Results 1 to 14 of 14

Thread: has anyone been targeted by the UPS trojen email?

  1. #1
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    has anyone been targeted by the UPS trojen email?

    Around the 18th of this month some moron decided to start sending an email pretending to be from the UPS delivery company. It stated that a parcel could not be delivered and you needed to open the attachment, print out the page and send it back to UPS to claim your parcel back. The .zip contained a .exe file that opened a back door for a lot of nasty things.

    Has anyone here had to deal with this yet?
    □ΞVΞ□

  2. #2
    Does he need a reason? Funkstar's Avatar
    Join Date
    Aug 2005
    Location
    Aberdeen
    Posts
    19,874
    Thanks
    629
    Thanked
    962 times in 813 posts
    • Funkstar's system
      • Motherboard:
      • Gigabyte EG45M-DS2H
      • CPU:
      • Intel Core2Quad Q9550 (2.83GHz)
      • Memory:
      • 8GB OCZ PC2-6400C5 800MHz Quad Channel
      • Storage:
      • 650GB Western Digital Caviar Blue
      • Graphics card(s):
      • 512MB ATI Radeon HD4550
      • PSU:
      • Antec 350W 80+ Efficient PSU
      • Case:
      • Antec NSK1480 Slim Mini Desktop Case
      • Operating System:
      • Vista Ultimate 64bit
      • Monitor(s):
      • Dell 2407 + 2408 monitors
      • Internet:
      • Zen 8mb

    Re: has anyone been targeted by the UPS trojen email?

    Not seen it and not heard of it from work either.

  3. #3
    Senior Member
    Join Date
    Sep 2004
    Location
    The JimNasium
    Posts
    657
    Thanks
    13
    Thanked
    5 times in 4 posts
    • JimNastics's system
      • Motherboard:
      • Asus P5K Deluxe
      • CPU:
      • Q6600
      • Memory:
      • 4gb
      • Storage:
      • About 750gb me thinks...
      • Graphics card(s):
      • EVGA ACS3 8800GTS
      • PSU:
      • Corsair HX 520w
      • Case:
      • Antec P182
      • Monitor(s):
      • Dell 2005FPW
      • Internet:
      • IDNet 8mb

    Re: has anyone been targeted by the UPS trojen email?

    Yep I had it sent to me, but Avast detected it through Mailwasher whilst it was still on my mail server, so it didn't even get to my machine

  4. #4
    Senior Member Betty_Swallocks's Avatar
    Join Date
    Jan 2005
    Location
    Feet up, spliff lit.
    Posts
    1,140
    Thanks
    70
    Thanked
    60 times in 44 posts
    • Betty_Swallocks's system
      • Motherboard:
      • Asus Z97-A
      • CPU:
      • Intel Core i5 4690K o/c to 4.6 gHz
      • Memory:
      • 8Gb DDR3
      • Storage:
      • 256Gb SSD + 1320Gb (3x SATA drives)
      • Graphics card(s):
      • MSI R9 390 8Gb
      • PSU:
      • Corsair CS750M
      • Case:
      • Thermaltake Shark
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 37" Samsung TV @1920x1080 + Dell 20.1" TFT secondary screen
      • Internet:
      • 150Mb Virgin Media cable

    Re: has anyone been targeted by the UPS trojen email?

    It'll be clever if they can develop one that will sidle up your garden path and slip a card through the door without alerting the dog like Citilink do.
    "Free speech includes not only the inoffensive but the irritating, the contentious, the eccentric, the heretical, the unwelcome and the provocative provided it does not tend to provoke violence. Freedom only to speak inoffensively is not worth having."

  5. #5
    radix lecti dave87's Avatar
    Join Date
    Sep 2005
    Location
    England
    Posts
    12,806
    Thanks
    657
    Thanked
    931 times in 634 posts
    • dave87's system
      • Motherboard:
      • Asus
      • CPU:
      • i5 3470k under Corsair H80 WC
      • Memory:
      • 8gb DDR3
      • Storage:
      • 240gb SSD + 120gb SSD
      • Graphics card(s):
      • Asus HD7950
      • PSU:
      • XFX 600w Modular
      • Case:
      • Lian Li PC-A05FNB + Acoustipack
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2x Dell S2309W (1920x1080)
      • Internet:
      • BT Infinity Option 2

    Re: has anyone been targeted by the UPS trojen email?

    The Uni had a few people fall for this, but nothing major as far as I know.

    Still, if you aren't expecting a parcel from UPS, why would you open it?

  6. #6
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: has anyone been targeted by the UPS trojen email?

    Quote Originally Posted by dave87 View Post
    The Uni had a few people fall for this, but nothing major as far as I know.

    Still, if you aren't expecting a parcel from UPS, why would you open it?
    People do - out of curiosity (who doesn't like to receive a surprise parcel?)

    Had a couple of instances of it at home - one a couple of weeks ago not detected by Avast (but it was by me!) and another a few days ago which Avast did detect.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  7. #7
    Lovely chap dangel's Avatar
    Join Date
    Aug 2005
    Location
    Cambridge, UK
    Posts
    8,398
    Thanks
    412
    Thanked
    459 times in 334 posts
    • dangel's system
      • Motherboard:
      • See My Sig
      • CPU:
      • See My Sig
      • Memory:
      • See My Sig
      • Storage:
      • See My Sig
      • Graphics card(s):
      • See My Sig
      • PSU:
      • See My Sig
      • Case:
      • See My Sig
      • Operating System:
      • Windows 10
      • Monitor(s):
      • See My Sig
      • Internet:
      • 60mbit Sky LLU

    Re: has anyone been targeted by the UPS trojen email?

    Yes, our company was hit.
    Crosshair VIII Hero (WIFI), 3900x, 32GB DDR4, Many SSDs, EVGA FTW3 3090, Ethoo 719


  8. #8
    Senior Member
    Join Date
    May 2006
    Posts
    578
    Thanks
    36
    Thanked
    24 times in 19 posts

    Re: has anyone been targeted by the UPS trojen email?

    Got this too but the email address was very suss. Something like upsparcel@dfdfhgldfhgkdfhxgodfjlgjvl...jcpbjpcbjp.com so decided it wasnt UPS

  9. #9
    Real Ultimate Power! Grey M@a's Avatar
    Join Date
    Oct 2003
    Location
    Newcastle
    Posts
    4,625
    Thanks
    52
    Thanked
    156 times in 139 posts
    • Grey M@a's system
      • Motherboard:
      • Gigabyte Z97X Gaming 7
      • CPU:
      • i7 4790K (With H100i cooling)
      • Memory:
      • Corsair Vengeance Pro 16GB DDR3 (2 x 8GB)
      • Storage:
      • Samsung 840 Pro 128GB SSD, 1TB Cavier Black WD HD, 4TB Cavier Black WD HD
      • Graphics card(s):
      • MSI R9 390X Gaming Edition 8GB
      • PSU:
      • SuperFlower Leadex GOLD 850W Fully Modular
      • Case:
      • Corsair 650D
      • Operating System:
      • Windows 8.1 Pro x64
      • Monitor(s):
      • 24" LG 24GM77-B 144Hz
      • Internet:
      • 100MB Virgin Media Cable

    Re: has anyone been targeted by the UPS trojen email?

    I have been spammed with this for a number of weeks saying they can't deliver the package etc and in the email there is the .zip and the .exe attached to it. Luckily though NOD32 catches it before it hits the inbox and sticks it in quarantine

  10. #10
    Senior Member
    Join Date
    Aug 2003
    Location
    bracknell
    Posts
    665
    Thanks
    33
    Thanked
    12 times in 10 posts
    • Elspuddy's system
      • Motherboard:
      • GIGABYTE GA-970A-DS3 AMD 970A
      • CPU:
      • AMD Phenom II X6 1075T 3.0GHz
      • Memory:
      • 14 gig
      • Storage:
      • Samsung 870 (128)ssd 2x1.5 tb, 2 of Seagate Barracuda 3.5 inch 2TB 7200 RPM 64MB (raid 0)
      • Graphics card(s):
      • EVGAC GeForce GTX 970 superclocked
      • PSU:
      • CORSAIR CX 750 WATT MODULAR PSU
      • Case:
      • NZXT phantom
      • Operating System:
      • windows 8.1
      • Monitor(s):
      • LG 32" tv , LG 22" montor
      • Internet:
      • 155 meg virgin cable

    Re: has anyone been targeted by the UPS trojen email?

    read about this on another forum, but i did get one, good thing my e-mail is on my mac

  11. #11
    Registered+
    Join Date
    Jul 2008
    Posts
    20
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: has anyone been targeted by the UPS trojen email?

    i do not think i have got one i will have to check my avg now.

  12. #12
    Senior Member
    Join Date
    May 2007
    Location
    West Wales
    Posts
    484
    Thanks
    30
    Thanked
    18 times in 16 posts
    • Phil_P's system
      • Motherboard:
      • Gigabyte P35-DS4
      • CPU:
      • Q6600 G0
      • Memory:
      • 4x1GB Crucial
      • Storage:
      • 2 x WD 1TB in RAID1
      • Graphics card(s):
      • Gigabyte 7600GS
      • PSU:
      • Etasis 750W
      • Operating System:
      • RHEL5/RHEL6
      • Monitor(s):
      • Samsung 226BW 22" panel
      • Internet:
      • F2S 8mbit

    Re: has anyone been targeted by the UPS trojen email?

    I've seen quite a few of these on my mail server. So far they've all been .exe's packaged as .zip's. I just quarantine all .zip attachments (along with .exe, .com, .pif etc) on the server so that kinda solves that problem

    I wouldn't rely on AV to catch these - at the time they arrive AV detection is usually pretty poor. Each sample
    quarantined on my server has been unique and all with varying levels of AV detection. Not much point your AV detecting them 24 hours after they've arrived.

  13. #13
    omg haxor listy's Avatar
    Join Date
    May 2006
    Location
    Scotland
    Posts
    1,042
    Thanks
    25
    Thanked
    39 times in 35 posts
    • listy's system
      • Motherboard:
      • gigabyte one :P
      • CPU:
      • 939 FX60
      • Memory:
      • 2gig DDR 400mhz ram
      • Storage:
      • 500ish gig
      • Graphics card(s):
      • 4870x2
      • PSU:
      • 700watt jeantech storm
      • Operating System:
      • XP Pro sp2
      • Monitor(s):
      • 19" crt random
      • Internet:
      • 8meg bt

    Re: has anyone been targeted by the UPS trojen email?

    getting about 5 coming in a day but mailwasher is flaging them as spam anyway

  14. #14
    Registered+
    Join Date
    Jul 2008
    Posts
    35
    Thanks
    0
    Thanked
    4 times in 3 posts

    Re: has anyone been targeted by the UPS trojen email?

    we have had a lot of these. they still seem to be getting through mcafee groupshield email scanning.

    lot's of users are opening and they can be a real pain to remove.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Stupid forum email restrictions?
    By stroberaver in forum Software
    Replies: 8
    Last Post: 24-03-2008, 03:16 PM
  2. What a nice automated email I just received!
    By kidzer in forum SCAN.care@HEXUS
    Replies: 1
    Last Post: 12-12-2007, 12:35 PM
  3. BELKIN Superior Series 500VA UPS USB & Serial Interface £19.99 + del
    By venkata in forum Retail Therapy and Bargains
    Replies: 38
    Last Post: 28-02-2006, 03:57 PM
  4. Replies: 0
    Last Post: 14-09-2005, 05:48 PM
  5. Scam email?
    By SarG in forum General Discussion
    Replies: 9
    Last Post: 26-10-2003, 09:29 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •