According to this email, which purports to be from hotel chain Hilton, a receipt for your hotel booking is included in an attached file. The sending email address appears to belong to Hilton. The email also features the rather strange subject line ‘A for guest WARDE SAID’.
However, the email is certainly not from Hilton, and the attachment does not contain a hotel booking receipt. The email uses a spoofed address to make it appear that the message came from Hilton.
But, in fact, the attached .zip file contains a malicious .exe file. If you click the .exe file, malware can be installed on your computer. Once installed, the malware may then attempt to download and install other types of malware. This malware can steal banking credentials and other sensitive information from your computer, lock your computer’s files and demand a ransom, or perform other nefarious tasks.
Like similar fake hotel booking emails, this message uses a simple social engineering trick to get people to open the attachment without due caution. People who receive the email may open the attachment because they mistakenly believe that their credit card has been used to purchase hotel tickets without their knowledge. Or, they may think that a booking error has been made and they should therefore open the attachment to view details before contacting the company.
Be very wary of any unsolicited email that claims that you can view an invoice or receipt for a purchase you know nothing about by opening an attached file or clicking a link. This is a very common criminal tactic.
Thank you for choosing our hotel and we very much hope that you enjoyed your stay with us.
Enclosed is a copy of your receipt(FOLIODETE_6100846.pdf). Should you require any further assistance please do not hesitate to contact us directly.
We look forward to welcoming you back in the near future.
This is an automatically generated message. Please do not reply to this email address.
This transmission is not a digital or electronic signature and cannot be used to form, document, or authenticate a contract. Hilton and its affiliates accept no liability arising in connection with this transmission. Copyright 2015 Hilton Worldwide Proprietary and Confidential
Since you’ve read this far……can I ask you for a big favour?
To enhance your privacy and security and offer you a better user experience, Hoax-Slayer is now ad-free. To keep the site online, I now rely on voluntary contributions from site visitors along with commissions from a few trusted products and services that I promote via reviews on the site.
If you found the above report useful, please consider supporting Hoax-Slayer by making a donation. Any amount you can give will be greatly appreciated.
You can donate using your credit card via the form below. Donations are collected securely via the online payment service Stripe. Stripe uses state of the art security to keep your data safe.