Nastygram: Bogus DHL e-mails harbor secret message

November 30th, 2009 admin

A recent spam run that tries to distribute malicious software disguised as a DHL package tracking number contains a poorly hidden message that insults the Security Fix author by name. According to an analysis by security firm Sophos, the messages arrive as a “Dear Customer” notification stating that the courier company was unable to deliver a parcel to the recipient’s address. The message urges recipients to click the attached “shipping label” for more information, and of course the attachment is a malicious program designed to steal the curious victim’s passwords. Sophos said the tracking number cited in the messages appears to be a jumbled mush of letters, but closer inspection reveals an insult aimed at this author. (Suffice it to say, it is off-color enough that it cannot be repeated here.) …


Originally posted on SecurityFix

 
  Related Posts
Nastygram: CDC ’swine flu’ vaccine scam
Nastygram: CDC ’swine flu’ vaccine scam
E-mail scam artists are impersonating the Centers for Disease Control with a bogus e-mail that claims to offer information about a state-run vaccination program for the H1N1 “Swine Flu” contagion. This highly topical and plausible e-mail message directs recipients to a fake CDC Web site that tries to foist malicious software. Recipients... 
Nastygram: MySpace phish plants spy software
Nastygram: MySpace phish plants spy software
A new spam campaign targeting MySpace.com users once again illustrates the blended threat from junk e-mail attacks, experts warn. This latest run tries to lure recipients into giving up their MySpace credentials, and then attempts to trick victims into installing password-stealing malicious software. Attackers began blasting out the junk e-mails... 
New Password-stealing Virus Targets Facebook Users
Hackers have flooded the Internet with virus-tainted spam that targets Facebook’s estimated 400 million users in an effort to steal banking passwords and gather other sensitive information. The emails tell recipients that the passwords on their Facebook accounts have been reset, urging them to click on an attachment to obtain new login credentials,... 
Fake Lawsuit Notification Attack
Fake Lawsuit Notification Attack
A few of days ago, we encountered an e-mail with a malicious RTF attachment. It was sent with a supposed lawsuit notification message. The e-mail didn’t mention any company by name and took a shotgun, rather than targeted, approach. Today, a security blogger forwarded us (and others) his version of the e-mail: At this point, it appears that... 
Border Patrol Asks People To Text Message Suspicious Activity
The U.S. Border Patrol is asking residents along a section of the U.S.-Canada border to send anonymous text messages to report any suspicious people they come across. The pilot program announced Tuesday is for the border area that runs from the Cascade Range in Washington to the Continental Divide in Montana. It allows residents, campers, hunters... 
Graffiti Message in Juarez Warns of Another Car Bomb
A graffiti message found Sunday night in Juárez warned U.S. law enforcement that another car bombing will occur if they do not arrest corrupt federal police agents. The unsigned message told the FBI and the U.S. Drug Enforcement Administration to investigate authorities that support the Sinaloa drug cartel. Otherwise, there will be another car bomb... 
Report: Programmer Conned CIA, Pentagon Into Buying Bogus Anti-Terror Code
A programmer who claims he produced software that detected hidden terrorist messages in Al Jazeera broadcasts was responsible for a false alert in 2003 that grounded international flights and raised the government’s security level, according to a remarkable story published by Playboy . The developer also allegedly faked software demonstrations... 
Merry Christmas, Idiot
Merry Christmas, Idiot
It’s not a huge surprise that we are seeing some malware spam runs where the malicious attachment attempts to portray itself as a Christmas Greeting of some sort. Here’s an example from today (md5: C670165AE6DFA8318F0EA795B1D3AD55). This one is actually a Zapchast (IRC bot variant). The “Christmas Card” requires it’s... 
Iran Incursion Into Iraq Was Message To Washington
This is an item worth paying attention to. It seems as though many folks have concluded that last week’s incursion by Iranian forces into Iraq, and onto an old oil well, was a minor, meaningless story. A popular, benign, interpretation is that it was just a few, rogue Iranian forces foolishly hoisting a flag onto a This story comes to us via... 
Nastygram: Beware the NACHA gotcha
Nastygram: Beware the NACHA gotcha
Cyber thieves on Thursday began blasting out millions of e-mails impersonating NACHA – The Electronic Payments Association, a not-for-profit group that develops operating rules for organizations that handle electronic payments, from payroll direct deposits to online bill pay services. The missives in this latest scam arrive with various subject... 
  Related Tweets from Twitter

There was an error processing the Feed, if this is your page, please check the information provided in your profile.

  Related News from Digg
No comments yet.
You must be logged in to post a comment.
TOP