FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Lufthansa, Austrian, Swiss, Brussels, LOT and Other Partners | Miles & More (https://www.flyertalk.com/forum/lufthansa-austrian-swiss-brussels-lot-other-partners-miles-more-495/)
-   -   "Miles & More" scam e-mail (https://www.flyertalk.com/forum/lufthansa-austrian-swiss-brussels-lot-other-partners-miles-more/1190305-miles-more-scam-e-mail.html)

lnixon Mar 3, 2011 7:32 am

"Miles & More" scam e-mail
 
Interesting, I think this is the first time I've seen an FF program targetted by these kinds of scams. I received this yesterday:


From: "Miles & More"<[email protected]>
Subject: Your booking confirmation
To: undisclosed-recipients:;
X-Spam-Flag: YES
X-Sent: 22 hours, 8 minutes, 26 seconds ago
X-Bogosity: Spam, tests=bogofilter, spamicity=1.000000, version=1.2.2

Thanks for the purchase!

Booking number: LVSN50
Your credit card has been charged for $493.67.

Please print PASSENGER ITINERARY RECEIPT by logging into your Miles account
by clicking the link below:

http://www.miles-and-more.com

On board you will be offered:
– Beverages;
– Food;
– Daily press.

You are guaranteed top-quality services and attention on the part of our benevolent personnel.
We recommend you to print PASSENGER ITINERARY RECEIPT and take it alone to the airport.
It will help you to pass control and registration procedures faster.

See you on board!

Best regards,
Miles & More
Of course, the link in the HTML e-mail does not actually point to miles-and-more.com, but to a hijacked server in Argentina.

olm022 Mar 3, 2011 9:02 am

You've got PM.

weero Mar 3, 2011 9:41 pm

If you log in and don't get the "der Zentralrechner ist zur Zeit nicht erreichbar..." intro, then you know it's something fishy.

Did you give it a try? What are they after? Simply the M&M login? Sounds like yet another looser scam.

lnixon Mar 4, 2011 1:32 am


Originally Posted by weero (Post 15972263)
If you log in and don't get the "der Zentralrechner ist zur Zeit nicht erreichbar..." intro, then you know it's something fishy.

Did you give it a try? What are they after? Simply the M&M login? Sounds like yet another looser scam.

The link I got was already dead.

However, according to other reports, like http://news.softpedia.com/news/Fake-...d-177840.shtml it's a drive-by attack. If you click on the link in the scam e-mail and you are running an unpatched Windows system, your computer will be compromised, and you will assimilated into the Zeus botnet: https://secure.wikimedia.org/wikiped...rojan_horse%29

weero Mar 4, 2011 5:57 am


Originally Posted by lnixon (Post 15972854)
The link I got was already dead..

^ for trying :) .

lnixon Mar 4, 2011 6:32 am


Originally Posted by weero (Post 15973416)
^ for trying :) .

I poked it gently with a stick. From a Linux system.

weero Mar 4, 2011 11:59 pm


Originally Posted by lnixon (Post 15973552)
I poked it gently with a stick. From a Linux system.

It is very tempting indeed.

So you reckon that the exploit could have been dangerous even when not using Outlook?

lnixon Mar 5, 2011 2:28 am


Originally Posted by weero (Post 15978440)
It is very tempting indeed.

So you reckon that the exploit could have been dangerous even when not using Outlook?

I'm pretty sure the attack targetted IE; visit the page with an out-of-date browser - *blam*.

weero Mar 5, 2011 4:44 am


Originally Posted by lnixon (Post 15978764)
I'm pretty sure the attack targetted IE; visit the page with an out-of-date browser - *blam*.

An out of date IE you mean.

With a 2 year old Opera you'd probably be just fine :cool: ...

zara Mar 5, 2011 7:09 am


Originally Posted by weero (Post 15978440)
It is very tempting indeed.

So you reckon that the exploit could have been dangerous even when not using Outlook?

According to this article here, it was Neosploit trying to exploit a 0day in Adobe Acrobat (as always...)

lnixon Mar 5, 2011 9:33 am


Originally Posted by zara (Post 15979443)
According to this article here, it was Neosploit trying to exploit a 0day in Adobe Acrobat (as always...)

Yeah, that's the other big contender.


All times are GMT -6. The time now is 6:30 am.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.