Jump to content


United Parcel Scam Email


14 replies to this topic

#1 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 22 July 2008 - 09:51 AM

Just got an email from a "United Parcel Service"

Quote

Unfortunately we were not able to deliver postal package you sent on July the 1st in time
because the recipient's address is not correct.
Please print out the invoice copy attached and collect the package at our office

Your UPS
The attached word document is actually an exe in disguise and will unload malware if executed.
Virus Total
[attachment=2489:Malware.JPG]

#2 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,462 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 22 July 2008 - 10:23 AM

Looks like it's the same one as here Humpty.

http://forum.pirifor...showtopic=16761

Unfortunately someone will believe it and open the document.
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#3 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 22 July 2008 - 10:25 AM

Sorry Hazel, missed your posting.Maybe you could merge the two.

I tried to send the zipped malware package to Oleg, the developer of AVZ anti rootkit tool for addition to it's data base but had a run in with my isp email service provider.

Below is a transcript of our little run in.
My isp:

Quote

The following viruses were detected in the message (MID 132528672):
'Troj/Agent-HFZ', 'Troj/Invo-Zip'

Actions taken:
Message archived
Message dropped
My reply:

Quote

I know it's malware that I was sending to an anti malware developer for
analsyis.

Funny thing is I got the malware as an email attachment through my Iprimus account!
LOL.

Come to think about it, why can it come through to me no probs but I can't
send it for expert analysis both going via my isp's email service????
:lol:

#4 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,462 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 22 July 2008 - 01:18 PM

Excellent reply to your ISP Humpty, bet they didn't know what to say!!
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#5 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,330 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 22 July 2008 - 06:45 PM

That's why people should configure their systems to display the file extensions. It's far too easy to put any icon into a program.
Complexity of incoherent design.

#6 OFFLINE   YoKenny

    Super Power User

  • Members
  • PipPipPipPipPip
  • 2,874 posts
  • Gender:Male
  • Location:Oshawa, Ont. Canada
  • Interests:Helping people get rid of malware on their systems then showing them how not to get re-infected again

Posted 22 July 2008 - 07:43 PM

View Posthazelnut, on Jul 22 2008, 09:18 AM, said:

Excellent reply to your ISP Humpty, bet they didn't know what to say!!
If it was Rogers they would say FORMAT the hard drive and re-install the operating system.
"Education is what remains after one has forgotten everything he learned in school." - Albert Einstein
IE7Pro user

#7 OFFLINE   davey

    Keep it simple !

  • Members
  • PipPipPipPipPip
  • 2,235 posts
  • Gender:Male
  • Location:Maryland U.S.A.

Posted 23 July 2008 - 08:21 AM

View PostAndavari, on Jul 22 2008, 02:45 PM, said:

That's why people should configure their systems to display the file extensions. It's far too easy to put any icon into a program.
Thanks Andavari.
I always have because it only makes sense to me.This is a "CRITICAL" reason. I am glad you pointed it out.
There are so many "esthetic" options that make me want to puke!!! How esthetic is that ? :lol:
:) davey
P.S. Thank you all. I think I might have fallen for that except I don't use UPS. Still is tricky though.

#8 OFFLINE   AMG

    Newbie

  • Members
  • Pip
  • 2 posts

Posted 23 July 2008 - 01:47 PM

Hi,
I got this email today and unfortunetly we use UPS so much I opened it. When I clicked on the zip file nothing happened and my Norton alerted me that something was trying to change a registry & I blocked it. Does this mean I am not infected or do I need to call the Geek squad? Any help is appreciated.
AMG



View PostHumpty, on Jul 22 2008, 09:51 AM, said:

Just got an email from a "United Parcel Service"

The attached word document is actually an exe in disguise and will unload malware if executed.
Virus Total
Attachment Malware.JPG


#9 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 23 July 2008 - 02:54 PM

I think you would have to execute the file within the zip to get infected and seeing as Norton stopped the zip from opening I would say you should be safe.

If you notice anything odd such as unexpected network activity then it would be advisable to post a Hijackthis log.

Any suspect attachments or files can be uploaded to Virus Total for a scan with several different av engines.

#10 OFFLINE   AMG

    Newbie

  • Members
  • Pip
  • 2 posts

Posted 25 July 2008 - 04:44 PM

View PostHumpty, on Jul 23 2008, 02:54 PM, said:

I think you would have to execute the file within the zip to get infected and seeing as Norton stopped the zip from opening I would say you should be safe.

If you notice anything odd such as unexpected network activity then it would be advisable to post a Hijackthis log.

Any suspect attachments or files can be uploaded to Virus Total for a scan with several different av engines.

I did. I ran Mcafee and it caught 4 trojans, repaired 1, removed 1 and then I deleted one. The last one was listed but it gave me no option to repair, remove so I am not sure what my status is at the moment. It froze my Internet Explorerer and Windows Media palyer but both came back after I ran the scan.

Any suggestions would be appreciated.

#11 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 26 July 2008 - 12:00 AM

You could try a scan with Dr Web Cureit which is a free standalone AV scanner.

Then run a scan with SuperAntispyware and if any probs are still around then probably post a Hijackthis log in the appropriate forum.

Which av are you using atm, Norton's or Mcafee?

#12 OFFLINE   Seanie

    Newbie

  • Members
  • Pip
  • 1 posts

Posted 31 March 2011 - 12:23 AM

Hi all,

I just came across an email also, supposedly from UPS and the message read as follows...Dear customer.

The parcel was sent your home address.
And it will arrive within 3 business day.

More information and the tracking number are attached in document below.

Thank you.
© 1994-2011 United Parcel Service of America, Inc.

My God it isn't even in proper English!! (Grammar wise) There is an attachment with it (A UPS.Zip Download)Naturally I haven't opened it and I'm so glad that I read these posts first. I take it that so long as I haven't opened/downloaded the zip file, I'm ok yeah?

Regards to all :)

#13 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,330 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 31 March 2011 - 12:40 AM

View PostSeanie, on 31 March 2011 - 12:23 AM, said:

I take it that so long as I haven't opened/downloaded the zip file, I'm ok yeah?

Holy old topic revival Batman!:blink:

If you haven't downloaded or opened the attachment you're fine, just delete the email and possibly block the sender.
Complexity of incoherent design.

#14 OFFLINE   Corona

    Power Member

  • Members
  • PipPipPipPip
  • 1,932 posts
  • Gender:Male
  • Location:US

Posted 31 March 2011 - 12:48 PM

I don't believe UPS would send an attachment anyway, they'd post all the info in the actual email. Matter of fact I don't believe UPS would email anyone except their biggest clients.

#15 OFFLINE   slowday444

    Power Member

  • Members
  • PipPipPipPip
  • 807 posts

Posted 31 March 2011 - 03:14 PM

Another reason to use Sandboxie (or similar). If you are using web mail I'm sure Sb is already at work. If you use a POP3 client like Outlook, OE or Thunderbird, be sure to enable Sb to always run them sandboxed!