lyte's Avatar
 
Join Date: Oct 2005
Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7 Lyte is on a distinguished road
Send a message via MSN to Lyte Send a message via Yahoo to Lyte Send a message via Skype™ to Lyte
Thanks Dragon,

I'll replace the code and give it a test. Thanks!

Lyte
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Lyte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-20-2006, 01:52 PM   #12
Senior
 
dr911's Avatar
 
Join Date: Nov 2005
Location: Northern Arizona
Posts: 660
Rep Power: 4 dr911 is on a distinguished road
Hey Lyte,

Next time you get these "phishing" scam e-mails......just forward them to:

[email address]

[email address]

These addresses are very important to cut down on "phishing scams".
__________________
May Your Wishes Come True !!

DR911

Goverment Grant & Loan Infomation


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
dr911 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-20-2006, 05:17 PM   #13
Head Mistress
 
Lyte's Avatar
 
Join Date: Oct 2005
Location: Good ol' U.S. of A
Posts: 3,470
Rep Power: 7 Lyte is on a distinguished road
Send a message via MSN to Lyte Send a message via Yahoo to Lyte Send a message via Skype™ to Lyte
Doc, kewl... when I get home I'll see if I can't find that email addy. You know I got another at one of my yahoo emails!

Lyte
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Lyte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Modification] EMail Address Obfuscator v1.0.2 Lyte vBulletin 0 09-21-2006 02:14 PM
All about Virus Janine PC Security 1 07-08-2006 11:45 AM
SMS vs. Mobile Email Will.Spencer Hardware 0 06-13-2006 06:32 AM
Urgent Virus Warning from Nero aleeonline PC Security 0 04-17-2006 03:47 PM
Create email stationery with Outlook Express! Lyte Tutorials and How-To... 0 03-06-2006 09:52 PM



All times are GMT -5. The time now is 07:17 AM.

Powered by vBulletin Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0 RC5