Close

Results 1 to 9 of 9
  1. #1
    DF VIP Member
    Argyll's Avatar
    Join Date
    Jun 2006
    Location
    Paradise
    Posts
    2,864
    Thanks
    96
    Thanked:        22
    Karma Level
    373

    Default Received dodgy Rar with exe file

    I've just received a dodgy email with a RAR attached containing an exe file. I've scanned it with nod and malwarebytes. It contains an exe file. Now obviously it's either a virus or something similar. I'm a nosey bastard though so is there anyway I can find out exactly what it is?

    The email claims they're from United airlines:

    Thank you for using our new service "United Airlines ticket Online" on our website.
    Your account has been created:

    Your login: xxxxxxxxxxxxxxxxxxxxxxxxxx Your password: pass4L8B

    Your credit card has been charged for $990.85.
    We would like to remind you that whenever you order tickets on our website you get a discount of 3%!
    Attached to this message is the purchase Invoice and the United Airlines ticket.
    To use your ticket, simply print it on a color printed, and you are set to take off for the journey!
    I understand and accept that some people hold opinions that are different to my own. Living in a free and democratic society, I fully embrace and respect their right to be wrong.

  2. #2
    DF VIP Member Undertaker's Avatar
    Join Date
    Nov 2000
    Location
    Earth
    Posts
    2,533
    Thanks
    39
    Thanked:        189
    Karma Level
    479

    Default Re: Received dodgy Rar with exe file

    could disassemble it in olly or ida pro and see what you get

  3. #3
    VIP Member CzarJunkie's Avatar
    Join Date
    Jun 2001
    Location
    Atlantis
    Posts
    13,754
    Thanks
    832
    Thanked:        3,225
    Karma Level
    1993

    Default Re: Received dodgy Rar with exe file

    Looks like they've taken you in some kind of sophisticated sting operation, I'd cancel your credit cards and open the file they claim is the invoice to see how much it's actually for, could be more that the $990.85.

    Do it, before it's too late.

  4. #4
    DF VIP Member DJAd's Avatar
    Join Date
    Nov 2002
    Location
    *Classified*
    Posts
    6,987
    Thanks
    40
    Thanked:        25
    Karma Level
    858

    Default Re: Received dodgy Rar with exe file

    Quote Originally Posted by Argyll View Post
    I'm a nosey bastard though so is there anyway I can find out exactly what it is?
    Double click it and find out!

  5. #5
    DF VIP Member
    Argyll's Avatar
    Join Date
    Jun 2006
    Location
    Paradise
    Posts
    2,864
    Thanks
    96
    Thanked:        22
    Karma Level
    373

    Default Re: Received dodgy Rar with exe file

    Quote Originally Posted by CzarJunkie View Post
    Looks like they've taken you in some kind of sophisticated sting operation, I'd cancel your credit cards and open the file they claim is the invoice to see how much it's actually for, could be more that the $990.85.

    Do it, before it's too late.
    Better still why don't I send it to you. I hear you like opening things up
    I understand and accept that some people hold opinions that are different to my own. Living in a free and democratic society, I fully embrace and respect their right to be wrong.

  6. #6
    DF VIP Member Geezah's Avatar
    Join Date
    Jun 2004
    Location
    cyberspace
    Posts
    939
    Thanks
    52
    Thanked:        177
    Karma Level
    325

    Default Re: Received dodgy Rar with exe file

    I had the exact same email last week (or the week before) saying my airline tickets were booked and here is the invoice or something like.
    The rar.exe file has an excell icon and it is acctually a trojan horse programme (I forgett the name).
    Its clever how they used a VB script to cover their intentions.... the file wants to download and install the real malware once its activated.
    Wasn't picked up by Adaware, Spybot or Avira
    I'm a nosey bugger too

  7. #7
    DF VIP Member Over Carl's Avatar
    Join Date
    Apr 2006
    Location
    London
    Posts
    13,125
    Thanks
    3,975
    Thanked:        1,690
    Karma Level
    1252

    Default Re: Received dodgy Rar with exe file

    If you do have to run virus infected programs, get vmware - pm me if you need to know where to find it. Then set that up, set up a small xp machine without network access, then run whatever in there.

    At least if it kills windows, you can just shut that application and carry on.

  8. #8
    DF VIP Member Geezah's Avatar
    Join Date
    Jun 2004
    Location
    cyberspace
    Posts
    939
    Thanks
    52
    Thanked:        177
    Karma Level
    325

    Default Re: Received dodgy Rar with exe file

    Yeah, VMWare is perfect for cross platform tinkering with stuff like this.

  9. #9
    DF VIP Member
    unclex's Avatar
    Join Date
    Nov 2000
    Location
    MARS
    Posts
    2,070
    Thanks
    18
    Thanked:        38
    Karma Level
    401

    Default Re: Received dodgy Rar with exe file

    delete it and move on...
    Have Fun.





    U.N.C.L.E. X

    More UNCLEX than last week but less next :woot:

Similar Threads

  1. gta3 save file 4 u all (pc)
    By neilmachin in forum PC Gaming
    Replies: 6
    Last Post: 14th January 2003, 01:52 PM
  2. Wicked Flash File
    By Pegasus in forum The Dog and Duck
    Replies: 11
    Last Post: 13th November 2002, 11:46 PM
  3. Dodgy email
    By wonkyfox in forum PC Problems
    Replies: 6
    Last Post: 7th September 2002, 03:39 PM
  4. T100 To T108 Flash File
    By BAZZO69 in forum Unlocking Questions & Solutions
    Replies: 7
    Last Post: 4th September 2002, 07:53 PM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •