The malicious element is disguised as a harmless PDF file

Jul 9, 2013 17:41 GMT  ·  By

Internet users are advised to be on the lookout for bogus itinerary emails purporting to come from Expedia.

Entitled something like “Your Trip Details Lancaster Gate Hotel, London,” the emails inform recipients of the following:

“Thanks for booking with Expedia! Below is a summary of the trip you recently booked.To help ensure everything runs as smoothly as possible, keep this email handy so you can refer to it when you check in as it contains all the essential information you'll need.

If you're travelling internationally, don't forget to check the visa requirements for your end destination and any countries you're travelling through during your trip.Expedia Itinerary Number(s)

See trip details below or Attached”

According to Hoax Slayer, the file attached to these emails is a zip archive that appears to contain a harmless PDF file. However, in reality, the PDF is actually an executable that hides a piece of malware.

Over the past period, similar malware-spreading itinerary notifications have leveraged the names of companies such as Delta Airlines, American Airlines, Virgin Blue and Jetstar.