Antivirus Software

  1. Home
  2. Computing & Technology
  3. Antivirus Software
photo of Mary Landesman

Mary's Antivirus Software Blog

By Mary Landesman, About.com Guide to Antivirus Software since 2000

You Have 'Recieved' a Trojan

Monday June 4, 2007
The latest greeting card scam is once again targeting Hallmark. The bogus email claims "you have recieved a Hallmark E-Card!" The first tip-off for the security conscious should be the misspelled 'recieved' - it's I before E except after C (or when sounded like A as in neighbor and weigh). One would assume the prose experts at Hallmark would know their receive from their recieve - which, of course, they would. In any event, the message doesn't even read like a real Hallmark notice, which always identifies the sender by name and gives you an alternate link URL that you can copy and paste in lieu of blindly clicking a link. Why is this important? Because a real Hallmark URL doesn't point to an IP address followed by 'postcard.exe' - which the malicious link does.

To recap: tell-tale signs are poor spelling, failure to identify the sender, and a link that isn't displayed or a link that points to an executable file. The biggest tip-off - the legitimate Hallmark e-card email is sent 'from' the sender's email address and not from Hallmark.com. To avoid being fooled, be suspicious if:

  • The sender's address isn't a person you know, or is disguised generically as being from a greeting card company
  • There are misspellings in the text of the email
  • The link isn't displayed or the link points to an executable file

If you do receive an e-card that appears to be from someone you know, verify they intended to send it by calling or emailing the sender using a known good address (not the reply to address in the e-card).

And just what does this latest greeting card scam deliver? Like most others, it dishes up a variant of the Zapchast Trojan. Zapchast installs an Internet Relay (IRC) chat client and causes the infected computer to connect to an IRC channel. Attackers then use that connection to remotely command the machine. And you thought forgetting your birthday was bad.

Comments

June 22, 2007 at 10:34 am
(1) Michelle says:

I received an e-mail like this, but everything was spelled correctly. I wonder who I should forward it to for examination. :O

June 25, 2007 at 4:04 pm
(2) Mary says:

I also received one; I didn’t notice the spelling, but I did notice the bogus URL; in my case it was pointing to a file called “card.exe” on a server hosted in China.

June 29, 2007 at 9:46 am
(3) Mike says:

Their attempts are improving. The one I received was spelled correctly, it offered 2 options for viewing with copy and paste options, and the URL used some long code rather than pointing to an EXE file. The biggest giveaway, of course, is that it didn’t include my name or the name of the “family member” who supposedly sent it. And the “From” address displayed “hallmark.com”, but real address was something very different.

December 17, 2007 at 3:05 pm
(4) Marcia Purse says:

The ones I keep getting point to a file with a .scr (screensaver) extension.

My email preview software shows me the real links in emails before I ever actually download. Very handy! http://www.firetrust.com – MailWasher Pro. (I am not affiliated with Firetrust.)

July 23, 2008 at 4:14 pm
(5) Ray says:

got one with an attached zip file containing the postcard.exe

October 1, 2008 at 5:11 am
(6) Margaret says:

Very useful information, thank you. I became suspicious for exactly the misspelling of “recieve” which, however, was only in the actual message, not in the “Re:” And the attached file was “postcard.zip”. Luckily, this increased my suspicion. Bona fide e-cards always tell you who the sender is, that was the third giveaway.

October 13, 2008 at 6:43 pm
(7) David says:

Got one that is a very convincing spoof, with Hallmark logo, graphics, etc. Only problem is the link points to an executable at a numerical IP address.

November 14, 2008 at 5:47 pm
(8) Ellen says:

The school districts in our county got a rash of them this morning. They made it through an IronPort scanner. Our district’s email scanner (Guinevere) stopped them. These looked as if they really were from Hallmark. An infected file called “postcard.zip” was included, rather than a link.

January 21, 2009 at 11:16 pm
(9) Mary says:

Got 2 today with attachment of : postcard.zip

February 26, 2009 at 1:44 pm
(10) Hammer says:

Easy way to tell they are fake is that the Hallmark info that is in the email is a picture, with no working hyperlinks. My Kaspersky software zapped it the second it arrived. Thanks Kaspersky!

March 5, 2009 at 1:07 pm
(11) HEATHER says:

I get about 10 a day but dont open them.

April 28, 2009 at 10:28 pm
(12) Rachel says:

i before e
except after c
and when sounding like A as in neighbor and weigh
and in weekends and holidays
and all throughout may!

-brian regan :)

April 29, 2009 at 2:26 am
(13) Mary Landesman says:

Rachel (or Brian), it’s probably best to read an article before posting comments to it. The ‘recieved’ is clearly explained.

June 10, 2009 at 5:48 am
(14) Otis says:

Thank god for this, i always check the web incase these kind of things are viruses. As many people have said, received is spelt incorrectly, but only in the body of the e-mail, in the subject line it is correct.

I also wavered because of it pointing to a postcard.gif.exe – and it not knowing my name / the name of who it’s from.

Thanks again for this =]

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Discuss

Community Forum

Explore Antivirus Software

About.com Special Features

Build Your Own Website

Step-by-step advice on how to do everything from choosing a Web host to promoting your content. More >

Connect Your Home Computers

Easy ways to connect two computers for networking purposes. More >

Antivirus Software

  1. Home
  2. Computing & Technology
  3. Antivirus Software

©2009 About.com, a part of The New York Times Company.

All rights reserved.