Virus Email - BH Live Tickets Confirmation of Order Number for the Peter Pan Show
September 8, 2014
The email message below: "Confirmation of Order Number 484914," is a fake and has a virus or Trojan horse attached to it that will infect your Windows computer if you open it. The message was not sent by BH Live Tickets, but by cyber-criminals, who designed it to trick the recipients into opening the malicious attachment, by claiming that they should open the attachment to view and print their e-tickets for the 'Peter Pan' show.
Please continue reading below.
So, if you receive the same email message, please delete it and do not attempt to open the attachment.
The Virus Email Message
From: bhlivetickets @bhlive.co.uk
Date: 8 September 2014 09:15
Subject: Confirmation of Order Number 484914
Order Number Order Date
484914 07-09-2014 13:00
YOUR E-TICKET(S) ARE ATTACHED TO THIS EMAIL, SENT TO [Email Removed]. Please print ALL PAGES of the PDF file attached to the email and bring them with you to gain admission to the event.
The attachment requires that you have the Adobe Acrobat Reader installed on your computer. If you do not have Adobe Acrobat Reader installed, please click HERE to download and install this program.
TICKETS QTY TICKET TYPE PRICE EACHTOTAL
Bournemouth Pavilion Theatre
Tue 23 Dec 2014 - 7:00 PM 3 Early Bird - Price A 18.00 54.00
6 Early Bird Child Under 16 - Price A 15.00 90.00
Circle/A 35-30 (6) , Circle/B 33-31 (3)
DELIVERY METHOD AMOUNT
Print At Home - E-Ticket(s) are attached to this order confirmation (You must be able to open and print a PDF file) 1.00
PAYMENTS TYPE # DATE AMOUNT
Mastercard Sale ****** ****** 7006 03-09-2014 13:00 145.00
Please keep this confirmation in a safe place.
THIS IS NOT YOUR TICKET
YOUR E-TICKET(S) ARE ATTACHED TO THIS EMAIL
Please call 0844 576 3000 if there are any errors in your order, if you have not received your tickets as expected, or if you have any questions.
BH Live Tickets
Exeter Road, Bournemouth, BH2 5BH
Tel: 0844 576 3000
VAT Reg: 108 2248 37
PAYMENTS RECEIVED: 145.00
The email attachment "tickets.3130599.zip" contains the malicious file "tickets.3130599.exe" or "tickets.332091.exe", and is not a PDF document as the malicious email message stated.
Note: The attachment name may change.
We found the following threats after scanning the malicious file:
The cyber-criminals behind the malicious email message aim is to trick the curious recipients into opening the malicious attachment that will infect their computers with a virus or Trojan horse.
Once their computers have become infected with the malicious virus or Trojan horse, the cyber-criminals behind this email message will be able to access and take control of your computer remotely from anywhere around the world. They may spy on you, use your computer to commit cyber-crimes, or steal your personal and financial information.
Now, if you have already opened anyone of the malicious attachment, please do a full scan of your computer with the antivirus software installed on it. The name of the attachment may change, so be careful when opening email attachments.
If you don’t have antivirus software installed on your computer, please click here for a list of free antivirus software.
Also, never open an attachment that has a name ending with “.exe”, because these files will infect your computer with viruses, Trojan horse and other malware.
Click here for a list of email attachments you should never open, regardless of where they came from.
For a list of other virus email messages, please click here.
BH Live Tickets is aware of the malicious email and have posted the following notice on their website:
Monday 8 September – Emails have been sent to a number of recipients purporting to be from BH Live.initial investigations suggest that emails did not originate from BH Live’s systems or network. Please do not open any attachments or click any links.
We will post updates via our website and social media. We apologise for any inconvenience.
Please share with us what you know or ask a question about this article, by leaving a comment below. And, forward malicious email messages to us using the following email address: email@example.com .
Alert and help your family and friends by sharing this article with them: