{"id":1492,"date":"2019-04-06T19:33:39","date_gmt":"2019-04-06T19:33:39","guid":{"rendered":"http:\/\/www.syyhoaxanalyzer.com\/?p=1492"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T17:00:00","slug":"Fake-Costco-Order-Notification-Leads-to-Malware","status":"publish","type":"post","link":"https:\/\/www.syyhoaxanalyzer.com\/?p=1492","title":{"rendered":"Fake Costco Order Notification Leads to Malware"},"content":{"rendered":"<div>\n<h2>Outline<\/h2>\n<p>Email purporting to be from Costco thanks you for your recent order and invites you to view order details by clicking a link. \u00a0 <\/p>\n<p><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js\"><\/script><br \/>\n<!-- HS Net Top Content Responsive --><br \/>\n<ins class=\"adsbygoogle\"\n     style=\"display:block\"\n     data-ad-client=\"ca-pub-0355887770822260\"\n     data-ad-slot=\"4870821038\"\n     data-ad-format=\"auto\"><\/ins><br \/>\n<script>\n(adsbygoogle = window.adsbygoogle || []).push({});\n<\/script><\/p>\n<h2>Brief Analysis<\/h2>\n<p>The email is not from Costco. Clicking the link opens a website that contains malware. Once installed, this malware may collect personal information from your computer and connect with servers operated by criminals. If you receive this email, do not click any links or open any attachments that it contains.<\/p>\n<h2>Example<\/h2>\n<div class=\"example\">\n<p><strong>Subject: Thank you for buying from Costco<\/strong><\/p>\n<p>Costco<br \/>\nWHOLESALE<br \/>\nOur online store Costco.com received an order and the personal data of the recipient coincide with yours.<br \/>\nYou may get your order in the nearest Local Store.<br \/>\nAttention! Your order can be reserved within 4 days.<br \/>\nYou may see order details here .<br \/>\nHappy Thanksgiving Day!<\/p>\n<p>Truly yours,<br \/>\nCostco.com<\/p>\n<p><a href=\"https:\/\/www.hoax-slayer.net\/wp-content\/uploads\/2014\/11\/costco-order-notification-malware-2.jpg\" data-rel=\"penci-gallery-image-content\" ><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"21343\" data-permalink=\"https:\/\/www.hoax-slayer.net\/fake-costco-order-notification-leads-to-malware\/costco-order-notification-malware-2\/\" data-orig-file=\"https:\/\/www.hoax-slayer.net\/wp-content\/uploads\/2014\/11\/costco-order-notification-malware-2.jpg\" data-orig-size=\"728,377\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"costco-order-notification-malware-2\" data-image-description=\"\" data-medium-file=\"https:\/\/www.hoax-slayer.net\/wp-content\/uploads\/2014\/11\/costco-order-notification-malware-2-300x155.jpg\" data-large-file=\"https:\/\/www.hoax-slayer.net\/wp-content\/uploads\/2014\/11\/costco-order-notification-malware-2.jpg\" class=\"aligncenter size-full wp-image-21343\" src=\"https:\/\/www.hoax-slayer.net\/wp-content\/uploads\/2014\/11\/costco-order-notification-malware-2.jpg\" alt=\"Fake Costco Order Email\" width=\"728\" height=\"377\" srcset=\"https:\/\/www.hoax-slayer.net\/wp-content\/uploads\/2014\/11\/costco-order-notification-malware-2.jpg 728w, https:\/\/www.hoax-slayer.net\/wp-content\/uploads\/2014\/11\/costco-order-notification-malware-2-300x155.jpg 300w, https:\/\/www.hoax-slayer.net\/wp-content\/uploads\/2014\/11\/costco-order-notification-malware-2-500x259.jpg 500w, https:\/\/www.hoax-slayer.net\/wp-content\/uploads\/2014\/11\/costco-order-notification-malware-2-585x303.jpg 585w\" sizes=\"(max-width: 728px) 100vw, 728px\" \/><\/a><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<h2>Detailed Analysis<\/h2>\n<p>According to this &#8216;thank-you&#8217; email, which purports to be from Costco, the company has received your order and you may pick it up at a local store.<\/p>\n<p>The email invites you to click a link to view details about the supposed order. The message includes the Costco name logo and is designed to emulate a genuine email from the company. \u00a0<\/p>\n<p><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js\"><\/script><br \/>\n<ins class=\"adsbygoogle\"\n     style=\"display:block; text-align:center;\"\n     data-ad-format=\"fluid\"\n     data-ad-layout=\"in-article\"\n     data-ad-client=\"ca-pub-0355887770822260\"\n     data-ad-slot=\"9162856233\"><\/ins><br \/>\n<script>\n     (adsbygoogle = window.adsbygoogle || []).push({});\n<\/script><\/p>\n<p> However, the email is not from Costco and the link does not open information about an order. \u00a0 Instead, the link opens a website that harbours malware. Clicking the link automatically downloads a .zip file. In the sample I tested, the file was named CostcoOrderInfo-Tennyson.zip. File names may vary in different incarnations of the scam.<\/p>\n<p>Opening the .zip file reveals a .exe file with a similar name. Clicking this .exe file will install the malware on your computer.<\/p>\n<p>Typically, such malware can harvest sensitive information from the infected computer and send it to online criminals. It may also download and install further malware components and allow the criminals to control the computer from afar.<\/p>\n<p>Criminals often \u00a0<a class=\"norm\" title=\"Amazon 'Order Details' Malware Email\" href=\"https:\/\/www.hoax-slayer.com\/amazon-order-details-malware.shtml\">send out bogus order notifications<\/a> \u00a0as a means of \u00a0<a class=\"norm\" title=\"MALWARE - Order Number 'Thank You For Using Our Services' Email\" href=\"https:\/\/www.hoax-slayer.com\/order-number-malware-emails.shtml\">tricking people into installing malware<\/a>. The messages have used the names of many \u00a0<a class=\"norm\" title=\"American Airlines Flight Ticket Order Malware Emails\" href=\"https:\/\/www.hoax-slayer.com\/american-airlines-malware-emails.shtml\">high profile companies<\/a>.<\/p>\n<p>Some versions include the malware in an attached file rather than on a compromised website.<\/p>\n<p>If you receive one of these emails, do not click any links or open any attachments that it contains.<\/p>\n<p>If you have an account with the store named in the email, it is safer to log in by entering the address in your browser&#8217;s address bar rather than by clicking a link.<\/p>\n<p><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js\"><\/script><br \/>\n<!-- Third Content Ad Responsive --><br \/>\n<ins class=\"adsbygoogle\"\n     style=\"display:block\"\n     data-ad-client=\"ca-pub-0355887770822260\"\n     data-ad-slot=\"1909104632\"\n     data-ad-format=\"auto\"><\/ins><br \/>\n<script>\n(adsbygoogle = window.adsbygoogle || []).push({});\n<\/script><\/p>\n<div align=\"center\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js\"><\/script><br \/>\n<!-- HS Net Bottom AdLinks --><br \/>\n<ins class=\"adsbygoogle\" style=\"display: block;\" data-ad-client=\"ca-pub-0355887770822260\" data-ad-slot=\"1358951439\" data-ad-format=\"link\"><\/ins><br \/>\n<script>\n(adsbygoogle = window.adsbygoogle || []).push({});\n<\/script><\/div>\n<p><\/br><\/br> Original Source : <a href=\"https:\/\/www.hoax-slayer.net\/fake-costco-order-notification-leads-to-malware\/\" target=\"_blank\">https:\/\/www.hoax-slayer.net\/fake-costco-order-notification-leads-to-malware\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Outline Email purporting to be from Costco thanks you for your recent order and invites you to view order details by clicking a link. \u00a0 Brief Analysis The email is not from Costco. Clicking the link opens a website that contains malware. Once installed, this malware may collect personal information from your computer and connect [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":6890,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1492","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hoax-inggris"],"_links":{"self":[{"href":"https:\/\/www.syyhoaxanalyzer.com\/index.php?rest_route=\/wp\/v2\/posts\/1492"}],"collection":[{"href":"https:\/\/www.syyhoaxanalyzer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.syyhoaxanalyzer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.syyhoaxanalyzer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.syyhoaxanalyzer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1492"}],"version-history":[{"count":0,"href":"https:\/\/www.syyhoaxanalyzer.com\/index.php?rest_route=\/wp\/v2\/posts\/1492\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.syyhoaxanalyzer.com\/index.php?rest_route=\/wp\/v2\/media\/6890"}],"wp:attachment":[{"href":"https:\/\/www.syyhoaxanalyzer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.syyhoaxanalyzer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.syyhoaxanalyzer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}