
With Valentine's Day just around the corner and people search for the perfect gift for their loved ones, cybercriminals has been busy distributing an increasing amount of Valentine's day related spam to users with links to fake advertisements, online offers, and even photos or videos.
Over the last week, the Dell SonicWALL threats research team has been tracking down all Valentine's Day related spam emails.
Figure 1: Number of spam emails recevied per day
As Valentine's Day approaches, we are seeing an increasing amount of spam emails with links to phony florists or online retailer who promise a deal without the guarantee of ever receiving the products or services. Below are some of the most common email subjects:
Some emails provide links to photos, videos or online greetings that a "loved one" or a "secret admirer" might have left for you. Clicking these links often lead to survey scam, phishing sites or even malware.
Figure 2: Sample Spam Emails
For others that turn to the internet for something they can do instantly and finding an inexpensive last-minute idea like sending an e-card, cybercriminals have also got that covered. Searching online for free personalized Valentine's card will turn up with links to compromised websites that host malicious applications.
Figure 3: Example of a link to a compromised website
Clicking on the link will redirect to a website that will ask the user to download an application that will supposedly install an e-card maker. The installers may use the following variation of filenames:
Infection Cycle:
Upon execution, the Trojan will then silently download additional malware components.
Figure 4: Trojan sends an HTTP GET request to download additional components
The user will also be prompted to agree to install applications different from what was intended to be installed.
Figure 5: User prompt to install Internet Optimizer
We observed several other adwares being downloaded and silently installed on the system.
Figure 6: Example of several HTTP GET requests to download additional malware
The downloaded malware components are copied to the following directory:
The following files were silently installed into the following directories:
Within minutes of infection this Trojan was able to download and install multiple other malicious applications. Therefore, we urge our users to always be vigilant and cautious with any unsolicited email, to avoid clicking on unknown URLs, providing any personal information and installing unfamiliar applications specially if you are not certain of the source.
Dell SonicWALL Gateway AntiVirus provides protection against these threats with the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News