Malware Watch: Malicious Amazon themed emails in the wild

Borg 386

ADHD Senior Member
Guru
Gold Member
VIP
Local time
3:47 PM
Messages
5,489
Location
In a house with a cat trying to kill me
A currently spamvertised malware campaign is brand-jacking Amazon.com, in an attempt to trick end users into visiting a client-side exploits serving URL.

The campaign, is related to fake Amazon order confirmations, and Twitter password reset campaigns, and is part of a systematic attempt to impersonate well known brands - a well proven technique resulting in tens of thousands of clicks from socially engineered users.

Read More:

Malware Watch: Malicious Amazon themed emails in the wild | ZDNet

Go through related Malware Watch posts:

Windows users are advised to take basic precautions such as switching to an alternative PDF reader, ensure they are not running outdated 3rd party applications and plugins, consider the use of least privilege accounts, a securely configured modern browser, or isolate their Internet activities in order to mitigate the risk.
 

My Computer My Computer

At a glance

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
If you do happen to get email from Amazon (I do) ... right click on the subject and choose "View full header". Make sure you see X-Originating-IP: [207.171.164.47]



IP Information for 207.171.164.47

IP Location:
us.gif
United States Seattle Amazon.com Inc Resolve Host: mm-notify-out-2103.amazon.com IP Address: 207.171.164.47


OrgName: Amazon.com, Inc.
OrgID: AMAZON-4
Address: 605 5th Ave S
City: SEATTLE
StateProv: WA
PostalCode: 98104
Country: US​
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
A currently spamvertised malware campaign is brand-jacking Amazon.com, in an attempt to trick end users into visiting a client-side exploits serving URL.

The campaign, is related to fake Amazon order confirmations, and Twitter password reset campaigns, and is part of a systematic attempt to impersonate well known brands - a well proven technique resulting in tens of thousands of clicks from socially engineered users.

Read More:

Malware Watch: Malicious Amazon themed emails in the wild | ZDNet

Go through related Malware Watch posts:

Windows users are advised to take basic precautions such as switching to an alternative PDF reader, ensure they are not running outdated 3rd party applications and plugins, consider the use of least privilege accounts, a securely configured modern browser, or isolate their Internet activities in order to mitigate the risk.
Borg, thanks for the heads up!
 

My Computer My Computer

At a glance

Windows 7 7600 1 X64AMD PHENOM II X 550 PROCESSOR 3.1 ghzCorsair 4 gig ddr 3ati radeon 3300
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 7600 1 X64
CPU
AMD PHENOM II X 550 PROCESSOR 3.1 ghz
Motherboard
ASUS M4A78-TE
Memory
Corsair 4 gig ddr 3
Graphics Card(s)
ati radeon 3300
Sound Card
ati hd
Monitor(s) Displays
syncmaster 2033sw
Screen Resolution
1600X900 60 hz refresh
Hard Drives
twin_seagates SATA's 1 TB & 500 Gig, hitachi_slimline 160 gig
PSU
antec_550 watt
Case
cooler master GLite
Cooling
stock_heat sink
Internet Speed
20mbs up/ 1.5mbs down
Other Info
favorite child "stewie"
favorite dog "brian"
Back
Top