Spoofed Delta Airlines Contains Malware


Recommended Posts

Mar27

by Jake Soriano (Technical Communications)

The Trend Micro Content Security team discovered spoofed email messages that pretend to be from Delta Airlines. The fake email message contains a confirmation numbers of supposed ticket purchase and a ZIP file. Recipients are told that this said file contains details on the travel itinerary.

Here’s a screenshot of a spammed message: http://blog.trendmicro.com/spoofed-delta-a...ntains-malware/

The ZIP file is, of course, a malicious file detected by Trend Micro as TROJ_DELF.PSZ.

The Trojan automatically runs at every system startup by modifying a registry entry. It has rootkit routines which enable the binary to hide its processes, files, or registry entries. The file also connects to a website to download files. This exposes an infected system to more threats.

TreendLabs - http://blog.trendmicro.com/spoofed-delta-a...ntains-malware/

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...