Security thread masquerading as UPS email

Over the past several weeks, virus researchers worldwide have been tracking a high volume of fake emails purporting to come from UPS. These emails include an attachment, with a zip file that includes a malicious executable typically named something like “UPS_Invoice.exe”.

This Trojan was highlighted in a recent article in Security Center Magazine:

http://www.scmagazineuk.com/Trojan-disguised-as-UPS-delivery-note/article/112500/

The emails typically include text similar to the following:

“From: United Parcel Service
Subject: UPS Tracking Number xxxxxx

Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct. Please print out the invoice copy attached and collect the package at our office

Your UPS”

Generally, anti-virus engines have been able to keep up with this threat through new definition updates or heuristics. However, ongoing analysis of this Trojan shows that it continues to propagate in the wild due to highly aggressive methods used to evade detection. Test have also seen a marked increase in propagation over the past 24 hours.

Recommedation:
Do not open or forward these emails! If your virus software is up to date it should catch them, but that is no guarantee. The best course of action is to be on guard.

I have already received at least one copy of this, so it is out there. If you have any questions, please ask!

Related Posts

This entry was posted on Thursday, July 24th, 2008 and is filed under Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Tags: , , ,

One Response to “Security thread masquerading as UPS email”

  1. debtmanagementaffiliateprogram

    It sounds like you’re creating problems yourself by trying to solve this issue instead of looking at why there is a problem in the first place.

Leave a Reply

CommentLuv Enabled