TrojanDownloader.Kuluoz.B distributed via image based email

Another United Parcel Service (UPS) spam has been discovered and this involves emails regarding failed package deliveries due to a faulty recipient address.

The emails carry different subjects like:

  • Your parcel is not delivered
  • Error in the delivery address ID#7277
  • Failure to deliver ID #92198
  • Print your postal label
  • UPS delivery refuse ID #4714
  • You should come to the post office
  • Your delivery status has changed

The email is sent from a spoofed UPS address and has the following body:

Behind the image is a URL – hxxp:// This downloads a file named and contains a 109 kB executable file called Label_Copy_UPS.exe.

Upon execution, it downloads and installs a rogueware called Live Secutiy Platinum.

Quick Heal successfully detects and deletes the attached file along with the installed rogueware from your machine.

Anand Yadav

Anand Yadav


Your email address will not be published.


  1. Avatar Onil S SonawaniAugust 28, 2012 at 1:14 PM

    I downloaded and then VP repaired Label_Copy_UPS.exe as TrojanDownloader.Kuluoz.B

    But if it is proved that mentioned url downloads malicious file then Quick Heal Browsing Protection should detect url as a first line of defence But it is not detecting that !.

    • Rahul Thadani Rahul ThadaniAugust 29, 2012 at 11:07 AM

      Hi Onil,
      Browsing Protection blocks access to infected websites. In this case the malware enters the system only when an executable file is downloaded. That is when it is detected by Quick Heal.

  2. Thanks rahul for the update.

  3. Thanks for given information..

  4. thanks for information, I am receiving around 10-12 E-mails daily
    like this claiming that you have won lottery or UPS Parcel or Paypal A/d
    or RBI important mail how should I stop them they orignate from different

    • Rahul Thadani Rahul ThadaniSeptember 3, 2012 at 11:20 AM

      Hi Palak,
      Firstly, you can report the emails as spam to the service provider that you are receiving these emails on. As a precaution you should delete these emails right after that and you must never reply to them.

  5. Avatar Onil S SonawaniSeptember 3, 2012 at 3:47 PM

    Hi Rahul,

    Quick Heal Has Got Detection Now.

    Harmful website accessed.
    Detected: Blk/Domain.237995
    Website accessed:
    Action Taken: Blocked