If you or anyone in your organization is confused about the latest round of emails claiming to be from UPS concerning delivery notices, let’s make it clear that if they contain an EXE and a ZIP attachment then they’re most certainly viruses.
Subject lines for this latest campaign are fairly similar, with a randomized number tacked onto the end to help avoid simplistic spam filters:
- UPS Tracking Number 1890244.
- UPS Delivery Problem NR.34839
- UPS Delivery Problem Number 74426.
And the “spoofed” from addresses are pretty consistent as well, claiming to come from 3 variations of the UPS.com domain, with random fake names inserted:
- UPS Manager Percy Peck <firstname.lastname@example.org>
- UPS Manager Norris Tyson <email@example.com>
- UPS Support Wanda Bates <firstname.lastname@example.org>
The email itself is generally consistent as:
Unfortunately we failed to deliver postal package you have sent on the 1st of June in time because the addressee’s address is incorrect.
Please print out the invoice copy attached and collect the package at our department.
United Parcel Service of America.
Finally, the attachments, which are the actual virus payload, are also easy to spot, claiming to be invoices, with one an “exe” and the other a “zip” compressed file:
The virus campaign itself is spread by infected personal computers connected to the Internet worldwide, and as diverse as:
Opening or executing either of the attachments will no doubt result in adding your own PC to the list.
Here’s a PDF document from the UPS website referencing some older variations of spam, fraud and virus emails spoofed from the UPS.com domain:
OnlyMyEmail is an award winning hosted spam filtering service and business email hosting provider. Our enterprise cloud computing anti-spam solution, the MX-Defender, has the highest capture rate of any spam filter ever tested in the VBSpam Challenge, blocking a record setting 99.9993% of all malicious and junk email.
Our Personal spam filtering system is also a Software as a Service (SaaS) solution and has won both the PC World "World Class Award" and also the PC Magazine "Editor's Choice Award."
OME-Kids is a webmail solution that protects children from spam and other harmful emails. OME-Kids offers unique Parental Controls that allow you to choose the level of security and oversight that's right for your child.