The flood of malicious Ecard spam that we first reported at the weekend has continued seemingly unabated.
A variety of subject lines are used, but the theme is always “You’ve received a greeting card from a ….”
The links in the emails are ip addresses (a set of four numbers xxx.xxx.xxx.xxx ) Selecting the link downloads the Troj/JSEcard-A Trojan horse that Sophos has been protecting against since 29 June.
It will be interesting to see how long this campaign continues. Presumably it has been targeted to coincide with various national holidays that occur this week (Canada Day yesterday and 4th July tomorrow)