Security professionals have announced that there is a new round of greeting card spam that is spreading.

The subject line is “You’ve received a postcard from a family member!”.

The email contain links to a web site. If a user visits the web site, a javascript code will process and it will check whether the internet browser of the user has scripting enabled on or off.

If it is disabled, it will provide a link where the user’s computer can be exploited.

This announcement was made thursday afternoon by SANS Institute’s Internet Storm Center.

The exploits that may be performed are vulnerabilities from Quicktime, WinZip, and the dubbed “the Hail Mary”.

Source: COMPUTERWORLD