Spamvertised "Reqest Rejected" campaign leads to scareware
Summary: A currently spamertised campaign is enticing end users into downloading and executing a malicious attachment.
A currently spamertised malware campaign is enticing end users into downloading and executing a malicious attachment.
Sample subject: Reqest rejected Sample message: "Dear Sirs, Thank you for your letter! Unfortunately we can not confirm your request! More information attached in document below. Thank you Best regards." Sample attachments: EX-38463.pdf.zip; EX-38463.pdf.exe
Upon execution the binary downloads additional files, in this case a scareware variant. Detection rate for TrojanDownloader:Win32/Chepvil.J.
See also:
- Spamvertised Post Office Express Mail (USPS) emails lead to malware
- Spamvertised DHL notifications lead to malware
- The Ultimate Guide to Scareware Protection
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback
Not sure why people do this
RE: Spamvertised
macs don't allow viruses? ummm.
http://www.pcworld.com/article/208540/mac_users_warned_of_growing_virus_threat.html
Error in your thesis
This is wrong.
<i>If we built computers that didn't allow viruses (like a mac), this would stop a lot of this</i>
Macs allow any software to be installed once the Admin user enters a password. Similar to Windows UAC, this technical protection cannot stop the "security weakest link" which is simply to fool the person at the keyboard.
The difference is only one of execution, though, and Macs can be, have been, and will be the victims of malicious software just like Windows PCs if their users aren't vigilant.
RE: Error in your thesis
As much as the rabid ABMer (<b>Always Bash Micro$oft</b>) in me appreciates the sentiment; I hate to tell you that it is NOT the O/S that is completely at fault.
I have had my share of WindoZE troubles, and have finally left <b>them</b> behind when I switched to Ubuntu some 4 years ago. While much safer, that in and of itself, <b>does not excuse <u>stupidity</u></b>. Surf to a bad site, you can get taken.
You can be pwned in Linux if you are not careful; but the target sitting on the back of a Linux user is quite smaller compared to his WindoZE using brother.
Usually it is a case of PEBKAC (for those that don't know: <i>Problem Exists Between Keyboard And Chair</i>).
WindoZE users need to stop their `click monkey` behavior, and THINK before clicking on links.
RE: Spamvertised
"If we built computers that didn't allow viruses (like a mac), this would stop a lot of this."
LMAO! If I were one of those lowlifes that writes malicious software, I'd *LOVE* for people to believe that! One of the WORST security flaws is /believing/ you're secure, when you're not.
This is old news.
In ohter words stop playing games and get it fixed already
RE: Catch the criminals and put them in jail ....
Sorry Stan, I would be much harsher in exacting punishment, I would subject them to <b>summary execution</b> on conviction. Zero chance of becoming a repeat offender.
Agreed
People who write malicious code are oxygen thieves who don't deserve to live.
No one is worse than an intelligent person who uses his intelligence for evil purposes.
LOL.....
RE: Spamvertised
No, it's only in your twisted little ABM world, loser. And we laugh at you.
effin awesome...
"If we built computers that didn't allow viruses (like a mac), this would stop a lot of this"
with a straight face. you sound so sure but are so wrong. now about the post...
thanks Mr. Danchev for the reminder. even the best of us tech pros get complacent and kinda forget people still do this. make sure you follow safe practices.
RE: Spamvertised
RE: I'm amazed that people open EXEs sent via e-mail
But, there are those whose intelligence is questionable.
I recall in the past sending some product photos to a customer packed in a "self executing" file. His IT department was not too thrilled at that. I ended up sending the photos individually; and removed that application from my system, once i appreciated its security implications.
Innocents at the computer
I too am amazed, but then we can't expect the entire computer-using planet to be savvy.
My husband is a highly intelligent mechanical engineer, but I had a devil of a time trying to explain to him what an *.exe file was.
RE: Spamvertised
RE: Spamvertised
<a href="http://www.yuregininsesi.com" title="seslichat">sesli chat</a> <a href="http://www.yuregininsesi.com" title="seslisohbet">sesli sohbet</a>