More UPS delivery malware spammed out via email

Filed Under: Malware, Spam

With apologies to Dooley Wilson..

# It's still the same old story
A fight for love or glory
A case of do or die.
The world will always welcome spammers
As time goes by.. #

Yes, the oldies are the goldies, and so long as the public are still falling for tried-and-trusted tricks why should the hackers adopt new ones?

Here's a malicious spam campaign that we've seen in large numbers in the last few hours. It's modus operandi shouldn't be any surprise to regular readers of the Clu-blog:

UPS Tracking malware email

The emails read as follows:

Hello!

We were not able to deliver postal package you sent on February the 23th in time because the recipient's address is not correct.

Please print out the invoice copy attached and collect the package at our office.

Your United Postal Service

Attached to the email is a file, UPS_ID.zip, which contains the malicious Troj/Inject-FG Trojan horse. But many users won't even realise that there's a nasty bite contained in the email attachment, such will be their belief that UPS has notified them about a failed delivery.

By the way, the tracking reference number used in the email changes each time.

Of course, this attack has not posed the boffins in SophosLabs any difficulty, and customers of our anti-spam and anti-virus solutions are protected. Play it again spam..

(Sorry, I'm so sorry..)

About the author

Graham Cluley is senior technology consultant at Sophos. The readers of Computer Weekly voted him security blogger of the year in 2009 and 2010, and he pipped Stephen Fry to the title of "Twitter user of the year" too. Which was nice. He was also named "Best Security Blogger" by the readers of SC Magazine in 2011. You can subscribe to Graham's updates on Facebook, follow him on Twitter and circle him on Google Plus for regular updates.