You do not want this package

This month has seen a new twist on an old scam.  There have been mass Spam mailings with fake invoices.  One version purports to inform you that you have a package, from one of the very pick next-day-delivery companies, that could not be delivered and was returned.  There is a zip file attached, you are asked to download it, print it out and then collect your parcel from your local office.

When you download and unzip the file, the malware is copied onto the system, replacing a Windows file that manages explorer, the user interface and some other important processes. Additionally, it establishes a connection with a domain, which has been used on some occasions by banker Trojans. From this domain it will redirect the request to another domain in order to download a rootkit and a rogue antivirus.

So, you get a ‘package’ but not one you want nor expect!

comments

Leave a Reply