Friday, December 17, 2010

Amazon shipping update email spreads malware attack in time for Christmas

Researchers at SophosLabs have intercepted a malware campaign that has been spammed out, pretending to be a notice from Amazon.com.

The emails headers are forged to look like it was sent from order-update@amazon.com, here are some details from the email to help you detect these fraudulent emails:

Subject : Shipping update for your Amazon.com order
Message text : Shipping update for your Amazon.com order [number]
Attached file : Shipping documents.zip

Whatever you do, don't open the attached ZIP file as it contains malware. Sophos detects it as W32/AutoRun-BHY and the ZIP file as Troj/BredoZp-BD.


Screenshot of email
via: Naked Security

No comments:

Post a Comment