She-geeks Forum
May 28, 2012, 01:40:13 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: He-geeks are welcome!
 
   Home   Help Search Login Register  
Pages: 1   Go Down
  Print  
Author Topic: Don't open that invoice.zip file its not from UPS  (Read 684 times)
0 Members and 2 Guests are viewing this topic.
tomron
Full Member
*******

Karma: 351
Offline Offline

Posts: 254



« on: September 17, 2008, 06:04:40 PM »

We received two reports of fake UPS invoice tracking Trojan zip files.
This is similar to other invoice Trojans we have seen. .....

http://isc.sans.org/
« Last Edit: March 03, 2009, 10:15:23 AM by justy » Logged

Click for Garfield, New Jersey Forecast" border="0" height="41" width="127
Moderator_
Guest
« Reply #1 on: September 17, 2008, 06:16:19 PM »

We received two reports of fake UPS invoice tracking Trojan zip files.
This is similar to other invoice Trojans we have seen. .....

isc.sans.org/




source:

http://myitforum.com/cs2/blogs/cmosby/archive/2008/09/17/don-t-open-that-invoice-zip-file-its-not-from-ups-sans-internet-storm-center.aspx





Don't open that invoice.zip file its not from UPS - SANS Internet Storm Center
Don't open that invoice.zip file its not from UPS
Published: 2008-09-16,
Last Updated: 2008-09-16 20:15:52 UTC
by xxxx xxxx (Version: 1)
1 comment(s) digg_url = 'http://isc.sans.org/diary.html?storyid=5051&rss'; digg_title = 'Don\'t open that invoice.zip file its not from UPS'; digg_skin='compact'; digg_topic = 'security';

We received two reports of fake UPS invoice tracking Trojan zip files.
This is similar to other invoice Trojans we have seen.

Here is one of the email bodies notice that while this appears to be a two way conversation it was really just the spammer who created the whole thing. The victim did not send UPS an email.
Email header:


To: victims@email.address
Subject: Re: missing package
From: John Henry <johnhenry.support@ups.com>
Reply-To: johnhenry.support@ups.com

Email body:

 Mr./Mrs. Victims First and Last name
 
 I am sorry for this late reply, but we have good news.
 
 We managed to track your package, and we have attached the
 invoice you asked for to this reply.
 
 The invoice contains the correct tracking# , since the one
 you gave us was invalid.
 
 You can use it on the ups website to track your shipment.
 
 Thank you
 John Henry
 UPS Customer Care Department
 
 
 From: victim’s name and email address
 Subject: missing package
 To: support@ups.com
 Date: Monday, September 8 , 2008, 10:38 AM
 
 I have recently used UPS to send a package to my cousin but
 he never received it.
 
 Also , the tracking number doesn't check on the website, and
 I lost the invoice.
 
 Can you forward me a copy?
 
 
 
Here you have the tracking# :xxxxxxxxxxxxxxxx


 
Original File Name: invoice.zip

9/36 of the virus engines at VT recognized it.

AntiVir 7.8.1.28 2008.09.16 TR/Crypt.FKM.Gen
Authentium 5.1.0.4 2008.09.16 W32/Heuristic-VFM!Eldorado
BitDefender 7.2 2008.09.16 MemScan:Trojan.Spy.Delf.NQT
CAT-QuickHeal 9.50 2008.09.16 (Suspicious) - DNAScan
F-Prot 4.4.4.56 2008.09.16 W32/Heuristic-VFM!Eldorado
Ikarus T3.1.1.34.0 2008.09.16 BehavesLike.Win32.Malware




thoughts?

« Last Edit: March 03, 2009, 10:15:48 AM by justy » Logged
justy
Administrator
Hero Member
*************

Karma: 4588
Offline Offline

Posts: 1407


but then it's your life uh huh, it's your life. uh, huh. but, you've only got one.


WWW
« Reply #2 on: September 17, 2008, 06:31:52 PM »

wow...thank you for posting this tomron!
« Last Edit: September 17, 2008, 06:53:41 PM by justy » Logged

01101010011101010111001101110100011010010110111001100001
tomron
Full Member
*******

Karma: 351
Offline Offline

Posts: 254



« Reply #3 on: September 17, 2008, 07:00:56 PM »

@justy

If anyone is interested they can subscribe for e-mail notifications.

@Moderator_

Are you seeking thoughts on the subject itself.
« Last Edit: March 03, 2009, 10:15:02 AM by justy » Logged

Click for Garfield, New Jersey Forecast" border="0" height="41" width="127
Moderator_
Guest
« Reply #4 on: September 17, 2008, 08:26:16 PM »


@Moderator_

Are you seeking thoughts on the subject itself.


Actually, when I said "Thoughts?" at the end of my previous post--I was asking that to all the members, not just you.

But if you have thoughts on the matter, post them up.
« Last Edit: March 03, 2009, 10:14:42 AM by justy » Logged
tomron
Full Member
*******

Karma: 351
Offline Offline

Posts: 254



« Reply #5 on: September 17, 2008, 09:11:14 PM »

@Moderator_

Quote
Actually, when I said "Thoughts?" at the end of my previous post--I was asking that to all the members, not just you.

I figured that,I just got confused when you said "source" then provided a link cause I didn't get this from the link that you provided.
I got this from CNET,and also I've been getting e-mail notifications from SANS for years.
« Last Edit: March 03, 2009, 10:14:10 AM by justy » Logged

Click for Garfield, New Jersey Forecast" border="0" height="41" width="127
Moderator_
Guest
« Reply #6 on: September 17, 2008, 09:15:33 PM »

I just got confused when you said "source" then provided a link cause I didn't get this from the link that you provided.

The link I provided is the source for what I posted. Because when we post things from other websites (copy and paste) we provide a source for it as proper etiquette. Nice thread, tomron.
« Last Edit: March 03, 2009, 10:13:47 AM by justy » Logged
tomron
Full Member
*******

Karma: 351
Offline Offline

Posts: 254



« Reply #7 on: September 17, 2008, 09:28:46 PM »

@Moderator_

Quote
The link I provided is the source for what I posted. Because when we post things from other websites (copy and paste) we provide a source for it as proper etiquette. Nice thread, tomron.

Understood and thanx.

« Last Edit: March 03, 2009, 10:12:41 AM by justy » Logged

Click for Garfield, New Jersey Forecast" border="0" height="41" width="127
Pages: 1   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
.
Custom Search