TrojanDownloader.Kuluoz.B distributed via image based email

Another United Parcel Service (UPS) spam has been discovered and this involves emails regarding failed package deliveries due to a faulty recipient address.

The emails carry different subjects like:

  • Your parcel is not delivered
  • Error in the delivery address ID#7277
  • Failure to deliver ID #92198
  • Print your postal label
  • UPS delivery refuse ID #4714
  • You should come to the post office
  • Your delivery status has changed

The email is sent from a spoofed UPS address statements@us-ups.com.prediger.de and has the following body:

Behind the image is a URL – hxxp://www.wis-freiberg.de/JLBYAWZHRN.htm. This downloads a file named Label_Copy_UPS.zip and contains a 109 kB executable file called Label_Copy_UPS.exe.

Upon execution, it downloads and installs a rogueware called Live Secutiy Platinum.

Quick Heal successfully detects and deletes the attached file along with the installed rogueware from your machine.

Anand Yadav

Anand Yadav

Follow @

Subscribe
Notify of
guest
7 Comments
Inline Feedbacks
View all comments
Onil S Sonawani
Onil S Sonawani
8 years ago

I downloaded Label_Copy_UPS.zip and then VP repaired Label_Copy_UPS.exe as TrojanDownloader.Kuluoz.B

But if it is proved that mentioned url downloads malicious file then Quick Heal Browsing Protection should detect url as a first line of defence But it is not detecting that !.

Rahul Thadani
8 years ago

Hi Onil,
Browsing Protection blocks access to infected websites. In this case the malware enters the system only when an executable file is downloaded. That is when it is detected by Quick Heal.

Sameer
Sameer
8 years ago

Thanks rahul for the update.

Dineshs
Dineshs
8 years ago

Thanks for given information..

Palak Shah
Palak Shah
8 years ago

thanks for information, I am receiving around 10-12 E-mails daily
like this claiming that you have won lottery or UPS Parcel or Paypal A/d
or RBI important mail how should I stop them they orignate from different
places

Rahul Thadani
8 years ago
Reply to  Palak Shah

Hi Palak,
Firstly, you can report the emails as spam to the service provider that you are receiving these emails on. As a precaution you should delete these emails right after that and you must never reply to them.
Thanks.

Onil S Sonawani
Onil S Sonawani
8 years ago

Hi Rahul,

Quick Heal Has Got Detection Now.

Harmful website accessed.
Detected: Blk/Domain.237995
Website accessed: http://www.wis-freiberg.de/label_copy_ups.zip
Action Taken: Blocked

7
0
Would love your thoughts, please comment.x
()
x