<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: UPS_Invoice.exe trojan received by email</title>
	<atom:link href="http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/</link>
	<description>the unofficial voice of Meteor IT</description>
	<lastBuildDate>Mon, 06 Feb 2012 13:06:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: drvanski</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3384</link>
		<dc:creator><![CDATA[drvanski]]></dc:creator>
		<pubDate>Thu, 04 Mar 2010 12:26:52 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3384</guid>
		<description><![CDATA[Thanks for blogging this virus.  Received my &#039;UPS Invoice&#039; today and deleted it.]]></description>
		<content:encoded><![CDATA[<p>Thanks for blogging this virus.  Received my &#8216;UPS Invoice&#8217; today and deleted it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sachin Naik</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3369</link>
		<dc:creator><![CDATA[Sachin Naik]]></dc:creator>
		<pubDate>Sun, 24 Jan 2010 15:44:05 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3369</guid>
		<description><![CDATA[well now is 2010 and this webpage is 1 year old
I received 4 such emails this year

first was from &quot;tracking.support@ups.com&quot;
second and third were from &quot;service@ups.com&quot;
fourth from &quot;shipping@dhl.com&quot;

subjects were same for the first 3 mails i.e. UPS Manager (with some varying names)
but for the fourth one it was, DHL Manager (with a name)

and the mail body contained the following for all 4 mails

Hello! 

The courier company was not able to deliver your parcel by your address.
Cause: Error in shipping address. 

You may pickup the parcel at our post office personaly!

Please attention!
The shipping label is attached to this e-mail. 
Please print this label to get this package at our post office.


Please do not reply to this e-mail, it is an unmonitored mailbox.



Thank you.
United Parcel Service.






happy to see my AVG Free has detected the threat in the email itself with the following certification


Viruses found in the attached files.
The file UPS_invoice _Nr34678.zip: Virus found FakeAlert. The attachment was moved to the Virus Vault.

but i wonder why avg did not detect the first 2 emails, why it detected only the third and fourth email, when all 4 emails were same 
and one more thing i updated my avg after i received the first 2 mails, so is it because of the update it detected the 3rd and the 4th mail, but the virus is 1 year old]]></description>
		<content:encoded><![CDATA[<p>well now is 2010 and this webpage is 1 year old<br />
I received 4 such emails this year</p>
<p>first was from &#8220;tracking.support@ups.com&#8221;<br />
second and third were from &#8220;service@ups.com&#8221;<br />
fourth from &#8220;shipping@dhl.com&#8221;</p>
<p>subjects were same for the first 3 mails i.e. UPS Manager (with some varying names)<br />
but for the fourth one it was, DHL Manager (with a name)</p>
<p>and the mail body contained the following for all 4 mails</p>
<p>Hello! </p>
<p>The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address. </p>
<p>You may pickup the parcel at our post office personaly!</p>
<p>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Please print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox.</p>
<p>Thank you.<br />
United Parcel Service.</p>
<p>happy to see my AVG Free has detected the threat in the email itself with the following certification</p>
<p>Viruses found in the attached files.<br />
The file UPS_invoice _Nr34678.zip: Virus found FakeAlert. The attachment was moved to the Virus Vault.</p>
<p>but i wonder why avg did not detect the first 2 emails, why it detected only the third and fourth email, when all 4 emails were same<br />
and one more thing i updated my avg after i received the first 2 mails, so is it because of the update it detected the 3rd and the 4th mail, but the virus is 1 year old</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: welonaranee</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3317</link>
		<dc:creator><![CDATA[welonaranee]]></dc:creator>
		<pubDate>Tue, 07 Jul 2009 09:39:54 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3317</guid>
		<description><![CDATA[I find a lot of badly infected systems &quot;protected&quot; by McAfee these days.  I just don&#039;t think they are as good as they once were.  Same thing happened with Norton, although I have read they are doing better of late.  After doing a lot of testing, the only one I am happy with these days is Bit Defender, but who knows which one will be the &quot;good&quot; one in a few months.  I was using Kapersky, but they are now my second choice after BD.]]></description>
		<content:encoded><![CDATA[<p>I find a lot of badly infected systems &#8220;protected&#8221; by McAfee these days.  I just don&#8217;t think they are as good as they once were.  Same thing happened with Norton, although I have read they are doing better of late.  After doing a lot of testing, the only one I am happy with these days is Bit Defender, but who knows which one will be the &#8220;good&#8221; one in a few months.  I was using Kapersky, but they are now my second choice after BD.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim watson</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3287</link>
		<dc:creator><![CDATA[Jim watson]]></dc:creator>
		<pubDate>Thu, 11 Sep 2008 17:49:04 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3287</guid>
		<description><![CDATA[I just got one of these today , but spamfilter had filtered it out.]]></description>
		<content:encoded><![CDATA[<p>I just got one of these today , but spamfilter had filtered it out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam Vero</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3260</link>
		<dc:creator><![CDATA[Adam Vero]]></dc:creator>
		<pubDate>Mon, 28 Jul 2008 21:50:11 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3260</guid>
		<description><![CDATA[Claire
Glad my humble blog could be of some help.
I&#039;ve also had a version masqerading as some bogus e-tickets, mine claimed to be from Midwest Airlines with whom I have never travelled. Text was as follows:
&lt;blockquote&gt;Hello, Thank you for using our new service &quot;Buy flight ticket Online&quot; on our website.
Your account has been created:
Your login: Info
Your password: passSJZK
Your credit card has been charged for $438.88.
We would like to remind you that whenever you order tickets on our website you get a discount of 10%! Attached to this message is the purchase Invoice and the airplane ticket.
To use your ticket, simply print it on a color printed, and you are set to take off for the journey!

Kind regards,
Harris Rosas
Midwest Airlines&lt;/blockquote&gt;
As with the &lt;a href=&quot;http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/&quot; rel=&quot;nofollow&quot;&gt;Customs Tax Bill variant&lt;/a&gt;, the similarity of the wording was a bit of a red flag, but the approach here is slightly different. By telling people some money has been charged to their credit card it makes people worry they have been a victim of identity theft, or at the very least their card details have been stolen and used. This is more likely to trigger them to see what is in the invoice, hoping to identify who has done this.
The executable in the attached E-ticket_N7399294.zip seems to be another ZBot variant (or whatever name is popular for it this week).

In theory many of the main antivirus vendors do host such information - Network Associates Inc has a Virus Information Library at vil.nai.com, but that was a few days behind, along with everyone else, it seems. I would always suggest checking the site of the company you use for your antivirus software, whether online or installed software, free or paid for. That way you get an idea not just what the threat is, but whether your chosen solution is protecting you yet.]]></description>
		<content:encoded><![CDATA[<p>Claire<br />
Glad my humble blog could be of some help.<br />
I&#8217;ve also had a version masqerading as some bogus e-tickets, mine claimed to be from Midwest Airlines with whom I have never travelled. Text was as follows:</p>
<blockquote><p>Hello, Thank you for using our new service &#8220;Buy flight ticket Online&#8221; on our website.<br />
Your account has been created:<br />
Your login: Info<br />
Your password: passSJZK<br />
Your credit card has been charged for $438.88.<br />
We would like to remind you that whenever you order tickets on our website you get a discount of 10%! Attached to this message is the purchase Invoice and the airplane ticket.<br />
To use your ticket, simply print it on a color printed, and you are set to take off for the journey!</p>
<p>Kind regards,<br />
Harris Rosas<br />
Midwest Airlines</p></blockquote>
<p>As with the <a href="http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/" rel="nofollow">Customs Tax Bill variant</a>, the similarity of the wording was a bit of a red flag, but the approach here is slightly different. By telling people some money has been charged to their credit card it makes people worry they have been a victim of identity theft, or at the very least their card details have been stolen and used. This is more likely to trigger them to see what is in the invoice, hoping to identify who has done this.<br />
The executable in the attached E-ticket_N7399294.zip seems to be another ZBot variant (or whatever name is popular for it this week).</p>
<p>In theory many of the main antivirus vendors do host such information &#8211; Network Associates Inc has a Virus Information Library at vil.nai.com, but that was a few days behind, along with everyone else, it seems. I would always suggest checking the site of the company you use for your antivirus software, whether online or installed software, free or paid for. That way you get an idea not just what the threat is, but whether your chosen solution is protecting you yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claire Vian</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3257</link>
		<dc:creator><![CDATA[Claire Vian]]></dc:creator>
		<pubDate>Sun, 27 Jul 2008 08:28:43 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3257</guid>
		<description><![CDATA[Thanks for your reassuring reply last week, Adam.  As far as I know my computer is not infected and for several days following first message (on 14th July) I did not receive any more of the UPS fake emails.

However in the last 5 days I have received several (up to 6) each day - some as before; from &quot;UPS&quot; and others from Customs, and just in the last two days pretending to be from Continental Airlines re e-tickets (no I had not ordered any tickets).  They all have attachments, but I have just deleted them without even reading the message.

Interestingly there still seems to be very little info on the web generally about this problem.

Is there anywhere, other than this site, where this information could be available to everyone?]]></description>
		<content:encoded><![CDATA[<p>Thanks for your reassuring reply last week, Adam.  As far as I know my computer is not infected and for several days following first message (on 14th July) I did not receive any more of the UPS fake emails.</p>
<p>However in the last 5 days I have received several (up to 6) each day &#8211; some as before; from &#8220;UPS&#8221; and others from Customs, and just in the last two days pretending to be from Continental Airlines re e-tickets (no I had not ordered any tickets).  They all have attachments, but I have just deleted them without even reading the message.</p>
<p>Interestingly there still seems to be very little info on the web generally about this problem.</p>
<p>Is there anywhere, other than this site, where this information could be available to everyone?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Riddhi</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3251</link>
		<dc:creator><![CDATA[Riddhi]]></dc:creator>
		<pubDate>Sat, 26 Jul 2008 08:04:39 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3251</guid>
		<description><![CDATA[Hello guys,

This UPS email is really on wild for last couple of days. the UPS_Invoice attachment install couple trozans and downloaded on your system and then the downloaded downloads more trozans. the first thing happens when you click on the attachment is it install a rootkit into kernel and hide itself from WIndows API and it disables your antivirus as soon as it is executed.

I work for SYmantec and so far there is 400 variants for this threat.

as it disabled the antivirus at the fist go it then downloads some known and unknown trozans which willnot be detected as the antivirus is non-functional already.]]></description>
		<content:encoded><![CDATA[<p>Hello guys,</p>
<p>This UPS email is really on wild for last couple of days. the UPS_Invoice attachment install couple trozans and downloaded on your system and then the downloaded downloads more trozans. the first thing happens when you click on the attachment is it install a rootkit into kernel and hide itself from WIndows API and it disables your antivirus as soon as it is executed.</p>
<p>I work for SYmantec and so far there is 400 variants for this threat.</p>
<p>as it disabled the antivirus at the fist go it then downloads some known and unknown trozans which willnot be detected as the antivirus is non-functional already.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zeke</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3233</link>
		<dc:creator><![CDATA[zeke]]></dc:creator>
		<pubDate>Thu, 24 Jul 2008 17:55:03 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3233</guid>
		<description><![CDATA[I opened the UPS email in gmail and downloaded the attachment to my computer but never unzipped it and promptly deleted it. Is there any chance my computer could be infected. I&#039;m on Windows XP.]]></description>
		<content:encoded><![CDATA[<p>I opened the UPS email in gmail and downloaded the attachment to my computer but never unzipped it and promptly deleted it. Is there any chance my computer could be infected. I&#8217;m on Windows XP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: UPS_Invoice email trojan variant claims to be from Customs Service &#171; Adam Vero at Getting IT Right</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3228</link>
		<dc:creator><![CDATA[UPS_Invoice email trojan variant claims to be from Customs Service &#171; Adam Vero at Getting IT Right]]></dc:creator>
		<pubDate>Thu, 24 Jul 2008 14:38:11 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3228</guid>
		<description><![CDATA[[...]In the last hour I found in my inbox a variation on the UPS_Invoice trojans of last week. This &lt;a href=&quot;http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/&quot; rel=&quot;nofollow&quot;&gt;new email claimed to be from “Customs Service”&lt;/a&gt; with the subject “Customs - We have received a parcel for you”[...]]]></description>
		<content:encoded><![CDATA[<p>[...]In the last hour I found in my inbox a variation on the UPS_Invoice trojans of last week. This <a href="http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/" rel="nofollow">new email claimed to be from “Customs Service”</a> with the subject “Customs &#8211; We have received a parcel for you”[...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dmitri</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3226</link>
		<dc:creator><![CDATA[Dmitri]]></dc:creator>
		<pubDate>Wed, 23 Jul 2008 19:58:36 +0000</pubDate>
		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comment-3226</guid>
		<description><![CDATA[Here is the link on how to remove that threat
http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=TSPY%5FZBOT%2EPF]]></description>
		<content:encoded><![CDATA[<p>Here is the link on how to remove that threat<br />
<a href="http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=TSPY%5FZBOT%2EPF" rel="nofollow">http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=TSPY%5FZBOT%2EPF</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

