Warning: Virus Like Activity from friendlygreetings.com Re: E-cards

hevnsnt

Lifer
Mar 18, 2000
10,868
1
0
I just spent 5 hours of my life fighting this one off around here.. FYI.. Do not click on the link contained in the email if you get it!


McAfee has received a number of reports, which cite mass-mailing behavior from friendlygreetings.com E-cards. AVERT has examined samples of the messages and our findings are as follows:

1) When users access the URL, in the E-card, an installer program is
downloaded locally
2) When the installer program is run, an End User License Agreement
is presented. The EULA states that it will send an email to all
the users contacts. When users accept this EULA, the email
is sent.
3) This is not a worm, virus, or exploitation.

McAfee is building gateway-only detection, for this program, into the DATs.
Only the gateway-scanning products (Webshield SMTP, ePPliances) will
detect this non-viral program.

A VIL description has been posted at the following URL:


http://vil.nai.com/vil/content/v_99760.htm
 

KeyserSoze

Diamond Member
Oct 11, 2000
6,048
1
81
Thanks for the heads up.

Even though I'm pretty aware of stuff like this, I guarantee it's going to affect friends/family of mine.








KeyserSoze
 

hevnsnt

Lifer
Mar 18, 2000
10,868
1
0
I am too, but it is very convincing.. Plus if you go to the root url on that site, it even looks like a V-Card site..




To: jason.t.whatever
Subject: Jason you have an E-Card from Stacy.


Greetings!

Stacy has sent you an E-Card -- a virtual postcard from
FriendGreetings.com.
You can pickup your E-Card at the FriendGreetings.com by clicking on the
link below.

http://www.friendgreetings.com/linkremoved/linkremoved.aspx?code=removed&id=removed

Message:
------------------------------------------------------------
Jason,
I sent you a greeting card. Please pick it up.
Stacy
------------------------------------------------------------

 

RaySun2Be

Lifer
Oct 10, 1999
16,565
6
71
yeah, my wife got hit with this one. She's not computer literate, so said ok when prompted. I knew something was up when I got an email from a mutual friend asking about all the spam mail that looked like it was coming from my wife's account.

Cusswords. :|