UPS Delivery Scam

Out of the blue I received the famous UPS delivery emails.

Dear customer.
The parcel was sent your home address.
And it will arrive within 7 business day.
More information and the tracking number are attached in document below.
Thank you.
© 1994-2011 United Parcel Service of America, Inc.

Attached was a rar file pertaining to be the delivery information.
Knowing of the scam and also that I had not ordered anything I saved the rar file into a virtual machine and took a peek with notepad. Pretty much all of it was random ASCII except for the legible text "United Parcel Service document.exe".

Knowing this was a virus I submitted it to an online virus scanner to verify the content. The abrieviated version of the output is outlined as follows.

W32/Agent.OUH!tr

It displays the following fake warning message:
Danger!
Harmful viruses detected on your computer...

It deletes the following various registry keys
It creates the following new registry entries
It tries to download files from the specific URLs
It tries to access the specific URLs
It deletes itself from the current folder

Needless to say I deleted the file.

Comments

Popular posts from this blog

configuring the zmodo ZP-IBi-13W camera to work with Blue Iris Software.

Apple MAC Fake Virus Alert

Evolution