Archive for July, 2008

Airline E-ticket Email Scam

Add comment July 31st, 2008

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!

With so many people cutting back on travel because of the high fuel prices the chance of getting a ‘free’ airline ticket anywhere will surely entice some percentage of people to open this attachment and get infected. If it sounds too good to be true… you know the saying.

CudaMail is currently blocking these as Trojan.Zbot variation.

- Shaun

US-CERT Current Activity

Airline E-ticket Email Attack

Original release date: July 31, 2008 at 9:15 am Last revised: July 31, 2008 at 9:15 am

US-CERT is aware of public reports indicating that a new email attack is circulating. This attack uses email messages that appear to be from legitimate airlines and contain information about a bogus e-ticket.

These email messages instruct the user to open the attachment to obtain the e-ticket. If a user opens this attachment, a file may be executed to infect the user’s system with malicious code.

Reports, including a posting by Sophos, indicate that these messages have the following characteristics. Please note that these attributes may change at any time.

  • The subject line “E-Ticket#XXXXXXXXXX”
  • An attachment named “eTicket#XXXX.zip”

US-CERT encourages users and administrators to take the following preventative measures to help mitigate the security risks:

  • Install anti-virus software, and keep its virus signature file up to date.
  • Do not open attachments in unsolicited email messages.
  • Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.
  • Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.

Relevant Url(s):

====

This entry is available at

Here are some more Blog articles on Airline Ticket Email Scams:

 

Popularity: 20% [?]

The Register - “Beloved Websites Riddled With Crimeware”

Continue Reading Add comment July 30th, 2008

Great but quick article on how any website can be taken over and a great reason to use something like the Barracuda Website Firewall in front of your web servers.

The FBI Facebook Storm Worm Scam

Continue Reading Add comment July 29th, 2008

With the 4 year prison term for Robert Soloway and the Murder/Suicide of Eddie Davidson still fresh in our minds comes the following alert from the US-Cert warning us that the subject of the FBI looking at Facebook is being used to spread a new variation of the Storm Worm.

The U.S. Customs and Border Protection Email Scam

Continue Reading Add comment July 25th, 2008

Be wary of any email that claims to come from U.S. Customs and Border Protection as there are reports of an attack circulating via bogus email messages that claim to be from “US Customs Service.”

From “Fastflux” to “Hydraflux”: A Brief History Of The Botnet

Continue Reading Add comment July 21st, 2008

I’m not sure if you’ve been reading the news over at the Internet Storm Center recently but … they have a an interesting write up on what William Salusky dubs the “Hydraflux” that is worth reading.

US-CERT Says “New Storm Worm Variant Spreading!”

Continue Reading Add comment July 10th, 2008

US-CERT is warning everyone that Spammers and Hackers are at it again with the “Storm Worm” using news of a fictitious US war with Iran to get you to open their email.

Update of the McAfee S.P.A.M Experiment

Continue Reading Add comment July 2nd, 2008

While McAfee is supposed to release the full report today one mother of three named Tracey Mooney has already talked to Network World and given her version of the experience of being deliberately naive on the Internet for a month. The outcome?

Archives

Categories

July 2009
M T W T F S S
« Jun «-»  
 12345
6789101112
13141516171819
20212223242526
2728293031  

White T-Shirt

$18.99

Meta