Email with United Parcel Service notification from UPS contains trojan.31 March 2011, http://blog.mxlab.eu/
New Trojan distribution campaign threatening computer security worldwide via email with the subject United Parcel Service notification. The email is send from the spoofed address United Parcel Service ****@ups.com where *** is filled in with various combinations like:
infojs@ joiner2@joiner22@joisupport@ups.comsupportadm@ups.comThe message has the following body:
Dear customer.
The parcel was sent your home address.
And it will arrive within 7 business day.
More information and the tracking number are attached in document below.
Thank you.
1994-2011 United Parcel Service of America, Inc.
The attached ZIP file in the email has the name UPSnotice.rar and contains the 16kB Trojan file... UPS notify.exe. The trojan is known as BDS/Hostil.F.9 (Antivir), rojanDownloader:Win32/Chepvil.I (Microsoft), Mal/Bredo-K (Sophos), Backdoor.Cycbot (Symantec).
The following files will be created if u unzip the email attachment:
%Temp%lol2.exe
The trojan can establish connection with the IP 193.105.121.33 on port 80 and data will be obtained from following URL hxxp://193.105.121.33/lol2.exe. Only 20 of the 43 Anti Virus engines able to detect this trojan.