CONGRATULATIONS LOTTERY WINNERウイルス付きロト当選偽メール
 
{{{ 2014年10月更新 }}}
 
『おめでとうございまーす! ロトくじ当選したよぉ!』ってな感じの英語表記の迷惑メール(スパムメール)がキタ━(゚∀゚)━!!!
件名 CONGRATULATIONS LOTTERY WINNER
差出人 LOTTERY WINNING NOTIFICATION


This e-mail has been issued to you in order to Officially inform you that we have completed an investigation on an International Payment in which was issued to you by World Bank. With the help of our newly developed technology (International Monitoring Network System) we discovered that you were not able to complete your transfer because of the amount involved. During our investigation we discovered that your fund ($11 million) is still available and we have authorized the fund to be paid to you via a Certified Cashier's Check, ATM or Via Wire Transfer.

You were asked to provide Anti-Terrorism and Anti-Drug Certificate which you never did and that has led to suggestion that you might be sponsoring Terrorism nor Drug.On that note We urge you to open the attached file named FBI FILE and then click RUN to view which yoot give you access to winning number for the lottery as we need to confirm you have the correct number for collection at any of our stations near you.

We therefore urge you to open the attached file named winning number and then click RUN to view which you would find inside the winning number attached.The file is encrypted so you need not worry.

I want you to proceed now and open the attached winning number then click on RUN to view your winning number and collection point.Attached is your winning number.
この手の当選メールだと、419詐欺(ナイジェリア詐欺)のパターンもあるみたいだけど、今回はメールにナゾの添付ファイルが付いてました。
 
解凍してみると、中身は実行ファイル(拡張子 *.exe)でしたー。 <コンピュータウイルスさん!
 
イメージ 1
ウィニングナンバー!?
 
WINNING NUMBER.zip
 ↓ 解凍
WINNING NUMBER.exe
(MD5ハッシュ値 b96d021bb2d26c8c5559b52edf98d795)