Malware Email Example #005 (Vaio Order)
Please be sure to read my Malware Home Page
NOTE: This page Under Construction/Conversion
This page has not been completely converted to OFPv2 Standards.
When this is completed, this paragraph will go away.
Meanwhile, all external links on this page open a new window.
Things I Did, Below
I, personally, receive email in HTML format. The following was received (and looked) like I received it.
- I removed my email addresses. These came to various accounts and some no longer exist. There are places on this site you can get hold of me if you wish or need to. They are protected from spambots using JavaScript, but all you have to do is click on them.
- All scammer and related email addresses, and any actual website links have been changed, at least putting spaces into them. They appear as underlined blue links, though they aren't.
- Any notes I added in the actual letter are in square brackets ("[" "]"), are bold, red in color, and highlighted. If what I found "behind the links" (email or website) are different than what was displayed, I will include them in this type of note.
- All spelling, spacing, line-wrapping, and punctuation errors are the ones that appeared in the original received email. (I may or may not analyze some or all of these.)
Malware Email Example 005
Received 11/01/2006 (a); 11/07/2006 (b); 11/25/2006 (c)
I received this email from two separate emailers, about a week apart, then another copy about three weeks later, all with the same content.
[a]
From: customercare @ zipzoomfly.com
To: bigwillp @ hotmail.com
Sent: Wednesday, November 01, 2006 12:48 PM
Subject: Your 37679041 order information
[b]
From: customercare @ bestbuy.com
To: lexapro345 @ hotmail.com
Sent: Tuesday, November 07, 2006 10:35 AM
Subject: Your 37679041 order information
[c]
From: info @ zipzoomfly.com
To: yaeyo @ hotmail.com
Sent: Saturday, November 25, 2006 12:59 PM
Subject: Order ID : 37679041
[content of all three of the above]
Dear Customer,
Thank you for ordering from our internet shop. If you paid with a credit card, the charge on your statement will be from name of our shop.
This email is to confirm the receipt of your order. Please do not reply as this email was sent from our automated confirmation system.
Date : 08 Oct 2006 [a]
06 Nov 2006 [b] - 12:40
24 Nov 2006 - 12:55 [c]
Order ID : 37679041
Payment by Credit card
Product : Quantity : Price
WJM-PSP - Sony VAIO SZ370 C2D T7200 : 1 : 2,449.99
Subtotal : 2,449.99
Shipping : 32.88
TOTAL : 2,482.87
Your Order Summary located in the attachment file ( self-extracting archive with "37679041.pdf" file ).
PDF (Portable Document Format) files are created by Adobe
Acrobat software and can be viewed with Adobe Acrobat
Reader.
If you do not already have this viewer configured on a
local drive, you may download it for free from Adobe's
Web site.
We will ship your order from the warehouse nearest to you that has your items in stock (NY, TN, UT & CA). We strive to ship all orders the same day, but please allow 24hrs for processing.
You will receive another email with tracking information soon.
We hope you enjoy your order! Thank you for shopping with us!
[NOTE: That's the whole message, except for the attachment. It came to one of my Hotmail addresses (none of which are the ones listed in the TO:s
I left names, email addresses, and phone numbers in here for the search engines to find. DO NOT TRY TO CONTACT THEM! They sent a virus! -LE]
This email included an attached file, "37679041.pdf.zip (24.7 KB) [a] (24.8 KB) [b]", "37679041.pdf.exe (19.6 KB) [c] which is a "double-extension" file. Remember, the outer extension is used to chose the program to run.
The line that says it's a "self-extracting archive" is patently wrong for [a] and [b]. Any of those from WinZip that I've seen are executables (.exe). I know, because I've tried to send pictures to family that way, and they've been rejected because they ARE executables! As for the one from [c], since I'd already received the others, I KNEW what this was.
Example Email 005a Headers
11/01/2006
If you're not interested in the technical aspect of the headers, skip to Example 005 Notes
X-Message-Status: n:0
X-SID-PRA: customercare @ zipzoomfly.com
X-SID-Result: Fail
X-Message-Info: LzIk29jQYuLz2BMnKMQE9mKDwn4VOGonpxbPCp9NKFk=
Received: from host167.190-30-38.telecom.net.ar
([190.30.38.167]) by bay0-mc1-f19.bay0.hotmail.com with
Microsoft SMTPSVC(6.0.3790.2444);
Wed, 1 Nov 2006 09:47:29 -0800
Date: Wed, 01 Nov 2006 21:48:57 +0400
From: customercare @ zipzoomfly.com
Message-ID: <53791116.07591976 @ rebutted.com>
To: bigwillp @ hotmail.com
Subject: Your 37679041 order information
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----------60904D8BD2CE1E0"
Return-Path: customercare @ zipzoomfly.com
X-OriginalArrivalTime: 01 Nov 2006 17:47:30.0543 (UTC)
FILETIME=[CD967FF0:01C6FDDD]
[NOTE: The rest of the email was the text (above block) and a large block of random-looking letters (this would be the attachment).
I left names, email addresses, and phone numbers in here for the search engines to find. DO NOT TRY TO CONTACT THEM! They sent a virus! -LE]
Example Email 005b Headers
11/07/2006
X-Message-Status: n:0
X-SID-PRA: customercare @ bestbuy.com
X-SID-Result: SoftFail
X-Message-Info:
txF49lGdW432hwgH3AGNOJKedOdL/uUK3gVkRTe8tss=
Received: from
host78-36-dynamic.6-87-r.retail.telecomitalia.it
([87.6.36.78]) by bay0-mc3-f14.bay0.hotmail.com with
Microsoft SMTPSVC(6.0.3790.2444);
Tue, 7 Nov 2006 07:44:08 -0800
Date: Tue, 07 Nov 2006 10:35:27 -0500
From: customercare @ bestbuy.com
Message-ID: <64729615.45834382 @ inflict.com>
To: lexapro345 @ hotmail.com
Subject: Your 37679041 order information
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----------589D54D8CC6EC34"
Return-Path: customercare @ bestbuy.com
X-OriginalArrivalTime: 07 Nov 2006 15:44:09.0838 (UTC)
FILETIME=[90E708E0:01C70283]
[NOTE: The rest of the email was the text (above block) and a large block of random-looking letters (this would be the attachment).
I left names, email addresses, and phone numbers in here for the search engines to find. DO NOT TRY TO CONTACT THEM! They sent a virus! -LE]
Example Email 005c Headers
11/25/2006
X-Message-Status: n:0
X-SID-PRA: info @ zipzoomfly.com
X-SID-Result: Fail
X-Message-Info:
LsUYwwHHNt0+VCwh1uWeSHKFumlSGJryrymPOdEsHkA=
Received: from segment-124-7.sify.net ([124.7.128.158])
by bay0-mc7-f12.bay0.hotmail.com with Microsoft
SMTPSVC(6.0.3790.2444);
Sat, 25 Nov 2006 10:02:06 -0800
Date: Sat, 25 Nov 2006 19:59:56 +0200
From: info @ zipzoomfly.com
Message-ID: <91062047.45321693 @ comb.com>
To: yaeyo @ hotmail.com
Subject: Order ID : 37679041
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----------0E15611ED3BECDC"
Return-Path: info @ zipzoomfly.com
X-OriginalArrivalTime: 25 Nov 2006 18:02:07.0539 (UTC)
FILETIME=[D23B7830:01C710BB]
[NOTE: The rest of the email was the text (above block) and a large block of random-looking letters (this would be the attachment).
I left names, email addresses, and phone numbers in here for the search engines to find. DO NOT TRY TO CONTACT THEM! They sent a virus! -LE]
Notes
- Ok... This is as ugly as the Microsoft spoof ... with the same type of results - I get a virus/worm if I open the attachment!
- Here's a trick... The TO email address of the first one is bigwillp @ hotmail.com. I DO have a hotmail address that starts with "big", but the address to which this email came was NOT that one. Even so, I didn't really pay much attention to it until I expanded the email to see the name of the attached file.
The other two TO: email addresses are totally unknown to me.
Guess I need to add the rule:
NEVER OPEN ATTACHMENTS ON AN EMAIL THAT DOESN'T HAVE YOUR ADDRESS ON IT!
You may ask, "Why would I?" Well ...
- Maybe the correct address is in the attachment. (No... The email is SENT to an address, and if it's not yours, yours was in the BCC or we're talking about a mailing list.
- Curiosity (Well, remember the old saying, "Curiosity killed the cat," or in this case, your computer!)
- Criminal mentality - There might be something worth something in it. (Kinda like #2, huh? Also, thinking you might be receiving something in error, that someone else paid for. Uh... Wouldn't that be "receiving stolen goods?" Think about that one.)
- There should be little reason to Zip a single-page (ostensibly small) receipt, and I know of no shopping site that does so. The text of the email is enough. Even then, there should/would NOT be a "double-extension" on it.
- NOTE: Many of the sites, listed below, have different file extensions. Mine was a "double-extension". Theirs were singles. DO NOT OPEN THE ATTACHED FILE!
Since I have been receiving emails with attachments, like this one, fairly regularly, the first thing I did was, Google for the name (not the extensions) of the file: "37679041", and found a few links where the email was discussed. While my email did not come from a "known" (to me) website, others have received the same email (the product and amounts may change) saying it's from WalMart, Circuit City, Best Buy, etc. Here are a few of them:
- CastleCops :: View topic - Suspect zip attachement spoofed Circuit City sender
- Malware being spammed as PDF from retail stores | Spyware Confidential | ZDNet.com (Quotes the CastleCops' article.)
- Computing Main | Bryn Mawr College Computing
- OSU - IT Announcements Alerts
- Help Desk News and Notes: Fake Email from Best Buy
- Best Buy News Center: Statement: Best Buy Responds to October Consumer Phishing Incident
- Fraud Alert
- Spam Mail With 'Vaio' Order Distributes Malware - SPAMfighter
Send comments/questions about this page to Bill Sanders at:
Go to Malware
(Viruses, Adware, Spyware) Home page
Go to Malware Examples Home Page
Go to NEXT
Malware Example Page (last in sequence is not a link)
Send email to Bill Sanders
()
with questions or comments about this page or site.
This site, all text and graphics (unless otherwise noted) on it
were designed, developed and published by Bill Sanders of Orange Frog Productions.
It and it's CSS was validated and complies with both the:
CSS and
HTML 4.01
validators from W3C.
NOTE: All CSS validates except the "New Window Buttons"
which include some invalid code (ie: hacks),
added PicoSearch Tables,
and warnings for using transparent backgrounds when color foregrounds defined.
Copyright © 2003, 2004, 2005, 2006, 2007 by Bill Sanders / Full site last modified: October 21, 2006
Any reproduction, printing, or selling of this content is
prohibited without express written consent from William D.
Sanders.
![Welcome to Orange Frog Productions Scams, Shams & Flim-Flams Section [Banner]](images/ssff/ofp_banner_ssff.jpg)




