Malware New Year Greeting Emails

The barrage of bogus greeting card emails that have been hitting inboxes for months has now shifted its theme from Christmas to New Year.

The Happy New Year emails include links that supposedly leads to such items as a "greeting card" or a "2008 song". However, those who click on the link will be taken to a website that tries to entice visitors into downloading a malicious .exe file.

New Year Scam Website

There have already been several different versions of these malware messages and more are likely to follow. Be very cautious of any Happy New Year messages that claim to contain links to greeting cards, songs, or other New Year orientated material

Examples:

A New Year 2008 song

Happy 2008!
[LINK REMOVED]


Happy New Year To (email address removed)

New 2008 Year Greeting Card
[LINK REMOVED]

posted by Brett Christensen @ 8:25 AM, ,


The Red Rock Hikers Stranger Encounter Video

A somewhat disturbing YouTube video featuring what seems to be a terrifying, and apparently deadly, encounter between a hiking couple and an alien being is currently generating plenty of speculation, and perhaps a degree of fear, among some Internet users.

Indeed, the first time I viewed the footage, it did raise a few goose bumps!

According to the information that goes with the video, the footage was discovered in a camcorder apparently left at the scene by two missing hikers, Scott Pendleton and Jennifer Fox. The obviously amateurish camera work and seemingly unrehearsed dialog in the video make it seem quite possible that it really is a home movie.

If you haven't already seen this video, can I suggest that you go have a look yourself and see what you think?

Click Here to Watch Video

If you are happy to believe that the encounter featured in the video is genuine, then good luck to you and thanks for stopping by. But if the skeptic in you comes to the fore, you can read my further analysis of the video by scrolling down past the following, scary, but completely unrelated ghost picture:




























If you've read this far, you've probably guessed that the video is actually a clever piece of cinema, not genuine footage.

The couple in the "mockumentary" are actors Kyle Rankin and Karen Zumsteg. The short film, called Case Tape 347 was made by New Born Pictures in 2005. The piece is quite reminiscent of the movie, The Blair Witch Project.

And, by the way, if you are curious about the "ghost" in the picture I've used as a spoiler-block above, you can read more about her here:

Sundarbans Ghost Chain Letter

posted by Brett Christensen @ 7:17 AM, ,


Send Cards to Wounded US Soldiers via Red Cross

In another article, I discussed an email forward that claimed that people can send Christmas greetings to wounded soldiers by addressing cards to "A Recovering American soldier" care of the Walter Reed Army Medical Center.

This claim is false in that, due to security issues, cards sent to "A Recovering American soldier" or similar will not be accepted by Walter Reed Army Medical Center and no soldiers will receive them.

However, on 5th December 2007, the American Red Cross and Pitney Bowes announced an initiative that allows people to send greeting cards and messages to soldiers via the Red Cross. The following press release provides details of this new initiative:

America's wounded soldiers are always grateful for supportive cards and notes – especially during the holiday season.

This season, communities across America are invited to mail holiday greeting cards along with personal messages of support to wounded service members at military hospitals around the country through a unique partnership between the American Red Cross and Pitney Bowes Inc.

With the support of the Department of Defense, Walter Reed Army Medical Center and with help from Pitney Bowes Government Solutions, the American Red Cross will collect, review and disseminate holiday greeting cards to wounded military personnel. For security reasons, the Red Cross will only be able to accept holiday cards, not packages. Red Cross volunteers will receive and bundle the cards to be shipped by Pitney Bowes Government Solutions. Then, Red Cross volunteers at military medical facilities will distribute the cards to patients and their families in time for the holidays.

"So many Americans want to show their support and gratitude by reaching out to wounded service members at Walter Reed and other medical centers during the holiday season," said Neal Denton, American Red Cross Senior Vice President for Service to the Armed Forces. "With the support of the Department of Defense, Walter Reed leadership and Pitney Bowes, we can bring a little cheer to those soldiers," added Denton.

"It is an honor to provide this small measure of comfort at holiday time to those who have sacrificed so much," said Pitney Bowes President and CEO Murray Martin. "We want to make it as easy as possible for all Americans to show their appreciation to the men and women who serve this nation so proudly and selflessly."


Holiday cards should be addressed to:

We Support You During Your Recovery!

c/o American Red Cross

PO Box 419

Savage, MD 20763-0419

Be sure to affix adequate postage. Cards must be received no later than December 27. Cards received after this date will be returned to sender. Senders are reminded that “care packages” are not part of the program. Cards and notes only – and please refrain from using glitter or any other inserts that would not be appropriate in a hospital environment.

posted by Brett Christensen @ 11:10 AM, ,


Christmas malware eCard Notifications

Predictably, criminals have begun using bogus Christmas eCard notification emails to distribute malware. Emails, ostensibly from 123Greetings.com, claim that the recipient has been sent an eCard from a "dear friend". The user is instructed to click a link to view the eCard.

Clicking the link runs an .exe file that displays a Christmas greeting card image on the users's computer. However, it also installs malware that can give the attacker access to the compromised computer. It can also install other malware that can then turn the computer into a zombie that can be used to distribute spam without the knowledge of the user.

As Christmas approaches, other Christmas orientated malware attacks are likely to follow. Be very cautious of any eCard notification emails that you receive.

An example of the malware email:

Dear friend,

A dear friend has sent you an ecard from http://www.123Greetings.com

Your ecard will be available with us for the next 30 days. If you wish
to keep the ecard longer, you may save it on your computer or take a
print.

To view your ecard, CLICK HERE
Your ecard number is
HF11128094935247
Best wishes,
http://www.123Greetings.com


More Information:
Merry Christmas and so on
Backdoor.IRC.Zapchast

posted by Brett Christensen @ 10:58 AM, ,


Another Grant Scam Email

In another article, I discussed a scam email that purported to be a grant offer from the Freemasons in the UK. This grant tactic is one that is increasingly be used by scammers. The messages claim that the "lucky" recipient has been awarded a large cash grant or donation to be used as they see fit. They usually name a real organization that does offer grants or donations to make the bogus "offer" seem more legitimate.

Of course, there is no grant and the supposed grant offers do not originate from the organizations named in the messages. Those who fall for this ruse and reply may be tricked into sending money and sensitive personal information to the scammers, ostensibly to allow the non-existent "grant" to be processed. All money sent will be pocketed by the scammers and the personal information may be used to steal the victim's identity.

Be very cautious of any message that claims that you have been awarded a grant that you never even applied for. Legitimate organizations DO NOT award grants out of the blue to individuals for their own personal use.

The version of the scam included below claims that the recipient has been awarded a grant of $1,350,000.00 from Fondation De France(FDF):

Subject: FDF GRANT AWARD
THE FOUNDATION DE FRANCE(FDF)
http://www.fdf.org

The Fondation De France(FDF) would like to notify you that you have been chosen by the board of trustees as one of the final recipients of a cash Grant/Donation for your own personal, educational, and business development.

The FDF, established 1977 by the Multi-Million groups and now supported by the Economic Community for West African States (ECOWAS), United Nations Organization (UNO) and the European Union (EU) was conceived with the objective of human growth, educational, and community development.

In conjunction with the ECOWAS, UNO and the EU, We are giving out a yearly donation of US$1,350,000.00 (One Million, Three Hundred And Fifty Thousand United States Dollars)each to 100 lucky recipients.These specific Donations/Grants will be awarded to 100 lucky international recipients worldwide; in different categories for their personal business development and enhancement of their educational plans. This is a yearly program, which is a measure of universal development strategy.

You are required to contact the Executive Secretary below, for qualification documentation and processing of your claims. After contacting our office,you will be given your donation pin number, which you will use in collecting the funds. Please endeavor to quote your Qualification numbers (FDF-444-6647-9163)in all discussions. You are also required to contact the executive sec. with the following requirements

DONATION REQURIEMENTS:

1. Full names:
2. Residential address:
3. Phone number:
4. Fax number:
5. Occupation:
6. Sex:
7. Age:
8. Nationality:
9. Present Country:
10.Next of kin name/address

Executive Sec. Mr. Arthur Dion
Email: contact_arthur_dion@yahoo.fr

You are by all means hereby advised to keep this whole information confidential until you have been able to collect your donation, as there have been many cases of double and unqualified claim, due to beneficiaries informing third parties about his/her donation.

Regards.
Mrs. Maria Riccardo
(Foundation officer)

posted by Brett Christensen @ 10:57 AM, ,