Emold: eTicket_I2.zip

Seit heute Morgen versendet sich Emold (AutoRun) wieder einmal unter dem Deckmantel von Fluggesellschaften:

Betreff: Your Online Flight Ticket N 38885
Dear customers,
Thank you for using our new service “Buy airplane ticket Online” on our
Your account has been created:

Your login: *youremailaddress*
Your password: pass8OFW

Your credit card has been charged for $683.14.
We would like to remind you that whenever you order tickets on our website
you get a discount of 10%!
Attached to this message is the purchase Invoice and the airplane ticket.
To use your ticket, simply print it on a color printed, and you are set to
take off for the journey!

Kind regards,
Spirit Airlines

Die Ticket-Nummer im Betreff, der Absender sowie die Anrede variiert:


  • Southwest Airlines
  • Northwest Airlines
  • Delta Air Lines
  • Spirit Airlines
  • American Airlines
  • Anrede:

  • Greetings
  • Dear customers
  • Good day
  • Good afternoon
  • Im Attachement eTicket_I2.zip befindet sich die Ausführbare Datei eTicket_I2.doc.exe welche wie gewohnt den Trojaner Emold beinhaltet:

    Filename: eTicket_I2.doc.exe
    File size: 38400 bytes
    MD5…: f4bda06f2e92bc79ef836170c975b0dc
    SHA1..: 360f4fb1f1b07608b6ab9abee71edbebdeafa7c9
    Erkennungsrate: 15/36 (41.67%)

    Am Verhalten des Trojaners hat sich nichts geändert (Siehe Post vom 28.8.08).

    3 thoughts on “Emold: eTicket_I2.zip

    1. Pingback: Emold: eTicket_s3.zip | abuse.ch

    2. Pingback: Emold: [NO-REPLY] UPS Tracking Number | abuse.ch

    3. Pingback: Emold: e-Ticket_N32XXX.zip | abuse.ch

    Leave a Reply

    Your email address will not be published. Required fields are marked *