Sophos has posted an entry on their blog about a valentine’s day e-card malware.
Spammers send users an email which contains a link that redirects the users to a main.php web page of the same domain name. The trojan in that webpage was detected by Sophos as Troj/Flamgo-A.
Once users have been infected, they will be redirected to the legitimate AmericanGreetings.com website.
The blog entry contains a screen shot of the spam. It shows four paragraphs and a link. The domain extension of the link has been blacked out by Sophos.
Source: Sophos

Articles
Blogs
Kits
Forums