Be Wary of ‘Order Confirmation’ Emails

  • 3 December 2014
  • 8 replies
  • 3 views

Userlevel 7
Badge +3
 If you receive an email this holiday season asking you to “confirm” an online e-commerce order or package shipment, please resist the urge to click the included link or attachment: Malware purveyors and spammers are blasting these missives by the millions each day in a bid to trick people into giving up control over their computers and identities.
 
 http://krebsonsecurity.com/2014/12/be-wary-of-order-confirmation-emails/

8 replies

Userlevel 7
Badge +56
These are especially effective when sent to the AP person at companies.  I'll generally know if I've ordered something or not, but they deal with hundreds of orders so they're more likely to click to find out.
I just picked up at least two viruses by doing just that, I had ordered something from Costco and later got a "confirmation" email.  I already had my purchases but opened it anyway.  Stupid, stupid, stupid.  Now I need your HELP. 
 
I have scanned my computer a half dozen times using Webroot and each time I get multiple "detections" and each time I click on "Remove".  It says they are removed but upon rescan It is NOT being removed.  HELP.  
 
It is in C:usersjamesappdatalocal and has this kind of address:
 
pcxvqvki.exe AND wfvsrqbv.exe
 
I have a desk PC running Windows 7.  Any help would be appreciated.
Jim 
 
Userlevel 7
Badge +56
Sorry to hear you're having problems removing those Jim.  Included with the Webroot license is free support, and our support team can remote into your computer (with your permission) and make sure those are properly removed.  Just submit a ticket here.
Thanks, will hold on taking a "ticket", just got a clear scan. But it did that before so I opened my email inbox and will now scan again. If clean, maybe I'm OK. Thanks again,
Userlevel 7
Badge +56
Sure thing - let us know how it goes and we're happy to help if you need it!
beyond deleting these types of emails, is there any organization investigating or interested in these?
Userlevel 7
Hi mjkacarney
 
Welcome to the Community Forums.
 
Your first and best port of call in terms of reporting this sort of email is to your ISP.  They can investigate this and pass on the details but most likely they will update their own anti spam software so that hopefully these are cut out and do not even reach the end user, i.e., you, in the first instance.
 
Regards, Baldrick
Userlevel 7
@ wrote:
I just picked up at least two viruses by doing just that, I had ordered something from Costco and later got a "confirmation" email.  I already had my purchases but opened it anyway.  Stupid, stupid, stupid.  Now I need your HELP. 
 
 
Don't beat yourself up over this. It is a very effective type of spam. If it didn't work so well, they wouldn't be using it still. This time of year, it is highly effective!

Reply