RSS feed of Security Labs Alerts from M86 Security

Greeting Card Spam

 

July 2, 2007

There are large numbers of fake greeting card email being spammed at present.  Only its not just spam, it carries a malicious payload if you choose to follow the link.

The email has a subject line along the following lines:

You've received a (greeting|post|e)card from a (colleague|mate|family member|friend)

And a message content similar to:

 

Good day.

Your mate has sent you a greeting card from greetingCard.Org.

Send free ecards from greetingCard.Org with your choice of colors, words and music.

Your ecard will be available with us for the next 30 days. If you wish to keep
the ecard longer, you may save it on your computer or take a print.

To view your ecard, choose from any of the following options:

--------
OPTION 1
--------

Click on the following Internet address or
copy & paste it into your browser's address box.

http://XX.XX.XXX.XXX/?4eec46dc539e3b14a79bb24c4d2c855844a49

--------
OPTION 2
--------

Copy & paste the ecard number in the "View Your Card" box at
http://XX.XX.XX.XXX/

Your ecard number is
4eec46dc539e3b14a79bb24c4d2c855844a49

Best wishes,
Postmaster,
greetingCard.Org

If the website is visited, it will automatically try a number of common browser exploits.  If this doesn't work, users are also presented with a link to download a Trojan file called ecard.exe. 

While the latest MailMarshal SpamCensor version provides excellent protection against this spam, users should be aware of its malicious nature.

For more information, there are some good analyses here:

http://asert.arbornetworks.com/2007/06/you-got-postcard-malware

http://isc.sans.org/diary.html?storyid=3063


Last Reviewed: July 13, 2007