Trojans spammed out in malicious wave of fake DHL emails

Filed Under: Malware, Spam

DHLThere is a significant wave of malicious emails being spammed out presently, posing as notification messages from DHL.

If you make the mistake of opening the attached ZIP file you will be putting your computer at risk of infection by a Trojan horse.

There's nothing new, of course, about cybercriminals disguising their attacks as notifications from DHL.

This attack, though, is particularly aggressive and - as you can see in the examples below - uses a variety of different DHL-related subject lines, attachment names and message bodies:

Malicious DHL email

HELLO!

Dear Client, Recipient's address is wrong

Print out the invoice copy attached and collect the package at our department

Best wishes , DHL Customer Services

Malicious DHL email

ATTENTION!
DEAR CLIENT , We were not able to deliver the postal package

Please print out the invoice copy attached and collect the package at our department

Pack it. Ship ip. No calculating, Your DHL .com Customer Services

Malicious DHL email

Good afternoon!

DEAR CUSTOMER, Recipient's address is wrong
PLEASE PRINT OUT THE INVOICE COPY ATTACHED AND COLLECT THE PACKAGE AT OUR DEPARTMENT

Pack it. Ship ip. No calculating, Your DHL .com Customer Services

Malicious DHL email

Good afternoon!

Dear User , Delivery Confirmation: FAILED
Please print out the invoice copy attached and collect the package at our department
With respect to you, DHL Team

Here are just some of the different disguises we saw in a snapshot of less than one minute in a small selection of our spam traps:

Malicious DHL email subject lines

Sophos products intercept the attack, detecting the ZIP file as Troj/Invo-Zip and the Trojan horse contained within as Mac/EncPk-NS.

Dangerous emails claiming to come from courier companies are nothing new - it has become one of the most commonly-used methods by which hackers socially engineer unsuspecting users into opening a malicious attachment or clicking on a dangerous link.

Make sure that you and your friends are wise to the trick - and think before you click.

, , , ,

You might like

8 Responses to Trojans spammed out in malicious wave of fake DHL emails

  1. maxrosecollins · 971 days ago

    Who falls for this?!

    If you just look at the email address it was sent from you know it is spam!

    and my spam blocker picks them up every time.

    You must be a mug to fall for these emails

    • Tony · 971 days ago

      High pressure business are not interested in a "from" address, Only the content of any email that may affect their business concerns,
      This is the exact oversight the spammers are trying to exploit, and it does work.
      The management lot that have no time to assess a from address. and think abaout it, why should they care?, they pay mega bucks to us IT lot to worry about that sort of thing.

  2. jacob hinson · 971 days ago

    I also got one the other day from the 'new york police department' about a parking ticket!

    ive not been to new york, i like in the UK!

  3. Tony · 971 days ago

    Did notice however that the Sophos Gateway appliance took a bit of time to get on top of these, when the first started appearing, :) Just a friendly dig.... you guys do a top job - keep up the good work!!!

  4. Draula68 · 971 days ago

    I think they are funny. DHL closed in my area 2 years ago and does not deliver at all here. Stupid idiots!!!!!

  5. nicolasconnault · 971 days ago

    Look guys, neither the cyber-criminals, nor the victims are complete idiots. The criminals aren't idiots because they know that at least a few people will fall for the trick. The victims aren't idiots because some of them might actually be expecting a parcel from DHL. It just takes a moment's inattention or lack of vigilance, that's all.

  6. Sherlee · 971 days ago

    This happened to me with a Fed Ex email. It stated our package would be delivered within 7 days, and to reply to the email for the details. I knew we were not expecting a package, so immediately deleted the email. Thanks to Sophos posts on FB, I have been made aware of the possible problems involved in such things.

  7. Georgy · 969 days ago

    I just want to point to the issue that usually spammers leave behind misspellings. And in exemple #2 and #3, we can see the Pack it. Ship ip instead of Pack it. Ship IT !

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

About the author

Graham Cluley is an award-winning security blogger, and veteran of the anti-virus industry having worked for a number of security companies since the early 1990s. Now an independent security analyst, he regularly makes media appearances and gives computer security presentations. Send Graham an email, subscribe to his updates on Facebook, follow him on Twitter and App.net, and circle him on Google Plus for regular updates.