Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
Campaign involving fake airline e-ticket emails with malware detected
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Campaign involving fake airline e-ticket emails with malware detected

Campaign involving fake airline e-ticket emails with malware detected

Anuradha Shetty • September 25, 2012, 13:32:08 IST
Whatsapp Facebook Twitter

In a post on their Security Labs blog, Websense shared that their Websense ThreatSeeker Network …

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Campaign involving fake airline e-ticket emails with malware detected

In a post on the  Security Labs blog, Websense shared that the Websense Threat Seeker Network has stumbled upon yet another instance of users receiving fake airline e-ticket emails containing malicious attachments. Folks at Websense detected a campaign being made to depict as coming from KLM, the Dutch flagship airline.

Elaborating further on the nature of the malware campaign, the blog post stated that every malicious message came with the subject line ‘‘KLM e-Ticket’’. Findings reveal that it appears to use a legitimate KLM e-ticket layout, but it does not display the itinerary information. What it instead does is prod users to view the itinerary in a malware-laden attachment, thereby risking compromising their machines. 

STORY CONTINUES BELOW THIS AD

In a shocking revelation, Websense shares that they intercepted over 850,000 messages from this campaign on Monday, September 17 alone.

eticket

A sample e-ticket with malicious intent

Importantly, the post notes that while this scam is not aimed at KLM customers, specifically, and those with recent ticket purchases as well as recipients fearing an unauthorised credit card purchase could be potential victims. 

More from News & Analysis
What is the US HIRE Bill and why is India’s $250-billion IT sector worried? What is the US HIRE Bill and why is India’s $250-billion IT sector worried? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true?

Websense researchers, as per this post, scanned through a sample set of messages to find that each ’e-ticket’ came with unique values in the passenger and receipt sections, which their researchers presume is an attempt to slip away from sight, along with a malicious zipped attachment named ‘KLM-e-Ticket_.zip’.

Going further, it has been found that the attachments contained two different malicious binaries, both of which were extracted in the campaign. The post points that both binaries are named ‘KLM-e-Ticket.pdf.exe’ and both allow remote shell (command line) access to the compromised machine via telnet to port 8000. What comes as interesting here is that although, both of these binaries are attempting to trick users into believing that the file is a PDF file, neither uses an Adobe Reader or similar icon!

“It is worth noting that the same binaries have been used in recent ‘Microsoft Services Agreement’ and ‘Telstra Online Account’ campaigns based on submitted filenames,” adds the post.

Last month, in a blog post titled “ Benefits of your BlackBerry ID in this attached malware”, WebSense Security Labs elaborated on yet another one of its worrying find. Websense ThreatSeeker Network intercepted a malware campaign aimed at BlackBerry users. The campaign ran through fake e-mails that essentially state that the recipient has successfully created a BlackBerry ID. The e-mail adds that to enjoy the full benefits of the BlackBerry ID, the recipient should follow the instructions given in the attached file. Clearly, this is done to trick the user into running the malicious file.

STORY CONTINUES BELOW THIS AD

In one of its other blog posts, WebSense Security Labs discussed the menace of the Nigerian email scam. The Nigerian email scam - also known as the 419 scam, a reference to the article of the Nigerian Criminal Code that such activities violate - is so common by now that it is identifiable on first look. Yet, they continue to dupe unsuspecting people into financial losses amounting to millions of dollars, and disrupting their lives. Examples of such scam e-mails are countless, so much so that it has retained its place on the list of top ten internet/email scams for 2012.

Tags
General Airline tickets Websense Security Labs Websense ThreatSeeker Network mails non Nigerian scammers scambaiters suspicious e mails KLM e Ticket
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV