Saturday November 22, 2008 6:28 AM AEST
Latest Comments
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM

Trojan disguised as UPS delivery note

  • Email a Friend
  • Print Page
By Joy Persaud
Jul 17, 2008 10:19 AM | 1 Comment
Tags: Trojan | UPS | delivery | note
Panda Security is warning email recipients that a series of messages purporting to come from UPS, the world's largest shipping carrier, may in fact harbor the Agent.JEN trojan.

Panda, an anti-virus provider, said the suspicious emails have subject lines such as “UPS packet N3621583925.” The messages claim that it was not possible to deliver a package and advise recipients to print out a copy of an attached invoice.

The “invoice” is a zip file that contains an executable file disguised as a Microsoft Word document – it's typically named “UPS_invoice” or something similar. By running the file, the user unwittingly introduces a copy of the trojan into their computer.

Once downloaded, the code copies itself to the system and replaces the Userinit.exe file in the Windows operating system, which runs Internet Explorer, the system interface and other essential processes.

The trojan then copies the system file to another location (under the name “userini.exe”) and does not interfere with the computer's operation, thereby allaying suspicion.

Dominic Hoskins, a manager with Panda Security said: “Today's malware tactics aim to get financial returns as silently as possible and this particular effort is an obvious manifestation of the current malware dynamics.”

“We had already seen cybercrooks use erotic pictures, Christmas or romantic cards, fake movie trailers and so on as baits to make users run infected files,” he added. “However, it is not usual to see bait like this one.”

Agent.JEN connects to a Russian domain that is already used by other banker trojans and uses it to send a request to a German domain to download a rootkit and adware detected by PandaLabs as Rootkit/Agent.JEP and Adware/AntivirusXP2008 respectively. These increase the risk of further infection.

See original article on SC Magazine US

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 1
I have been the recipient of Agent.JEN.Trojan through an email suggesting a UPS parcel (including tracking nr.)was undeliverable. Checking with UPS, the tracking nr was invalid. I deleted the zip file without opening it. Cheers Vincent Laing
SC Magazine - comments icon Posted by Vincent LaingNov 13, 2008 4:01 PM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers