Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

United Parcel Service - Fake email for package non-delivery

Email McAfee and other AV vendors are highlighting this latest social engineering attack.  A well disquised email message appears to come from UPS.  It claims that a package cannot be delivered unless the fake waybill attachment is selected. 
 
Users selecting these attachments will be infected with malicious code from a downloader that originates from a Russian website

United Parcel Service - Fake email for package non-delivery 
http://vil.mcafeesecurity.com/vil/content/v_132901.htm
http://wcco.com/techcenter/ups.email.virus.2.771489.html
http://urbanlegends.about.com/b/2008/07/15/ups-virus-warning.htm
http://www.startribune.com/local/25464324.html
http://www.ups.com/content/us/en/about/news/service_updates/virus_us.html

QUOTE: United Parcel Service is warning of a computer virus circulating under the guise of an e-mail from UPS. According to a release from UPS, the virus is attached to an e-mail that warns readers they have a shipment that couldn't be delivered unless they click on the attachment. The e-mail claims the attachment contains a waybill that will allow the undelivered package to be picked up.

COPY OF EMAIL MESSAGE: (spoofed to appear from UPS)

"Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct. Please print out the invoice copy attached and collect the package at our office. 
 
Your UPS"

The attached file is an executable which downloads files from the following server:

hxxp: //fixaserver (dot) ru / ldr / [Removed]

Comments

Kevin Ball said:

They seem to have updated the content of the e-mail, I received this today

Good day,

We have received a parcel for you, sent from France on July 9. Please fill out the customs declaration attached to this message and send it to us by mail or fax. The address and the fax number are at the bottom of the declaration form.

Kind regards,

Errol Hastings

Your Customs Service

# July 25, 2008 5:27 AM

louise college said:

i have recieved this email today, i opened thew email but not the attachment, since then my computer has not worked properly, none of my number buttons work, i cannot do a system restore or open files, i have done three virus checks with 3 different companies but cannot find a virus, my computer was fine until this email came, i am not running a fourth checker that is scanning files that i shouldnt have on my system, it includes thousands of full file games which i dont even have on my system, i really think there is no hope and i may lose everything on my system, i warn anyone if you see a email from ups dont even open it, DELETE IT!!!

# August 5, 2008 12:41 PM

Simon said:

Received the e-mail this evening - fortunately the BT filter on my e-mail account picked up the virus and deleted the file.

Also received one yesterday from another American company with a suggestion that they had received my bank statement by e-mail and wanted me to stop the bank sending further personal infomation - the attached "statement" would have been another virus but good old BT blocked that as well.

# September 11, 2008 3:30 PM

Shane said:

I have just received this one today

Unfortunately we were not able to deliver postal package you sent on Sept the 18 in time

because the recipient's address is not correct.

Please print out the invoice copy attached and collect the package at our office

Your UPS

# September 28, 2008 1:42 PM

Bitten said:

I have just received this one yesterday

Unfortunately we were not able to deliver postal package you sent on Sept the 28 in time

because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office

Your UPS

# September 30, 2008 11:47 PM

carm vass - b'ham england said:

I received this email today...did not open the attachment.  It said, "Unfortunately we were not able to deliver postal package you sent on Sept the 28 in time

because the recipient's address is not correct.  Please print out the invoice copy attached and collect the package at our office.  Your UPS"

# October 1, 2008 12:49 PM

mobcat said:

I am in Australia got this today :)

Unfortunately we were not able to deliver postal package you sent on Sept the 18 in time

because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office

Your UPS

# October 3, 2008 6:28 PM

chris said:

i'm in ny but have an old UK email address, and just got a variation of this today. strangely, i did send a package on that day, which is why i double-checked it online rather than just mark it as spam.

subject: Your Tracking # 6539175260

from:UPS Mail Support <rfbrxohoxgft@bovar.com>

attachment: UPSINVOICE_8000073.zip (55KB)

Sorry, we were not able to deliver postal package you sent on October the 19th in time because the recipients address is not correct.

Please print out the invoice copy attached and collect the package at our office.

If you do not receive package in ten days you will have to pay 6$ per day.

Your UPS

# November 7, 2008 3:09 PM

Matt said:

Sorry, we were not able to deliver postal package you sent on November the 1st in time

because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office.

If you do not receive package in ten days you will have to pay 36$ per day.

Your UPS

(Following everyones advice I am going to delete this email. Thanks for the warning! Cheers, Matt)

# November 18, 2008 9:18 PM

TG said:

Sorry, we were not able to deliver postal package you sent on November the 1st in time because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office.

If you do not receive package in ten days you will have to pay 36$ per day.

Your UPS

# November 19, 2008 6:12 PM

Peter said:

I got the following two days after requesting a delivery from www.cdon.com. Might be a coinsident though:

Sorry, we were not able to deliver postal package you sent on November the 1st in timebecause the recipient’s address is not correct. Please print out the invoice copy attached and collect the package at our office.If you do not receive package in ten days you will have to pay 36$ per day. Your UPS

# November 20, 2008 11:00 AM

Gretl said:

I recently ordered something from Amazon.de, then canceled the order shortly afterwards and received this email on the day that the package was set to arrive (had it not been canceled)...perhaps they're tracking purchase websites for potential victims--people that might be inclined to expect a package.

Here's what I received:

"Sorry, we were not able to deliver postal package you sent on November the 1st in time

because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office.

If you do not receive package in ten days you will have to pay 36$ per day.

Your UPS"

# November 21, 2008 6:21 PM

Bjørn Tore said:

This email has arrived e-mails i Norway to.

Denne e-posten har kommet til Norge også:

It look like this.

Den ser slik ut:

Unfortunately we were not able to deliver postal package you sent on Nov the 7 in time

because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office

Your UPS

# November 28, 2008 7:40 AM

Simon said:

I got it today:

Sorry, we were not able to deliver postal package you sent on November the 1st in time

because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office.

If you do not receive package in ten days you will have to pay 36$ per day.

Your UPS

Mailwasher Pro picked it up and labelled it as spam, and a report has been sent to Spamcop.

# November 28, 2008 7:02 PM

my name said:

Sorry, we were not able to deliver postal package you sent on November the 1st in time

because the recipients address is not correct.

Please print out the invoice copy attached and collect the package at our office.

If you do not receive package in ten days you will have to pay 36$ per day.

Your UPS

i was so stupid and i clocked on the attachment, but my computer gave me a notice "virus detected in the attachment, are you sure you want to open?"

so i deleted the email and shut down my computer. hopefully everything is ok.

# December 10, 2008 4:30 PM

francesco said:

Sorry, we were not able to deliver postal package you sent on November

the 1st in time

because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at

our office.

If you do not receive package in ten days you will have to pay 36$ per

day.

Your UPS

# December 14, 2008 4:17 PM

MacSafe said:

I love my mac...this stupid virus doesn't work in it...

# December 17, 2008 11:57 AM

reese said:

Just got the same one today, but the message was updsted to "...sent on November 25th..."

# December 18, 2008 9:36 AM

brigid LaBonge said:

mine was updated to "...on December 25th"

# January 13, 2009 7:25 PM

Hans Fielsch said:

Same email was in my inbox today.  A few items about it seemed suspicious: the email referst to the package as "postal", which makes reference to the USPS versus UPS, but it's signed as coming from "UPS Team".  Secondly, the email is not addressed to me by name, which always makes me nervous.  Lastly, I know FOR A FACT, that I do not give UPS my email address when I send packages.  If you know even a little bit about how bogus emails "feel and smell", then this one does not seem genuine.  A quick check on the internet confirmed my doubts and I double-deleted the entire email off my computer.

# March 3, 2009 4:09 PM

Kathy Rodriguez said:

Got the same email today,  Still going around...

# May 27, 2009 5:55 PM

Christian Nielsen said:

I received this email today. Seems like it's making a comeback.

# June 4, 2009 3:00 PM