Community
Wiki Posts
Search

"Miles & More" scam e-mail

Thread Tools
 
Search this Thread
 
Old Mar 3, 2011, 7:32 am
  #1  
Original Poster
 
Join Date: Aug 2006
Location: LPI
Programs: SK *B (?)
Posts: 362
Exclamation "Miles & More" scam e-mail

Interesting, I think this is the first time I've seen an FF program targetted by these kinds of scams. I received this yesterday:

From: "Miles & More"<[email protected]>
Subject: Your booking confirmation
To: undisclosed-recipients:;
X-Spam-Flag: YES
X-Sent: 22 hours, 8 minutes, 26 seconds ago
X-Bogosity: Spam, tests=bogofilter, spamicity=1.000000, version=1.2.2

Thanks for the purchase!

Booking number: LVSN50
Your credit card has been charged for $493.67.

Please print PASSENGER ITINERARY RECEIPT by logging into your Miles account
by clicking the link below:

http://www.miles-and-more.com

On board you will be offered:
– Beverages;
– Food;
– Daily press.

You are guaranteed top-quality services and attention on the part of our benevolent personnel.
We recommend you to print PASSENGER ITINERARY RECEIPT and take it alone to the airport.
It will help you to pass control and registration procedures faster.

See you on board!

Best regards,
Miles & More
Of course, the link in the HTML e-mail does not actually point to miles-and-more.com, but to a hijacked server in Argentina.
lnixon is offline  
Old Mar 3, 2011, 9:02 am
  #2  
 
Join Date: Apr 2006
Location: PRN
Programs: LH HON* || HH Diamond || Accor Gold
Posts: 1,271
You've got PM.
olm022 is offline  
Old Mar 3, 2011, 9:41 pm
  #3  
 
Join Date: Aug 2004
Location: OSL/IAH/ZRH (time, not preference)
Programs: UA1K, LH GM, AA EXP->GM
Posts: 38,265
If you log in and don't get the "der Zentralrechner ist zur Zeit nicht erreichbar..." intro, then you know it's something fishy.

Did you give it a try? What are they after? Simply the M&M login? Sounds like yet another looser scam.
weero is offline  
Old Mar 4, 2011, 1:32 am
  #4  
Original Poster
 
Join Date: Aug 2006
Location: LPI
Programs: SK *B (?)
Posts: 362
Originally Posted by weero
If you log in and don't get the "der Zentralrechner ist zur Zeit nicht erreichbar..." intro, then you know it's something fishy.

Did you give it a try? What are they after? Simply the M&M login? Sounds like yet another looser scam.
The link I got was already dead.

However, according to other reports, like http://news.softpedia.com/news/Fake-...d-177840.shtml it's a drive-by attack. If you click on the link in the scam e-mail and you are running an unpatched Windows system, your computer will be compromised, and you will assimilated into the Zeus botnet: https://secure.wikimedia.org/wikiped...rojan_horse%29
lnixon is offline  
Old Mar 4, 2011, 5:57 am
  #5  
 
Join Date: Aug 2004
Location: OSL/IAH/ZRH (time, not preference)
Programs: UA1K, LH GM, AA EXP->GM
Posts: 38,265
Originally Posted by lnixon
The link I got was already dead..
^ for trying .
weero is offline  
Old Mar 4, 2011, 6:32 am
  #6  
Original Poster
 
Join Date: Aug 2006
Location: LPI
Programs: SK *B (?)
Posts: 362
Originally Posted by weero
^ for trying .
I poked it gently with a stick. From a Linux system.
lnixon is offline  
Old Mar 4, 2011, 11:59 pm
  #7  
 
Join Date: Aug 2004
Location: OSL/IAH/ZRH (time, not preference)
Programs: UA1K, LH GM, AA EXP->GM
Posts: 38,265
Originally Posted by lnixon
I poked it gently with a stick. From a Linux system.
It is very tempting indeed.

So you reckon that the exploit could have been dangerous even when not using Outlook?
weero is offline  
Old Mar 5, 2011, 2:28 am
  #8  
Original Poster
 
Join Date: Aug 2006
Location: LPI
Programs: SK *B (?)
Posts: 362
Originally Posted by weero
It is very tempting indeed.

So you reckon that the exploit could have been dangerous even when not using Outlook?
I'm pretty sure the attack targetted IE; visit the page with an out-of-date browser - *blam*.
lnixon is offline  
Old Mar 5, 2011, 4:44 am
  #9  
 
Join Date: Aug 2004
Location: OSL/IAH/ZRH (time, not preference)
Programs: UA1K, LH GM, AA EXP->GM
Posts: 38,265
Originally Posted by lnixon
I'm pretty sure the attack targetted IE; visit the page with an out-of-date browser - *blam*.
An out of date IE you mean.

With a 2 year old Opera you'd probably be just fine ...
weero is offline  
Old Mar 5, 2011, 7:09 am
  #10  
 
Join Date: Jun 2005
Location: HKG
Programs: LH HON
Posts: 195
Originally Posted by weero
It is very tempting indeed.

So you reckon that the exploit could have been dangerous even when not using Outlook?
According to this article here, it was Neosploit trying to exploit a 0day in Adobe Acrobat (as always...)
zara is offline  
Old Mar 5, 2011, 9:33 am
  #11  
Original Poster
 
Join Date: Aug 2006
Location: LPI
Programs: SK *B (?)
Posts: 362
Originally Posted by zara
According to this article here, it was Neosploit trying to exploit a 0day in Adobe Acrobat (as always...)
Yeah, that's the other big contender.
lnixon is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.