If it Says You’ve Received a Greeting eCard from a Friend, Class Mate, or Partner - Well, You Haven’t. And Don’t Open It!   7/30/2007 - 3,054 views, 4 Comments

Summary: A rash of virus-laden spam has been going around posing as Hallmark e-cards or other e-cards. "You've received a greeting ecard from a friend" says the subject. Variations include "You've received a greeting card from a partner", "You've received a greeting postcard from a class-mate", and "You've received a greeting ecard from a class mate". The "ecard" appears to come from such legitimate sounding addresses as hallmark.com, MyPostcards.com, postcards.org, e-cards.com, NetFunCards.com, FunnyPostcards.com, Greeting-Cards.com, and VintagePostcards.com. Whatever the variation, it's not only spam, it's almost certainly carrying a virus or a trojan which will turn your computer into a spam- and virus-sending robot.

Previous Article « Nationwide Hotmail Outage Today
Read Next Article » Pure Digital Camcorder’s “Email Your Video” Option Harvests Email Addresses and Grabs Your Personal Videos!

A rash of virus-laden spam has been going around posing as Hallmark ecards or other ecards.

“You’ve received a greeting ecard from a friend” says the subject. Variations include “You’ve received a greeting card from a partner”, “You’ve received a greeting postcard from a class-mate”, and “You’ve received a greeting ecard from a class mate”.

The “ecards” appears to come from such legitimate sounding addresses as hallmark.com, MyPostcards.com, postcards.org, e-cards.com, NetFunCards.com, FunnyPostcards.com, Greeting-Cards.com, and VintagePostcards.com.

Whatever the variation, it’s not only spam, it’s almost certainly carrying a virus or a trojan which will turn your computer into a spam- and virus-sending robot.

So don’t open it!

If you were to open the email, what you would see would look very much like this:

“Hi. Friend has sent you a postcard.
See your card as often as you wish during the next 15 days.

SEEING YOUR CARD

If your email software creates links to Web pages, click on your card’s direct www address below while you are connected to the Internet:

http://58.9.174.164/?d41977bc649ea95523893748ae56

Or copy and paste it into your browser’s “Location” box (where Internet addresses go).

We hope you enjoy your awesome card.

Wishing you the best,
Administrator,
hallmark.com”

See that link up there? If you were to click on the link below “SEEING YOUR CARD”, it would take you to a location where a virus would be downloaded on to your computer. Oh, you might also see a card, so that you wouldn’t suspect what was going on, but within a few days, usually, your computer would be under the control of someone miles away, who would be spewing spam out through your computer. And you would never know until suddenly one day nobody would accept email from your computer any more, because all of the ISPs and spam filters had started blocking it because of all the spam it was sending.

Of course, if we are advising people not to open ecards, we must also advise well-meaning people that they shouldn’t bother sending ecards. And we do. Right here.

Get FREE email alerts of new Internet Patrol stories!
    *We never share your email address with anyone

Email Address:
Date of first visit:
How you found us:

Subscribe
to The Internet Patrol on your cell phone    Email the link for this page to a friend!

Read more:

»  Online Dating? Parents Would Rather See Their Daughter Date a Trekkie or Even Pick Someone Up in a Bar!

»  Putting on the Dog - the Small Dog, That Is

»  Hallmark Email Cards - A eCards a Good Idea or Evil Incarnate?

»  Unexpected Online Greeting Cards May Carry Trojan Horses

For additional similar stories check out our archives on Spam, Virus & AntiVirus

 

4 Comments »

  1. First, people using Linux or Macs probably don’t have to worry. And those Windows users who keep their systems patched with the latest security updates are probably doing okay too.

    Remember that the only way that clicking a link can give you a virus is when your web browser has a security hole the attacking web site can exploit to install and execute code on your system.

    More important is to tell people that URLs using an IP address instead of a domain name (i.e. 58.9.174.164 instead of whatever.com) should NEVER be clicked unless you know for a fact precisely where that numerical address leads.

    Comment by Smith — 7/30/2007 @ 8:28 am

  2. la la la la

    Comment by The Internet Patrol — 7/30/2007 @ 9:58 am

  3. Yeah, I am receiving such mails from a couple of days. I did try to see the site only. But in the middle i realized its a spasm. So I simply stopped my browser and started anti virus scan. Scanning indicated a virus and deleted the file. So I think I am safe :)

    Comment by Awan — 7/30/2007 @ 8:24 pm

  4. Notice that the bogus e-mails won’t have your name or the sender’s name (most of the valid ones include the sender’s name and e-mail address which is usually recognizable). Also, some of the bogus links look genuine to the viewer, but, in fact, are completely bogus. How can you tell? For most users, just move your mouse over the link WITHOUT CLICKING ON IT, then look at the bottom of your browser window, and you should see the bogus link (i.e., instead of saying something like “Hallmark.com”, it’ll show something completely different). If you don’t recognize the link appearing in either the e-mail or at the bottom of the window, don’t click on it! Unfortunately, some legit ones look bogus, but, there’s a “fix” for that, too! After you’ve deleted the seemingly bogus card, your friend will probably send you an e-mail asking whether you got it. When you say, “Oh, no, I thought it was a spam and deleted it!”, they can just re-send the card using the link they were given as a verification from the legit e-mail website; if they lost *that*, then everyone’s hosed, but, hey, the sender can always re-send it! (FWIW, I’m a computer programmer with over 30 years of experience including a sideline business of fixing home and business computers)

    Comment by Steffi Kaizun — 2/11/2008 @ 5:10 pm

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


We apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day!

 
The Internet Patrol
Patrolling the Internet for You!