Your eBay Invoice is Ready : Fake PDF malware

An email with the subject of  Your eBay Invoice is Ready  pretending to come from eBay <ebay@ebay.com> with  a zip attachment is another one from the current bot runs which try to download various Trojans and password stealers especially banking credential stealers, which may include cridex, dridex, dyreza and various  Zbots, cryptolocker, ransomware and loads of other malware on your computer. They use email addresses and subjects that will entice a user to read the email and open the attachment.

The content of the email which shouldn’t fool anybody because it has no eBay logos or links and is totally in plain text, which EBay never send because they want to grab you and get you on the eBay site spending money,  
 says :

PLEASE DO NOT RESPOND – Emails to this address are not monitored or responded to.

Dear Customer,

Please open the attached file to view invoice.

If the attachment is in PDF format you may need Adobe Acrobat Reader to read or download this attachment. If you require Adobe Acrobat Reader this is available at no cost from the Adobe Website www.adobe.com

______________________________________________________________________

This email and any attachment are intended solely for the addressee, are strictly confidential and may be legally privileged. If you are not the intended recipient any reading, dissemination, copying or any other use or reliance is prohibited. If you have received this email in error please notify the sender immediately by email and then permanently delete the email.

 

These malicious attachments normally have a password stealing component, with the aim of stealing your bank, PayPal or other financial details along with your email or FTP ( web space) log in credentials. Many of them are also designed to specifically steal your Facebook and other social network log in details.

None of the companies that seem to be sending these emails have been hacked or had their email or other servers compromised. They are not sending the emails to you. They are just innocent victims in exactly the same way as every recipient of these emails.

Beware from such fake emails.