Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Spam Reports

October 27th, 2011, 11:10 GMT · By Eduard Kovacs

DHL Express Notification Serves Trojan

SHARE:

Adjust text size:


DHL transports cargo, not malware
Enlarge picture
A spam message that seems to be a notification from DHL, the popular logistics group, alerts users on the existence of an alleged shipment that may try to reach the recipient of the email.

MX Lab
discovered the malicious campaign that spreads containing subjects such as “DHL Express Notification for shipment for 26 Oct 2011” or “Notification for shipment for 26 Oct 2011.”

To make the whole thing more cleaver, the date in the subject most likely changes and the alert seems to be coming from a genuine looking spoofed address that reads something like “DHL Express International Support <parcel.support@dhl.com>”.

The body of the message urges the unsuspecting victim to follow a link or open an attachment:

26 Oct 11 08:15 AM – Clearance processing complete
PLEASE REFER TO ATTACHED FILE FOR DETAILED INFORMATION.

Shipment status may also be obtained from our Internet site in USA under http://track.dhl-usa.com or Globally under http://www.dhl.com/track
Please do not reply to this email. This is an automated application used only for sending proactive notifications


The zip file named DHL_EXPRESS_Notification_Message_NR contains an executable file which actually hides a piece of malware that was undetected by many security providers. McAfee detected it as PWS-Zbot.gen.cc and AhnLab as Win-Trojan/Obfuscated.Gen.

Unfortunately, as these sort of emails are very well designed, containing all sorts of references to the company's genuine website, it's fairly difficult to detect them as being threats.

The best thing to do in this case is to rely on your instinct and treat everything with suspicion. It's like in those fake lottery emails. If you haven't entered, why would you win? It's the same in this situation. If you're not expecting a delivery, why would you receive a notification?

Also I would not advise anyone to click on the links that seem to point to the firm's package tracking system as the connections may hide replicas of the legitimate pages which may require you to provide sensitive information.

TELL US WHAT YOU THINK:

2,419 hits · 3 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Google and Yahoo Services Become Spammers' Heaven

Fake FDIC Emails Spread Malware

YesAsia Does Not Spam Customers with Fake Bills

Royal Mail Delivers Trojan

NHS Direct Twitter Account Serves Miracle Diet Spam

READER COMMENTS:


Comment #1 by: danilal on 22 Nov 2011, 02:09 UTC reply to this comment

Thank for the warning! I have already got 4 emails of this kind, yet not opened their attachments. Now I delete them lightly...


Comment #2 by: Darcy on 29 Nov 2011, 20:36 UTC reply to this comment

great story but where can we submit this emails so that they can be tracked down?

Comment #2.1 by: Eduard Kovacs on 01 Dec 2011, 07:24 GMT

Security solutions providers are tracking them and updating their products to make sure customers are safe. The best thing to do is to make sure your antivirus is up to date and if you want to, you can mark the email as 'spam' and your email provider will take the appropriate measures.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM