In the Wild: UPS Packet Service malware SPAM - ups_invoice.zip

It's in the wild - SPAM with infected file ups_invoice.zip and my inbox has 4 of it today:

ups

ups2

63% of malware scanner will detect the infected file, if user mistakenly download retrieve this unwanted email or save or touch that file:

upsvt

Scan result:  http://www.virustotal.com/analisis/07d607ef1cfcd0b67fe27595a71a9452

NOTE:  If you will google "UPS Packet" or UPS Paket", you will see the same message posted in newsgroup and forums :(

....really in the wild so be careful guys.

Published Mon, Jul 14 2008 17:26 by donna

Comments

Monday, July 14, 2008 5:45 PM by AdamV

# re: In the Wild: UPS Packet Service malware SPAM - ups_invoice.zip

Aha! someone else finally wrote about this!

All afternoon I was waiting to get a bit more information, and eventually your post made it onto the search engine pages.

I've had three of these so far, one with a subject line and attachment name in German, two in English (one of which had a mis-spelled file name). All had the body text in English.

I've posted about my findings here:

veroblog.wordpress.com/.../ups_invoiceexe-trojan-received-by-email

tomorrow I hope to get time to open this in a sand pit and see what it actually tries to do, and how well (if at all) Vista's UAC will spot it's behaviour and prevent it by requiring admin credentials before anything too nasty can take place.

Thursday, July 24, 2008 9:59 AM by Derek Knight

# re: In the Wild: UPS Packet Service malware SPAM - ups_invoice.zip

new one released

text or email is

Good day,

We have received a parcel for you, sent from France on July 9. Please fill out the customs declaration attached to this message and send it to us by mail or fax. The address and the fax number are at the bottom of the declaration form.

Kind regards,

Geraldine Kuhn

Your Customs Service

file attached to email is

Tax_Invoice.zip

this one badly detected so far but will get better as day go on

I have had 8 in last 2 hours

Thursday, July 24, 2008 11:30 AM by AdamV

# re: In the Wild: UPS Packet Service malware SPAM - ups_invoice.zip

There seems to be a variation in the subject, body and name of the attachment with the email, now claiming to be from the customs service:

veroblog.wordpress.com/.../ups_invoice-email-trojan-variant-claims-to-be-from-customs-service