More eCard Malware, Now Taking Advantage of Popular Russian Postcard Site

January 21st, 2008 by Rebecca Herson | Category: Email Security, Spam Favorites |

Thought we were done with ecards? Not yet! Just in from our detection center: a new blended threat with emails in Russian and English, purporting to be a postcard from a friend from the popular postcard site postcard.ru, but actually links to a site that tries to download an .exe file to the user’s computer. The scam email links to a malware site, not to the legitimate postcard.ru. The malware site looks like a postcard, however with the added “bonus” of an automatic download:

Fake Postcard.ru malware web site

I visited postcard.ru and sent myself a postcard from the site, just to see what their emails look like. Of course if phishers can design their emails to appear like they are coming from Chase Manhattan or Citibank, then malware writers can easily copy a text email message word for word. But still, it’s uncanny how much the two emails look alike. However the easiest way to tell the two emails apart is to hover the mouse over the hyperlink in the email, so you can see that the malicious email is simply pretending to link to postcard.ru, and is really directing the recipient to a different site.

The malware email:

Postcard.ru scam malware email message

The legitimate email from postcard.ru:

Legitimate email from postcard.ru

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

Related posts

 

3 Responses

  1. Infosecurity » Blog Archive » Завтра день Святого Валентина. Осторожно!

    [...] Блог компании Commtouch (лучшие спам-фильтры для корпоративных почтовых серверов в 2007 году) заранее предупредил об опасности, которую следует ожидать в связи с днём Святого Валентина. [...]

  2. Russian Postcard Spam is Back | Commtouch Café

    [...] new, massive outbreak of Russian postcard spam is underway, similar to the previous outbreak I wrote about a few weeks back. We know why spammers [...]

  3. Jeff

    Do you have any information on the threat malware? I got infected a couple of weeks ago (I think my computer is a zombie) and the latest versions of Symantec Antivirus and AVG Free can’t find the infection.

Leave a Comment

`