M86 Security Labs
RSS feed of Security Labs Alerts from M86 Security

New Storm 'Confirmation' spam

 

August 21, 2007

Again, the email "Storm" has morphed. Today the subject and content revolves around membership 'confirmation' of various organisations.   Here are some sample subjects:

New Member Confirmation
New User Letter
Login Info
Member Confirm
Registration Details
Tech Department
Please Confirm
Member Details
Welcome New Member
New User Support
Internal Verification
User Services


The body of the message is plain text and 'supplies' a membership number, login, and password. 
 


  

As before, the link leads to a website with malicous code which may exploit vulnerabilities in your browser, or prompt you to download malicious files.  In this case the file is called 'applet.exe'.

As before, be wary of clicking on links in any unsolicited email, and in light of these recent storm messages, be doubly suspicious of any links with an IP address.

Marshal updated the SpamCensor today to detect these messages as spam. MailMarshal customers should ensure their installations are running at least SpamCensor Version 190.


Last Reviewed: August 26, 2007