Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

April 5th, 2011, 09:58 GMT · By

New DHL-Themed Malware Distribution Campaign in the Wild

SHARE:

Adjust text size:


Fake DHL emails distribute scareware
Enlarge picture
Security researchers warn of a new malware distribution campaign which produces emails with malicious attachments that pose as delivery notifications from DHL.

The rogue emails have a subject "DHL Express Services" and their headers have been forged to appear as originating from a @dhl.com address.

They inform recipients that their package is on its way and tells them to read the attached document for more information and to obtain the tracking number. The enclosed message reads:

"Dear customer. The parcel was sent to your home address. And it will arrive within 3 business day. More information and the tracking number are attached in document below. Thank you."

The attached document is called dhl.zip and contains an executable file of the same name which is a trojan downloader.

This threat is responsible for downloading additional malware including a fake antivirus called XP Home Security, according to Vietnamese security vendor Bkis.

Judging from dates of scans and comments on Virus Total for the malicious files involved in this attack, the campaign began sometime over the weekend.

It also appears to have different variations, one using FedEx as cover, probably using similar fake package delivery notifications.

This lure has been re-used in malware distribution for years now, which suggests that despite repeated warnings there are still enough people who take the bait.

At the moment, the fake antivirus program dropped by this infection has a very low detection count on Virus Total with only 4 in 40 antivirus engines detecting it based on signatures and heuristics.

These rogue programs are also known as scareware because they try to scare users into paying for licenses in order to clean infections that don't exist.

Users are advised to exercise caution when dealing with attachments in emails. Services like Virus Total can be used to scan them in order to get an indication if they are malicious or not.

TELL US WHAT YOU THINK:

1,102 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Fake USPS Emails in Circulation

Fake UPS Email Campaign Delivers Malware Cocktail

Fake FDIC Emails Distribute Trojan

Fake Failed Package Delivery Notifications Spread SpyEye

Infected DHL Emails Target Spanish Speakers

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM