FYI…

- http://preview.tinyurl.com/2hxoqw
November 28, 2007 - Symantec Security Response Weblog - "…The email looks harmless enough, because the “From” header is spoofed to appear as if it's coming from "YouTube Service" , which helps it to look like a legitimate invitation. The video's description is enticing and seems innocuous, inviting potential victims to open a shared video file, which is a fake YouTube link…
Note: The domains that are used to impersonate the YouTube Web site are giower.li, fineir.ch, and be4koy.com.es. These TLDs are not the usual .com or .net domains. The links will force the download of a malicious executable “install_flash_player.exe”…"

(Screenshots available at the URL above.)

:ph34r: