Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 26th, 2012, 10:58 AM
Bob D's Avatar
Bob D Bob D is offline
Frequent Poster
 
Join Date: Apr 2005
Location: Mass., USA
Posts: 966
Default FedEx email scam Trojan is back

I rarely receive spam, and it's been a long long time since I received one with a malware payload. But lately, I'm seeing a spate of these things.
I do get frequent FedEx notifications, but these did not pass the "smell test" (my first line of malware defense).
Attached innocuous appearing zip file contains an exe. Suspect it contains malware as described:
http://www.snopes.com/computer/virus/ups.asp
http://www.kenkai.com/seo-blog-article-309.htm
Quote:
From: "FedEx Service" <postal@fedex.com>
To: mylegitimate email address
Subject: Your package is available for pickup
Date: Sat, 26 May 2012 13:01:37 +0200
Reply-To: "FedEx Service" <postal @ fedex.com>
Sender: <someperson@perseo.hostingplan.net>
X-Mailer: MagicalMailStandardEditionVersion1.0.1REL-1

Notification,

Our company’s courier couldn’t make the delivery of parcel.
Status:Wrong delivery address.

LOCATION OF YOUR ITEM:Boston
DELIVERY STATUS: not delivered
SERVICE: One-day Shipping
NUMBER OF YOUR PARCEL:U667559489NU
FEATURES: No

The label of your parcel is enclosed to the letter.
Print your label and show it in the nearest post office of USPS
You can find the information about the procedure and conditions of parcels keeping in the nearest office.

Thank you for attention.
FedEx Logistics.

[FedEx_Label_ID_Order_83-27-4533US.zip
__________________
noooxml.org
  #2  
Old May 26th, 2012, 11:34 AM
Gullible Jones
 
Posts: n/a
Default Re: FedEx email scam Trojan is back

Hey, I got that one too! That's the one that "broke" VirusTotal.

I wonder what sort of trojan that is.
  #3  
Old May 26th, 2012, 12:28 PM
Bob D's Avatar
Bob D Bob D is offline
Frequent Poster
 
Join Date: Apr 2005
Location: Mass., USA
Posts: 966
Default Re: FedEx email scam Trojan is back

Quote:
Originally Posted by Gullible Jones
Hey, I got that one too!...
Suspect our addresses were harvested by some manner of malware on someone else's box. Perhaps a contact that you / I have in common (looking at you location).
__________________
noooxml.org
  #4  
Old May 26th, 2012, 01:12 PM
Gullible Jones
 
Posts: n/a
Default Re: FedEx email scam Trojan is back

I have some info about the trojan now...

- It is a fake AV, "Smart Fortress 2012."

- It does not appear to install a rootkit, just runs from the application data folder for all users. The program running from the application data folder is apparently identical to the executable in the zip attachment.

- It blocks browsers other than IE from starting. For IE it acts as a local proxy at port 1036. The proxy prevents you from browsing at all until you register Smart Fortress by giving your credit card number to the scammers.

- It does not appear to run at all in Safe Mode.

- Interestingly, IE works fine in safe mode despite the proxy setup, and the IE proxy settings appear unchanged. I guess it's setting up the proxy some other way?

- It reports to an IP apparently located in Beijing. (PM me if you want the IP address.)

- Other blocked applications include Gmer (with any file name), Process Explorer, and Process Monitor. Process Monitor appears to load its driver anyway, but the GUI won't appear. Command prompts are also blocked (well, sort of; it obviously lets them start and then kills them).

- However, nothing is blocked unless the Smart Fortress tray icon is loaded. No icon -> everything runs.

- Also, Online Armor (trial version) can block the scareware from executing on startup. It really does not look terribly advanced.

In conclusion, it looks like a bog-standard fake AV...
  #5  
Old May 26th, 2012, 03:02 PM
Daveski17's Avatar
Daveski17 Daveski17 is offline
Massive Poster
 
Join Date: Nov 2008
Location: Lloegyr
Posts: 5,322
Default Re: FedEx email scam Trojan is back

I've seen something similar, except there was no mention of FedEx. There was a link inviting me to check on the 'package' that had been delivered to the Post Office. I was suspicious for a variety of reasons, notwithstanding the weight of the 'package' wasn't in metric. According to VirusTotal it was a known trojan link.
__________________
Quis custodiet ipsos custodes?
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:27 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums