snopes.com  

Go Back   snopes.com > Urban Legends > Computers

Reply
 
Thread Tools Display Modes
  #1  
Old 26 June 2007, 07:10 PM
pob14's Avatar
pob14 pob14 is offline
 
Join Date: 31 December 2002
Location: Springfield, IL
Posts: 866
Default Fake E-card message?

I keep getting these messages from a .hk domain that say:

Quote:
Good day.

Your family member has sent you an ecard from *****.hk.

Send free ecards from *****.hk with your choice of colors, words and music.

Your ecard will be available with us for the next 30 days. If you wish to keep
the ecard longer, you may save it on your computer or take a print.

To view your ecard, choose from any of the following options:

--------
OPTION 1
--------

Click on the following Internet address or
copy & paste it into your browser's address box.

http://*****

--------
OPTION 2
--------

Copy & paste the ecard number in the "View Your Card" box at
http://*****.hk/

Your ecard number is
******

Best wishes,
Postmaster,
*****.hk

*If you would like to send someone an ecard, you can do so at
http://****.hk/
Now, as it happens, we do have a family member who travels to Hong Kong fairly often, but she's not in HKG now, and the "your family member" language (instead of an actual name) would make me suspicious anyway. So I've just been deleting these. (Not even a little tempted to "take a print"!)

But does anybody know what's up with this? Are they some marketing thing, a virus, or what? A search for the domain name (which I've deleted above) shows nothing.
Reply With Quote
  #2  
Old 26 June 2007, 07:21 PM
Ariadne's Avatar
Ariadne Ariadne is offline
 
Join Date: 02 March 2006
Location: Iowa
Posts: 1,103
Default

I don't know, but I got one of these recently, too. I deleted it, since it was on my free excite account, on which I get mostly junk mail. My family and friends use my msn account.


ETA:
Woohoo...500th post!
Reply With Quote
  #3  
Old 26 June 2007, 07:25 PM
justusfour's Avatar
justusfour justusfour is offline
 
Join Date: 22 March 2006
Location: Fort Worth, TX
Posts: 1,915
Default

I've received 8 of those in the past two weeks - not to the same email address but to 3 of the "junk" email addresses I use. I am curious as to what happens, but I'm not about the be the guinea pig!
__________________
No one can make you feel inferior without your consent. -Eleanor Roosevelt
You haven't lived till your toddler has bitten your butt.-MamaDuck
Reply With Quote
  #4  
Old 26 June 2007, 07:34 PM
James G's Avatar
James G James G is offline
 
Join Date: 12 January 2004
Location: Edinburgh, UK
Posts: 3,308
Default

Yep, had a couple of those myself. Deleted it but was vaguely curious as it didn't look like the usual fake E-card spam.
__________________
My Website|My Blog|My Facebook
"As usual, the hard work of scientists gets smashed like a firefly butt on newsprint, creating a briefly luminescent glow and a total mess of the firefly." - ganzfeld
Reply With Quote
  #5  
Old 26 June 2007, 08:10 PM
tribrats's Avatar
tribrats tribrats is offline
 
Join Date: 15 September 2004
Location: New Hampshire
Posts: 5,856
Default

Don't click the link! It starts a self downloader and the only way to stop it is to turn off the computer manually. I found out the hard way. Went to put the link in the Google bar and managed to put it in the address bar instead.

When I booted back up, I scanned the partial that did download and it was a Trojan.
__________________
There are 3 sureties in life. Death, taxes and discrimination.
China | Alfie & Tilly
My blogs about my birds. (Updated 4/27)
Next time you're convinced nobody listens to you, swear in front of a child!
Reply With Quote
  #6  
Old 26 June 2007, 08:16 PM
James G's Avatar
James G James G is offline
 
Join Date: 12 January 2004
Location: Edinburgh, UK
Posts: 3,308
Default

Quote:
Originally Posted by tribrats View Post
Don't click the link! It starts a self downloader and the only way to stop it is to turn off the computer manually. I found out the hard way. Went to put the link in the Google bar and managed to put it in the address bar instead.

When I booted back up, I scanned the partial that did download and it was a Trojan.
Eeep, I'd probably be safe as I use Opera, but even so that shouldn't be happening even in IE. Seems like it must be exploiting some unpatched flaw, I wonder if MS know.
__________________
My Website|My Blog|My Facebook
"As usual, the hard work of scientists gets smashed like a firefly butt on newsprint, creating a briefly luminescent glow and a total mess of the firefly." - ganzfeld
Reply With Quote
  #7  
Old 26 June 2007, 08:23 PM
tribrats's Avatar
tribrats tribrats is offline
 
Join Date: 15 September 2004
Location: New Hampshire
Posts: 5,856
Fright

It's worse than that! I use Mozilla! I couldn't stop the download. It kept right on going no matter what I did. I haven't seen anything like it before. I opened the downloads window and it wasn't on there. I couldn't find a way to end the download! I probably could have if I found it on the Task Manager but I didn't want to wait for it to come up. Everything was running so slow. So I manually turned it off.
__________________
There are 3 sureties in life. Death, taxes and discrimination.
China | Alfie & Tilly
My blogs about my birds. (Updated 4/27)
Next time you're convinced nobody listens to you, swear in front of a child!
Reply With Quote
  #8  
Old 26 June 2007, 08:41 PM
Fantine's Avatar
Fantine Fantine is offline
 
Join Date: 17 September 2006
Location: Tacoma, WA
Posts: 427
Default

I've gotten five or six of those in the past week on my work e-mail (set up on Outlook), and immediately deleted them. I didn't recognize the domain, it didn't specify the name of the family member, and most importantly, my family doesn't have my work e-mail address!
Reply With Quote
  #9  
Old 26 June 2007, 08:47 PM
James G's Avatar
James G James G is offline
 
Join Date: 12 January 2004
Location: Edinburgh, UK
Posts: 3,308
Default

Quote:
Originally Posted by tribrats View Post
It's worse than that! I use Mozilla! I couldn't stop the download. It kept right on going no matter what I did. I haven't seen anything like it before. I opened the downloads window and it wasn't on there. I couldn't find a way to end the download! I probably could have if I found it on the Task Manager but I didn't want to wait for it to come up. Everything was running so slow. So I manually turned it off.
Wow, that is bad. Possibly an exploit in flash or something.

You know the really silly thing is that this is making me even more tempted to check out the site and see if I'm vulnerable.

'Mummy, I want to see the nasty trojans. Awww, why can't I see the malware?'
__________________
My Website|My Blog|My Facebook
"As usual, the hard work of scientists gets smashed like a firefly butt on newsprint, creating a briefly luminescent glow and a total mess of the firefly." - ganzfeld
Reply With Quote
  #10  
Old 27 June 2007, 04:11 PM
KathyB KathyB is offline
 
Join Date: 19 February 2000
Location: Sacramento, CA
Posts: 4,382
Default

A bit of Googling results in this: this is an ongoing deal. Various legit ecard companies get their name used in the email. It installs Storm Worm according to the techies at Wright State University
__________________
*******************
Kathy B.
The Plural of anecdote is not data
Reply With Quote
  #11  
Old 02 July 2007, 06:30 PM
zman977's Avatar
zman977 zman977 is offline
 
Join Date: 26 September 2003
Location: La Salle, IL
Posts: 2,122
Default

I've get at least one of these a day at home and at my work email. I just delete them.
__________________
My Facebook page
my podcast
Reply With Quote
  #12  
Old 02 July 2007, 07:07 PM
tribrats's Avatar
tribrats tribrats is offline
 
Join Date: 15 September 2004
Location: New Hampshire
Posts: 5,856
Crash

I have been getting them from "a family member" and the other day I got one from "a colleague". Yeah, right! I'm a SAHM so the only "colleague" I have is Hubby and he can barely figure out how to turn the machine on much less send anything!
__________________
There are 3 sureties in life. Death, taxes and discrimination.
China | Alfie & Tilly
My blogs about my birds. (Updated 4/27)
Next time you're convinced nobody listens to you, swear in front of a child!
Reply With Quote
  #13  
Old 02 July 2007, 08:04 PM
STF STF is offline
 
Join Date: 14 June 2001
Location: Jonesboro, GA
Posts: 7,176
Default

I've heard that fake e-cards are an effective tool for hackers as this thread shows.
Reply With Quote
  #14  
Old 02 July 2007, 09:27 PM
charlie23's Avatar
charlie23 charlie23 is offline
 
Join Date: 02 April 2005
Location: Varna, Bulgaria
Posts: 383
Default

I manage a couple of PHPbbs boards, and I'm getting about 10 of these per day presumably from a spambot that I can't figure out how to block. Fortunately Kaspersky caught the first one...although it was a different Trojan than Storm. I've filtered the rest by subject line. Be careful, because there seem to be a lot of variants on the hijacker.
Reply With Quote
  #15  
Old 03 July 2007, 03:56 PM
wayneland123
 
Posts: n/a
Default here's what happens if you click on a fake ecard link

http://asert.arbornetworks.com/2007/...tcard-malware/ has a good explanation of what happens with or without JavaScript if you click a link in one of those emails. There are some related links at the bottom of that page for those who want to learn more.
Reply With Quote
  #16  
Old 03 July 2007, 05:27 PM
tribrats's Avatar
tribrats tribrats is offline
 
Join Date: 15 September 2004
Location: New Hampshire
Posts: 5,856
Icon22

Got one today from "a classmate". I can't think of a single classmate that would send me an ecard. Especially 17 years after graduation!

__________________
There are 3 sureties in life. Death, taxes and discrimination.
China | Alfie & Tilly
My blogs about my birds. (Updated 4/27)
Next time you're convinced nobody listens to you, swear in front of a child!
Reply With Quote
  #17  
Old 03 July 2007, 08:17 PM
BlueStar's Avatar
BlueStar BlueStar is offline
 
Join Date: 07 August 2002
Location: Newcastle, UK
Posts: 2,650
Default

Got one today from a "neighbour". Dunno why the crazy cat lady next door wouldn't just pop round but hey.
Reply With Quote
  #18  
Old 03 July 2007, 08:50 PM
BluesScale BluesScale is offline
 
Join Date: 29 December 2005
Location: Woolhampton, Berkshire, UK
Posts: 1,357
Default

If you get any of these that you think are malicious, please feel free to forward them to me and I will make sure that they are investigated and, if possible, taken down.

My non-work email address is markalong64@hotmail.com

Yes, I WANT you to send me links to malware :-)

Thanks

Blues
Reply With Quote
  #19  
Old 03 July 2007, 09:18 PM
Bee's Avatar
Bee Bee is offline
 
Join Date: 10 May 2006
Location: Minnesota
Posts: 985
Default

Hey, I received one from a worshipper!! I didn't know I had any of those!

I've been getting 2-3 a day lately, but this one takes the cake.

Bee
__________________
Where were you when God laid the foundations of His marketing plan? -- Bryan With a 'Y'
Reply With Quote
  #20  
Old 04 July 2007, 02:50 AM
pob14's Avatar
pob14 pob14 is offline
 
Join Date: 31 December 2002
Location: Springfield, IL
Posts: 866
Default

Quote:
Originally Posted by BluesScale View Post
If you get any of these that you think are malicious, please feel free to forward them to me and I will make sure that they are investigated and, if possible, taken down.

My non-work email address is markalong64@hotmail.com

Yes, I WANT you to send me links to malware :-)

Thanks

Blues

I'm getting several a day as well. You want 'em, you got 'em!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 01:10 PM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.