Infesting you with Virus News
 

News

Contributed by: Aurelija
Date: June 2, 2009
Aurelija
14
Vote
0

Warning! Fake United Parcel Service “Failed Delivery” Notifications Spreading Troj/Agent-KBE

 

UPS.jpgCyber criminals are successfully bombarding our inboxes with various fake delivery notifications and infecting systems with malware or stealing personal as well as financial information. Last week I informed you about fake Western Union messages, promising refunds of money. This time everybody should watch out for fake messages purportedly coming from 'United Parcel Service of America' and infecting computers with Troj/Agent-KBE.

How does the whole campaign work and what should you pay attention to? Fake 'United Parcel Service of America' delivery notifications are being spammed around the world informing potential victims that their postal packages could not be delivered.

Here is a sample of the fake message belonging to this campaign:

Postal Tracking #HFHLB588566XK1G                   From: "United Parcel Service of America" xxxxxxxxxxx

Subject: Postal Tracking #HFHLB588566XK1G
From: "United Parcel Service of America" xxxxxxxxxxxxx
To: xxxxxxxxxxxxx

Date: 2009-06-01 05:59:43

Hello!

We were not able to deliver postal package you sent on the 14th of May in time because the recipient's address is not correct. Please print out the invoice copy attached and collect the package at our office.

Your United Parcel Service of America

Table 1.  Fake email message

As is the case with a majority of other fake delivery notifications, the number in the subject line is random and may vary with each message.

The message itself does not infect your computer. It comes with an attachment called UPSNR_976120012.zip. The title and number of the attachment may of course vary and change with each fake message. The size of the file is 38167 files and the MD5 reads as f8342178f82f9f637846d2c47bb3b2ff. However, everybody should remember that as soon as they download this file into their computers, their system will be infected with a malicious Trojan horse called Troj/Agent-KBE.

The following table gives you other possible names of the Trojan spread via these fake messages:

Alias names
Win-Trojan/ZBot.57344
TR/Spy.ZBot.JFG
Trojan.Inject.Acbb
W32/Zbot.YN (Exact)
Pakes.DRC
Gen:Trojan.Heur.3014EB8EAC
Trojan.Agent-115743
Trojan.Botnetlog.9
W32/Zbot.YN (exact)
Trojan-Spy:W32/Zbot.OUC [Orion]
Trojan.Win32.Inject.accz [Engine:A]
Trojan.Win32.Inject.accz
VirTool:Win32/Obfuscator.FH(Suspicious)
Heur.W32
Troj/Agent-KBE
Infostealer.Banker.C
TSPY_ZBOT.AWF
Trojan.Inject.JGR

Table 2.  Alias names of Troj/Agent-KBE

Therefore, be careful and do not download any similar files that actually aim to infect your computer. Delete these emails claiming to be from United Parcel Service prior to opening them. Use your common sense - if you didn't even try send a package how can a failed delivery notification come into your inbox... If you have any doubts, contact United Parcel Service directly. And, of course, don't forget to use appropriate anti-virus software and updated anti-spam filters.

User Comments

athar June 9, 2009
I think no difference between fake and genune, I am waiting of my shipment from more than one month but UPS still take no action, I wrote lot of mails but no result.
Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

July 31, 2010
http://farmclas .. m-chambers.htmlkim chambers, 132592, http://westland .. -templates.htmlcv templates,... more..
July 31, 2010
http://temple-b .. 6/fha-203k.htmlfha 203k, :(, http://uksoccer .. sy-grammar.htmleasy grammar, hbt,... more..
July 31, 2010
http://thedukes .. ncy-meyers.htmlnancy meyers, 8332, http://maillots .. /***-girl.html*** girl,... more..
more comments..
rss
Home > E-mail > Warning! Fake United Parcel Service “Failed Delivery” Notifications Spreading Troj/Agent-KBE