Search

Categories

Main menu:

Tags

UPS Delivery Problem Spam with Malware Payload Floods In-Boxes Again

This one is not new, but it is still a nasty one. Since yesterday, I have received 8 of these types of messages, all caught by my virus scanner and rendered harmless.

I decided to do a little digging this time around and find out just a little bit more about these messages.

The nasty payload that accompanies these messages is contained in an attached image file with various names that are probably randomly generated. For example, the messages I received had infected JPEG images with the following filenames: 2664423.jpg, 5617431.jpg, 2478363.jpg, 4599357.jpg, 6464145.jpg, 6178909.jpg, 9222752.jpg and 2535916.jpg. If opened, the images look like this:

ups-delivery-problem

In addition to displaying the above image, the modified JPEG file will attempt to infect your PC with malware known as “FakeAlert.” At least that is the way my anti-virus application identified it. FakeAlert infects your PC and pops up messages on the user’s screen claiming that the PC is infected with a virus. Kind of ironic, huh? The messages lead victims to believe that they need to register an anti-virus program in order to rid their PC of the infection. As one might suspect, registering the alleged anti-virus program is not free, and the scumbag that sent the message most likely gets a cut of the profits.

The messages I received were sent by a number of mail servers which were probably compromised (“hacked”) by the senders of these messages. The servers that sent the spam messages to me were all located in the U.S., which is a little unusual when compared with most of the other spam I get, but the spammers have evidently found fertile ground on some systems here in the U.S. to spew out their crap from. They can always count on the fact that some system administrator has not properly secured their system or some new bug will come along that will allow them to exploit systems that they are not authorized to use.

This batch is also a bit different since the messages do not have the same bogus claims about a package that was intended for the recipient but was unable to be delivered. This time, it appears the messages are just a sentence or two that was probably scraped from a news site. Really does not make sense to get a message that is supposedly from UPS and contains random news headlines, but this may be a tactic that makes this spam appear more legitimate and have a better chance of bypassing spam filters.

Here are the ones that I received:

From:    UPS Support, Misty Lelacheur [aerichter@ups.com]
Sent:    Tuesday, June 22, 2010 5:33 PM
Subject:    Delivery Problem NR4419092.
Attachments:    2664423.jpg

Analyst: Higher 2Q home orders for Lennar, KB Home The Most Awesome
Rubik’s Cube Creations Of All Time (HuffingtonPost.com) Red Hat 1Q
profit rises with revenue growth Excerpts from Times Square bomb plot
plea hearing

From:    UPS Manager, Doug Eggleton [philalan@ups.com]
Sent:    Tuesday, June 22, 2010 2:46 PM
Subject:    UPS INVOICE NR0549136.
Attachments:    5617431.jpg

Video: The Great Explorer, Part 2 Worker runs over people at Japanese
plant, 1 dead New Tools Find Cheap Private Student Loans Ariz.
wildfire near Flagstaff now at 10,000 acres

From:    United Parcel Service of America, Deane Schornick [maxxaz@ups.com]
Sent:    Tuesday, June 22, 2010 1:44 PM
Subject:    Delivery Problem NR9707335.
Attachments:    2478363.jpg

Existing home sales weak but supply falls Video: "Female Viagra"
Strikes Out $75M mansion near Orlando selling ‘as is’ UK slashes
spending, raises VAT and taxes banks

From:    UPS PostBox-Manager, Martin Kauffman [fashionseal@ups.com]
Sent:    Tuesday, June 22, 2010 11:21 AM
Subject:    Delivery Problem NR1200176.
Attachments:    4599357.jpg

AP source: White House budget chief stepping down Salazar creates new
agency to oversee drilling Worker runs over people at Japanese plant,
1 dead New killings in campaign against Iraqi ex-insurgents

From:    United Parcel Service of America, Magdalena Scanlon [octf@ups.com]
Sent:    Tuesday, June 22, 2010 8:36 AM
Subject:    UPS INVOICE NR3813549.
Attachments:    6464145.jpg

Election Problems Blog Dr. Phil Highlights CBS Investigation Obama
Budget Chief Peter Orszag Resigning Tony Hayward at Yacht Race Angers
La. Officials

From:    UPS PostBox-Manager, Valarie Reinholtz [billcoons@ups.com]
Sent:    Tuesday, June 22, 2010 5:58 AM
Subject:    Delivery Problem NR2399379.
Attachments:    6178908.jpg

Remade in NY: French ex-1st lady has new life NM father, 2 sons die
in apparent murder-suicide 2nd mistrial declared in McConaughey surf
battle "Little House" Star Alison Arngrim "Abused"

From:    UPS Support, Quincy Cockshot [bawidmaier@ups.com]
Sent:    Monday, June 21, 2010 3:38 PM
Subject:    Delivery Problem NR5866911.
Attachments:    9222752.jpg

Emanuel Casts Barton Apology as GOP Philosophy "Shmutz" Report: NYC
Subways Getting Dirtier Mortgage applications rise nearly 18 percent
Mass. state trooper killed by vehicle during stop

From:    United Parcel Service of America, Carlene Carridine [mothena@ups.com]
Sent:    Monday, June 21, 2010 2:34 PM
Subject:    UPS INVOICE NR4475927.
Attachments:    2635916.jpg

Stocks extend gains as China eases currency policy Gulf of Mexico oil
spill costs BP $2 billion Medical pot can cost parents in custody
disputes Lorenzo coasts to British MotoGP win