I've just received a malicious Christmas card - in June!

Filed Under: Malware, Spam

Christmas in the sunWe're having an uncharacteristically sunny June day here in Britain, making it feel all the more incongruous to see Christmas cards are being sent out via email.

But you should be careful, because these aren't just badly timed emails wishing you season's greetings - these emails have a malicious payload designed to infect your Windows computers.

Here's a typical example of the type of message that has been intercepted by SophosLabs:

Subject: You have received a Christmas Greeting Card!

Message body:
You have just received a Christmas greeting card!
To see your custom card and who sent it, please click the attachment

Attached file: Christmas Card.zip

Christmas card malicious email

Although the email claims to come from 123greetings, a legitimate and well-known ecard website, the reality is that the bad guys have forged the headers in this email in an attempt to trick you into clicking on the attachment.

The danger is, of course, that you may be bemused by the notion of receiving a Christmas card in June and click on the attachment out of curiousity. That would be a big mistake, however, as it contains the Mal/CryptBox-A Trojan horse.

So you should have trusted your instincts. There's always going to be something odd about a Christmas card arriving in June - and like any other unsolicited attachment it should be approached with caution.

Make sure that your anti-virus software and email protection is in place, and make sure you've had a good healthy helping of common sense next time you receive an out-of-season greeting.

, , ,

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <pre> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

About the author

Graham Cluley is senior technology consultant at Sophos. The readers of Computer Weekly voted him security blogger of the year in 2009 and 2010, and he pipped Stephen Fry to the title of "Twitter user of the year" too. Which was nice. He was also named "Best Security Blogger" by the readers of SC Magazine in 2011. You can subscribe to Graham's updates on Facebook, follow him on Twitter and circle him on Google Plus for regular updates.