<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;UPS packet (ups_invoice.zip) WORM&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/UPS-packet-upsinvoicezip-WORM-20789896</link>
<description></description>
<language>en</language>
<pubDate>Fri, 10 Feb 2012 10:41:30 EDT</pubDate>
<lastBuildDate>Fri, 10 Feb 2012 10:41:30 EDT</lastBuildDate>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20861336</link>
<description><![CDATA[anon posted : For any Vista users out there, this installs in a completely different place and way then the other Win OSes.<br>It drops teh ntos.exe file in C:\user\your_username\appdata\roaming<br>The audio.dll and video.dll are dropped in:<br>C:\user\your_username\appdata\roaming\wsnpoem<br><br>I booted into safemode, changed the folder options to see hidden and protected operating system files and folders, then deleted the wmspoem folder and the ntos.exe file.<br><br>Rebooted and logged in and then went into the registry, under HKUsers\S-1-5-21-* long SID string, the Non Classes one\Software\Microsoft\Windows\Currentversion\Run and deleted teh reg key that pointed to ntos.exe. After that the machine was working fine.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20861336</guid>
<pubDate>Mon, 28 Jul 2008 14:39:30 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20860201</link>
<description><![CDATA[amysheehan posted : <div class="bquote"><small>said by <a href="/profile/586276" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=586276');">premio</a>:</small><br><br>I'm seeing a lot of these come through the corporate servers, seemingly undetected by McAfee.  <br><br>Any insight?<br> </div>Here's what I found.<br>Note: McAfee comments in article<br>&raquo;<A HREF="http://www.vnunet.com/vnunet/news/2222590/spammers-deliver-bogus-invoices" >www.vnunet.com/vnunet/news/22225&middot;&middot;&middot;invoices</A><br><br>-amy-<br><small>--<br>Proud Member of <A HREF="http://asap.maddoktor2.com">ASAP</a><br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20860201</guid>
<pubDate>Mon, 28 Jul 2008 10:41:11 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20848843</link>
<description><![CDATA[kpatz posted : Here's another variation a co-worker received:<br><br> <blockquote><small>quote:</small><hr>From: Jackie Gleason" Continental Airlines [mailto:(removed)]<br>Sent: Friday, July 25, 2008 2:26 PM<br>To: (My coworker)<br>Subject: Your order from {airlines} N5240753<br><br>Good day,<br>Thank you for using our new service "Buy airplane ticket Online" on our website.<br>Your account has been created:<br><br>Your login: David<br>Your password: pass3GR9<br><br>Your credit card has been charged for $423.90.<br>We would like to remind you that whenever you order tickets on our website you get a discount of 10%!<br>Attached to this message is the purchase Invoice and the airplane ticket.<br>To use your ticket, simply print it on a color printed, and you are set to take off for the journey!<br><br>Kind regards,<br>Jackie Gleason<br>Continental Airlines<br><hr></blockquote><br>It had 2 files attached: another copy of the email (but with different names--I don't know if it came in that way or if my co-worker forwarded it that way), and a file called E-ticket_N7399294.zip.<br><br><pre class="brush: text">e3254936ed358457ed303529e7c2fa8f  E-ticket_N7399294_and_Invoice_for_N73992943442.exe&#012;68370361733b8f768a84c430c22dc06e  E-ticket_N7399294.zip&#012; &#012;</pre><!--end code block--><br>Scan results on my Linux box:<br><br><pre class="brush: text">Scanning with clamav: E-ticket_N7399294_and_Invoice_for_N73992943442.exe&#012;/home/kpatz/E-ticket_N7399294_and_Invoice_for_N73992943442.exe: Trojan.Zbot-1715 FOUND&#012; &#012;----------- SCAN SUMMARY -----------&#012;Infected files: 1&#012;Time: 7.391 sec (0 m 7 s)&#012; &#012;Scanning with f-prot: E-ticket_N7399294_and_Invoice_for_N73992943442.exe&#012; &#012;F-PROT Antivirus version 6.2.1.4252 (built: 2008-04-28T16-44-10)&#012;FRISK Software International (C) Copyright 1989-2007&#012; &#012;Engine version: 4.4.4.56&#012;Virus signatures: 2008072515489bbd19ce2aeeb422702f2f2adda83930&#012;                  (/usr/local/f-prot/antivir.def)&#012; &#012;&#91;Found trojan&#93; &lt;W32/Trojan2.AUFO (exact)&gt;       E-ticket_N7399294_and_Invoice_for_N73992943442.exe&#012; &#012;Running time: 00:10&#012; &#012;Scanning with AVG: E-ticket_N7399294_and_Invoice_for_N73992943442.exe&#012;AVG7 Anti-Virus command line scanner&#012;Copyright (c) 2007 GRISOFT, s.r.o.&#012;Program version 7.5.51, engine 442&#012;Virus Database: Version 270.5.6/1574  2008-07-25&#012;License type is FREE.&#012;E-ticket_N7399294_and_Invoice_for_N73992943442.exe  Trojan horse Pakes_c.SA&#012;Tested: 1 files, 0 sectors&#012;Infections: 1&#012;Errors: 0&#012; &#012;Scanning with AVAST: E-ticket_N7399294_and_Invoice_for_N73992943442.exe&#012;/home/kpatz/E-ticket_N7399294_and_Invoice_for_N73992943442.exe  &#91;OK&#93;&#012; &#012;</pre><!--end code block--><br><small>--<br>When providing an online service, such as email, 5% of the work goes into providing the service, and the other 95% goes into preventing or dealing with abusers of the service.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20848843</guid>
<pubDate>Fri, 25 Jul 2008 16:38:48 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20847863</link>
<description><![CDATA[anon posted : I'm looking for the outbound address this contacts - we've had several machines compromised by this as well, and I'd like to add an outbound firewall rule to block connection to the C&C server for the time being.  I'm sure they'll change that address at some point, but if I can at least contain the problem until the AV vendors catch up with this...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20847863</guid>
<pubDate>Fri, 25 Jul 2008 13:25:22 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20844559</link>
<description><![CDATA[Phil posted : I've been getting them at the office as well.  Mail server's Kaspersky anti-virus is not picking them up although NOD32 running on client PCs is.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20844559</guid>
<pubDate>Thu, 24 Jul 2008 20:01:12 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20844549</link>
<description><![CDATA[kpatz posted : <div class="bquote"><small>said by AdamV :</small><br><br>A further variation on this theme seems to have appeared today, claiming to be from the customs service who are holding a parcel:<br>&raquo;<A HREF="http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/" >veroblog.wordpress.com/2008/07/2&middot;&middot;&middot;service/</A><br> </div>My boss got this one too.  She forwarded me a copy to examine, which was handy since I used it to test my updated spam filter with virus scan capability. :)<br><br>8ceb0f61089d86c086dcc08d6a783015  Tax_Invoice_________________________NHHDLS883298792929.exe<br>959c5eebf417181ba8bc59ba8572cc41  Tax_Invoice.zip<br><br>Clam and F-prot detect it presently, but AVG and Avast don't.  I haven't tried any other scanners, or Jotti/Virustotal yet.  I'll submit it. ;)<br><small>--<br>When providing an online service, such as email, 5% of the work goes into providing the service, and the other 95% goes into preventing or dealing with abusers of the service.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20844549</guid>
<pubDate>Thu, 24 Jul 2008 20:00:07 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20844368</link>
<description><![CDATA[FiOS Dan posted : <div class="bquote"><small>said by <a href="/profile/762261" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=762261');">CKizer</a>:</small><br><br>Here is the analysis:<br><br>&raquo;<A HREF="http://www.virustotal.com/analisis/1725062b8c2a6271e2a098556f92b5b0" >www.virustotal.com/analisis/1725&middot;&middot;&middot;6f92b5b0</A><br> </div>Not a pretty sight.  :(<br><small>--<br><i>Courage is being scared to death but saddling up anyway.</i><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20844368</guid>
<pubDate>Thu, 24 Jul 2008 19:26:54 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20844087</link>
<description><![CDATA[CKizer posted : <div class="bquote"><small>said by AdamV :</small><br><br>A further variation on this theme seems to have appeared today, claiming to be from the customs service who are holding a parcel:<br>&raquo;<A HREF="http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/" >veroblog.wordpress.com/2008/07/2&middot;&middot;&middot;service/</A><br> </div>Here is the analysis:<br><br>&raquo;<A HREF="http://www.virustotal.com/analisis/1725062b8c2a6271e2a098556f92b5b0" >www.virustotal.com/analisis/1725&middot;&middot;&middot;6f92b5b0</A><br><small>--<br>Crunching for Help Defeat Cancer and FightAIDS@Home at the World Community Grid.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20844087</guid>
<pubDate>Thu, 24 Jul 2008 18:24:54 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20841995</link>
<description><![CDATA[anon posted : A further variation on this theme seems to have appeared today, claiming to be from the customs service who are holding a parcel:<br>&raquo;<A HREF="http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/" >veroblog.wordpress.com/2008/07/2&middot;&middot;&middot;service/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20841995</guid>
<pubDate>Thu, 24 Jul 2008 12:28:30 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20820139</link>
<description><![CDATA[trburkholder posted : md5sum of ups_invoice.zip 5b70ee6faffa80461eb3dff854b69d5c<br>md5sum of ups_invoice.exe 20c03fdaa12c08e36a26c7ace3ce3403<br><br>ClamAV 0.92.1 doesn't recognize this as a trojan.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20820139</guid>
<pubDate>Sun, 20 Jul 2008 11:52:21 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20800308</link>
<description><![CDATA[jbob posted : OT:  For those with issues with Gmail and exe files see this link:<br>&raquo;<A HREF="http://mail.google.com/support/bin/answer.py?answer=6590" >mail.google.com/support/bin/answ&middot;&middot;&middot;wer=6590</A><br><br><div class="bquote">As a security measure to prevent potential viruses, Gmail doesn't allow you to send or receive executable files (such as files ending in .exe) that could contain damaging executable code.<br><br>Gmail won't accept these types of files even if they are sent in a zipped (.zip, .tar, .tgz, .taz, .z, .gz) format. If this type of message is sent to your Gmail address, it is bounced back to the sender automatically.<br></div>I suppose you could rename the extension to anything but exe and leave instructions.  Or double compress the file.  Zip it then RAR/7zip, etc,  might help.<br><br>Edit:  Added...verified renaming works as well as double compression archiving.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20800308</guid>
<pubDate>Wed, 16 Jul 2008 12:53:07 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20798581</link>
<description><![CDATA[anon posted : <div class="bquote"><small>said by <a href="/profile/1303852" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1303852');">zteardrop</a>:</small><br><br><div class="bquote"><small>said by AlexSossa :</small><br><br>On the day this was sent through, I was awaiting a package from UPS, there were hassles at my address, with the road closed off due to a fire....<br><br>It got me, I clicked. How annoying. Have identified it as:<br><br>Win32.Obitel  trojan, although I cannot find a remover. VArious scans have failed, can anyone suggest a removal tool?<br><br>Many Thanks<br> </div>Please tell me this was a coincidence. If not then you have bigger problems.<br> </div>yup total coincidence. <br>Just my luck I guess, was half asleep at the time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20798581</guid>
<pubDate>Wed, 16 Jul 2008 03:48:28 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20798447</link>
<description><![CDATA[zteardrop posted : <div class="bquote"><small>said by AlexSossa :</small><br><br>On the day this was sent through, I was awaiting a package from UPS, there were hassles at my address, with the road closed off due to a fire....<br><br>It got me, I clicked. How annoying. Have identified it as:<br><br>Win32.Obitel  trojan, although I cannot find a remover. VArious scans have failed, can anyone suggest a removal tool?<br><br>Many Thanks<br> </div>Please tell me this was a coincidence. If not then you have bigger problems.<br><small>--<br>The official Norton Forum from Symantec: &raquo;<A HREF="http://community.norton.com/norton/" >community.norton.com/norton/</A> - where you really are allowed to say good things about Norton without getting banned !!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20798447</guid>
<pubDate>Wed, 16 Jul 2008 02:12:41 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20796970</link>
<description><![CDATA[premio posted : I understand and support the need to protect the end user, but I do not like this Windows, hide everything and do it automatically, approach.  There should be a way to over-ride these precautions.  I can't believe Google jumped into this mindset.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20796970</guid>
<pubDate>Tue, 15 Jul 2008 20:41:36 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20796960</link>
<description><![CDATA[Doctor Olds posted : <div class="bquote"><small>said by <a href="/profile/717751" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=717751');">Stem Bolt</a>:</small><br><br>Try WinRAR. You can set a password and choose to encrypt the file names within the archive. This will hide the name of the files from Gmail and Yahoo. <br> </div>I second the WinRAR recommendation and you can get a free older version 3.51 that has a non-upgradeable licence here:<br><br>&raquo;<A HREF="/forum/remark,18960910">[Free] Fully Registered WinRAR 3.51 (non-upgradeable)</A><br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20796960</guid>
<pubDate>Tue, 15 Jul 2008 20:38:28 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20796268</link>
<description><![CDATA[Stem Bolt posted : <div class="bquote"><small>said by <a href="/profile/424692" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=424692');">FiOS Dan</a>:</small><br><br>Same "WTF" here <b>premio</b>...unable to send an encrypted zip file last night via gmail.  :(<br> </div>Try WinRAR. You can set a password and choose to encrypt the file names within the archive. This will hide the name of the files from Gmail and Yahoo. <br><small>--<br><A HREF="http://www.drweb.com">Dr. Web</a> + <A HREF="http://www.nsclean.com">BOCLEAN: Anti-Malware</a> + Router/SPI</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20796268</guid>
<pubDate>Tue, 15 Jul 2008 18:32:48 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20795404</link>
<description><![CDATA[kpatz posted : Try renaming the .exe to .txt, then zip w/encryption, and see if it'll go through gmail.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20795404</guid>
<pubDate>Tue, 15 Jul 2008 15:42:30 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20795067</link>
<description><![CDATA[FiOS Dan posted : Same "WTF" here <b>premio</b>...unable to send an encrypted zip file last night via gmail.  :(<br><small>--<br><i>Courage is being scared to death but saddling up anyway.</i><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20795067</guid>
<pubDate>Tue, 15 Jul 2008 14:39:56 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20794912</link>
<description><![CDATA[premio posted : gmail will not allow me to send a .zip with a .exe in it, encrypted or not.  In fact I can not send a zip file, with an encrypted zip file in that contains a .exe.<br><br>wtf]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20794912</guid>
<pubDate>Tue, 15 Jul 2008 14:08:25 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20794655</link>
<description><![CDATA[Kayrac posted : did you password protect it?, gmails been annoying me lately]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20794655</guid>
<pubDate>Tue, 15 Jul 2008 13:13:59 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20794530</link>
<description><![CDATA[premio posted : Mine had a md5 of: 5bf574f62af6ecedbc8d3b43d4ed5f4b<br><br>I couldn't send it through gmail or yahoo as it was stripped, and a friendly mod deleted my attachment here :)<br><br>Was this just someone buying a malware creation tool, and packaging their own variant that was different enough on signature to not be detected?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20794530</guid>
<pubDate>Tue, 15 Jul 2008 12:45:40 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20794062</link>
<description><![CDATA[Kayrac posted : "MD5 hash of 6B4EF50E3E21205685CEA919EBF93476 which is the same as the one posted by Kayrac on the broadbandreports.com forum. Unfortunately he did not say what the name of the containing zip file was."<br><br>it's ups_invoice.zip, no subfolders, just opens to ups_invoice.exe :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20794062</guid>
<pubDate>Tue, 15 Jul 2008 11:06:10 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20794053</link>
<description><![CDATA[anon posted : I had four files with three different MD5 hashes. One matched Kayrac's, one of mine I think may have been broken anyway but I had two files with the same hash which is different from the one posted above:<br>58AC24B1F802990387870D3A5CC2312B<br>more here:<br>&raquo;<A HREF="http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/" >veroblog.wordpress.com/2008/07/1&middot;&middot;&middot;-trojan/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20794053</guid>
<pubDate>Tue, 15 Jul 2008 11:03:24 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20793076</link>
<description><![CDATA[anon posted : ok will do,<br><br>Am using Avast 4.8]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20793076</guid>
<pubDate>Tue, 15 Jul 2008 04:39:41 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20793061</link>
<description><![CDATA[amysheehan posted : <div class="bquote"><small>said by AlexSossa :</small><br><br>On the day this was sent through, I was awaiting a package from UPS, there were hassles at my address, with the road closed off due to a fire....<br><br>It got me, I clicked. How annoying. Have identified it as:<br><br>Win32.Obitel  trojan, although I cannot find a remover. VArious scans have failed, can anyone suggest a removal tool?<br><br>Many Thanks<br> </div>Submit the file using this info and links to all the vendors -<br>What AV are you using?<br><br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428#submit">I think my computer is infected or hijacked. What should I do?</A><br><br>-amy=<br><small>--<br>Proud Member of <A HREF="http://asap.maddoktor2.com">ASAP</a><br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20793061</guid>
<pubDate>Tue, 15 Jul 2008 04:25:19 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20793035</link>
<description><![CDATA[anon posted : <br>On the day this was sent through, I was awaiting a package from UPS, there were hassles at my address, with the road closed off due to a fire....<br><br>It got me, I clicked. How annoying. Have identified it as:<br><br>Win32.Obitel  trojan, although I cannot find a remover. VArious scans have failed, can anyone suggest a removal tool?<br><br>Many Thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20793035</guid>
<pubDate>Tue, 15 Jul 2008 03:57:38 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20792423</link>
<description><![CDATA[HA Nut posted : I never get to see any of these anymore. :( All zip's, exe's and several more are blocked from all email. If someone sends us a zip we really need, it has to be specially pulled from quarantine. (Of course, this also gives us zero day protection from all this junk. ;) )]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20792423</guid>
<pubDate>Mon, 14 Jul 2008 23:44:27 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20792207</link>
<description><![CDATA[rfnut posted : Trend Micro 2006 latest pre-release definitions identified it. But the release definitions did not flag it at all.<br><br>Incident name: ups_invoice.exe <br>Detection name: TROJ_DLOADR.GG ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20792207</guid>
<pubDate>Mon, 14 Jul 2008 22:50:28 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20791539</link>
<description><![CDATA[kpatz posted : The big cheese at work got one of these, she forwarded it to me to look at, I found it was detected as a variant of the Agent trojan.<br><br>SAV CE detected it with the current definitions.<br><br><pre class="brush: text">kpatz@zuul:~$ ls -l UPS*&#012;-rw-r--r-- 1 kpatz kpatz 5420 2008-07-14 13:58 UPS_Invoice_317.zip&#012;kpatz@zuul:~$ unzip UPS*&#012;Archive:  UPS_Invoice_317.zip&#012;   creating: UPS_Invoice_317/&#012;   creating: UPS_Invoice_317/Ups_invoice/&#012;  inflating: UPS_Invoice_317/Ups_invoice/UPS_INVOICE.exe&#012;kpatz@zuul:~$ cd UPS*&#012;kpatz@zuul:~/UPS_Invoice_317$ cd Ups*&#012;kpatz@zuul:~/UPS_Invoice_317/Ups_invoice$ ls -l&#012;total 8&#012;-rw-r--r-- 1 kpatz kpatz 8192 2008-07-13 19:16 UPS_INVOICE.exe&#012;kpatz@zuul:~/UPS_Invoice_317/Ups_invoice$ md5sum *&#012;6b4ef50e3e21205685cea919ebf93476  UPS_INVOICE.exe&#012;kpatz@zuul:~/UPS_Invoice_317/Ups_invoice$ clamdscan UPS*&#012;/home/kpatz/UPS_Invoice_317/Ups_invoice/UPS_INVOICE.exe: Trojan.Agent-30547 FOUND&#012; &#012;----------- SCAN SUMMARY -----------&#012;Infected files: 1&#012;Time: 0.017 sec (0 m 0 s)&#012;kpatz@zuul:~/UPS_Invoice_317/Ups_invoice$ fpscan UPS*&#012; &#012;F-PROT Antivirus version 6.2.1.4252 (built: 2008-04-28T16-44-10)&#012;FRISK Software International (C) Copyright 1989-2007&#012; &#012;Engine version: 4.4.4.56&#012;Virus signatures: 2008071415427fe6e809e5301f82aca02e1a890f8a03&#012;                  (/usr/local/f-prot/antivir.def)&#012; &#012;&#91;Found trojan&#93; &lt;W32/Trojan2.ATAB (exact)&gt;       UPS_INVOICE.exe&#012; &#012;Disinfect (Y/N/A/Q) ?&#012; &#012;</pre><!--end code block-->My copy (well, the big cheese's) has the same MD5 as Kayrac's.<br><br>None of my addresses have been hit, yet.  My main address has the world's most powerful spam blocker so I probably won't see it at all there. :D<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20791539</guid>
<pubDate>Mon, 14 Jul 2008 20:35:02 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20791169</link>
<description><![CDATA[beck posted : UPS Brown Bulletin (from UPS)<br><br>Attention Virus Warning <br><br>We have become aware there is a fraudulent e-mail being sent that says it is coming from UPS and leads the reader to believe that a UPS shipment could not be delivered. The reader is advised to open an attachment reportedly containing a waybill for the shipment to be picked up. <br><br>This e-mail attachment contains a virus. We recommend that you do not open the attachment, but delete the e-mail immediately.<br><br>UPS may send official notification messages on occasion, but they rarely include attachments. If you receive a notification message that includes an attachment and are in doubt about its authenticity, please contact customerservice@ups.com.<br><br>Please note that UPS takes its customer relationships very seriously, but cannot take responsibility for the unauthorized actions of third parties.<br><br>Thank you for your attention. <br><br>--------------------------------------------------------------------------------<br><br>&copy; 2008 United Parcel Service of America, Inc. UPS, the UPS brandmark, and the color brown are<br>trademarks of United Parcel Service of America, Inc. All rights reserved.<br><br>Click here to unsubscribe the UPS Brown Bulletin.<br><br>If you would like to be added to the UPS Brown Bulletin distribution, click here.<br><br>For information on UPS's privacy practices refer to the UPS Privacy Policy.<br>Please do not reply to this e-mail.<br><small>--<br><b>Some people are like slinkies - not really good for much.</b> <br>But they bring a smile to your face when pushed down the stairs.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20791169</guid>
<pubDate>Mon, 14 Jul 2008 19:24:43 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20790964</link>
<description><![CDATA[anon posted : I've had three so far today. I get the impression that the trojan itself is relatively common, but no-one is referring to it as the "UPS packet invoice email trojan" (or whatever).<br><br>More here:<br>&raquo;<A HREF="http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/" >veroblog.wordpress.com/2008/07/1&middot;&middot;&middot;y-email/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20790964</guid>
<pubDate>Mon, 14 Jul 2008 18:40:55 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20790603</link>
<description><![CDATA[Kayrac posted : File ups_invoice.exe received on 07.14.2008 22:58:52 (CET)<br>Current status: finished <br><br>Result: 24/33 (72.73%)<br> Compact Print results  <br>Antivirus Version Last Update Result <br>AhnLab-V3 2008.7.11.0 2008.07.14 Win-Trojan/Downloader.8192.LL <br>AntiVir 7.8.0.64 2008.07.14 TR/Dldr.Tiny.brm <br>Authentium 5.1.0.4 2008.07.14 W32/Trojan2.ATAB <br>Avast 4.8.1195.0 2008.07.14 Win32:Tiny-UR <br>AVG 7.5.0.516 2008.07.14 SHeur.BWIM <br>BitDefender 7.2 2008.07.14 Trojan.Downloader.Gadja.C <br>CAT-QuickHeal 9.50 2008.07.14 TrojanDownloader.Tiny.brm <br>ClamAV 0.93.1 2008.07.14 Trojan.Agent-30547 <br>DrWeb 4.44.0.09170 2008.07.14 Trojan.DownLoad.1379 <br>eSafe 7.0.17.0 2008.07.14 - <br>eTrust-Vet 31.6.5954 2008.07.14 Win32/SillyDl.EUC <br>Ewido 4.0 2008.07.14 - <br>F-Prot 4.4.4.56 2008.07.14 W32/Trojan2.ATAB <br>F-Secure 7.60.13501.0 2008.07.14 Trojan-Downloader.Win32.Obitel.a <br>Fortinet 3.14.0.0 2008.07.14 - <br>GData 2.0.7306.1023 2008.07.14 Trojan-Downloader.Win32.Obitel.a <br>Ikarus T3.1.1.26.0 2008.07.14 Trojan-Downloader.Win32.Tiny.brm <br>Kaspersky 7.0.0.125 2008.07.14 Trojan-Downloader.Win32.Obitel.a <br>McAfee 5338 2008.07.14 Generic Downloader.ab <br>Microsoft 1.3704 2008.07.14 Trojan:Win32/Agent.EE <br>NOD32v2 3266 2008.07.14 Win32/TrojanDownloader.Tiny.NDM <br>Norman 5.80.02 2008.07.14 - <br>Panda 9.0.0.4 2008.07.14 Suspicious file <br>Prevx1 V2 2008.07.14 Malware Downloader <br>Rising 20.53.02.00 2008.07.14 - <br>Sophos 4.31.0 2008.07.14 Troj/Agent-HFU <br>Sunbelt 3.1.1536.1 2008.07.12 - <br>Symantec 10 2008.07.14 Trojan Horse <br>TheHacker 6.2.96.379 2008.07.14 - <br>TrendMicro 8.700.0.1004 2008.07.14 PAK_Generic.001 <br>VBA32 3.12.6.9 2008.07.13 - <br>VirusBuster 4.5.11.0 2008.07.14 - <br>Webwasher-Gateway 6.6.2 2008.07.14 Trojan.Dldr.Tiny.brm <br><br>assuming the file i found was the same as yours(which it very well could be)<br><br>either you can compare the md5 with mine<br>MD5...: 6b4ef50e3e21205685cea919ebf93476<br><br>or send me it :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20790603</guid>
<pubDate>Mon, 14 Jul 2008 17:28:33 EDT</pubDate>
</item>

<item>
<title>Re: UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20790373</link>
<description><![CDATA[Kayrac posted : seen a few for another language found by another member on a dif forum, his files downloaded 2 other files, heres what he had to say about it<br><br>"i did not go into detail much, but i can say the following about network behaviour:<br><br>after execution of UPS_Lieferschein.exe, the previously described requests are made.<br>afterwards a data file is being downloaded from<br>hxxp://xxxxxxxx/40E8000800000000000000006C0000015766000000007600000138EB00053051596067<br>and a tcp connection established to xxxxx on port 1375 with encoded/encrypted content received and transmitted.<br>at the same time, the infected host tries to connect to several smtp servers (which i blocked), propably to further spread its malware.<br><br>there is also a http request made to x.x.net on port 3078:<br>GET /?bot_id=0&mode=1<br><br>the response from the webserver (c&c) contains instructions to for example register a hotmail account.<br>well, guess what happens now. right, it tries to register and login at hotmail.<br>i didnt look any deeper at that, just noticed something else:<br><br>POSTs to /r.cgi containing a jpg image, propably a screenshot of my desktop, at the following hosts:"<br><br>i edited out the ip's etc<br><br>if you could send me the files to Kayracc@gmail.com, i'll post it up over there and see if anyone else can take a better look at it<br><br>PS this should be detected by mcafee]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-UPS-packet-upsinvoicezip-WORM-20790373</guid>
<pubDate>Mon, 14 Jul 2008 16:41:35 EDT</pubDate>
</item>

<item>
<title>UPS packet (ups_invoice.zip) WORM</title>
<link>http://www.dslreports.com/forum/UPS-packet-upsinvoicezip-WORM-20789896</link>
<description><![CDATA[premio posted : I'm seeing a lot of these come through the corporate servers, seemingly undetected by McAfee.  <br><br>Any insight?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/UPS-packet-upsinvoicezip-WORM-20789896</guid>
<pubDate>Mon, 14 Jul 2008 15:04:52 EDT</pubDate>
</item>

</channel>
</rss>

