Home   >>   Security   >>   combined phish and virus?
combined phish and virus?
About Securehotel - Security

We usually get sent phish emails to see if they are legit but here is a  good one.

the email came from 123Greetings.com < This e-mail address is being protected from spambots. You need JavaScript enabled to view it >with an attachment ecard.zip which is a classic trojan virus.

The difference was the content of the email. See the screenshot.  This user just about managers their website and email let alone twitter.


The headers also give away some clues (sensitive info removed)

Return-path: < This e-mail address is being protected from spambots. You need JavaScript enabled to view it >
Envelope-to:
Delivery-date: Sun, 06 Jun 2010 10:38:07 -0500
Received: from [95.175.67.234] (port=2832)
(envelope-from < This e-mail address is being protected from spambots. You need JavaScript enabled to view it >)
id 1OLHuf-0002IV-LX
Received: from [95.175.67.234] by mailin-02.mx.aol.com; Sun, 6 Jun 2010 18:37:24 +0300
Date:    Sun, 6 Jun 2010 18:37:24 +0300
From:    "123Greetings.com" < This e-mail address is being protected from spambots. You need JavaScript enabled to view it >
X-Mailer: The Bat! (v3.64.05) Professional
Reply-To: This e-mail address is being protected from spambots. You need JavaScript enabled to view it
X-Priority: 3 (Normal)
Message-ID: < This e-mail address is being protected from spambots. You need JavaScript enabled to view it >

 

Add comment


Security code
Refresh

Latest Posts

You need to modify this file
components/com_k2/models/item.php Read More ...
Due to the summer holidays, the next meeting is scheduled for the end of August.. Dont forget to bring back send a postcard and bring back a stick of rock for everone! Read More ...
We usually get sent phish emails to see if they are legit but here is a  good one. the email came from 123Greetings.com <ecards@123greetings.com>with an attachment ecard.zip which is a classic trojan virus. Read More ...
I was recently asked via twitter {xtypo_quote}@mandville how do u cope with the volume @ joomla forums?{/xtypo_quote} Read More ...
We dont send emails like this Dear Webmail/E-mail user,

This message is from our Webmail Messaging Center to all our account
owners.We are currently upgrading our database and e-mail center. We are
deleting all unused webmail account to create more space for new accounts. Read More ...

The Joomla!(R) name is used under a limited license from Open Source Matters in the United States and other countries. Securehotel.org.uk is not affiliated with or endorsed by Open Source Matters or the Joomla! Project.