Bredolab.X trojan hidden in tracking details from an internet store

MX Lab intercepted several messages with a new trojan variant attached in a ZIP archive. The email messages are from an alleged internet shop where an order has been placed. The tracking number of the postal parcel has been attached according to the sender.

In fact, the ZIP archive contains an executable that is identified as TrojanDownloader:Win32/Bredolab.X (Microsoft), W32/Bredolab!Generic (F-Prot), Trj/CI.A (Panda) or Mal/Bredo-A (Sophos).

Subjects could be (the numbers in the subject are random):

Thank you for settling the order No.90322972
Shipping confirmation for order _24204

The from address is spoofed and the body of the email is similar to:

Goodafternoon!

Thank you for shopping at our internet store!
We have successfully received your payment.

Your order has been shipped to your billing address.
You have ordered Toshiba Satellite U400D.

You can find your tracking number in attached to the e-mail document.
Please print the label to get your package.

We hope you enjoy your order!
Momsview.com

Another body example:

Dear Customer!

Thank you for placing your order at our internet store.
Your order: Samsung R610, was sent at your address.
The tracking number of your postal parcel is indicated in the document attached to this letter.
Please, print out the postal label for receiving the parcel.

Online store.
Cart.undftd.com

The extracted ZIP archive contains an D*****.exe, of approx 36 kB, where * stands for random numbers and letters. Bredolab.X is a trojan horse that downloads and executes a file from the Internet.

Virus Total permlink and MD5: 74d95402682f7e11513433193e1a2684.

New DHL trojan variant in the wild

MX Lab has intercepted messages with the subject line “DHL Delivery problem NR ****”, where **** stands for random generated characters, probably to give the idea that these are tracking numbers of the package. The From address contains randomly choosen spoofed email addresses but no direct track to DHL.

The body of the email:

Dear customer!

We failed to deliver the postal package sent on the 28th of June in time
because the recipient’s address is erroneous.
Please print out the invoice copy attached and collect the package at our office.

Your DHL Delivery Services.

The email has a ZIP file attached that starts with the letter “D” followed by random generated characters, for ex. D1c8020fd.zip, and contains the trojan W32/Troj_Obfusc.J.gen!Eldorado (F-Prot), TrojanDownloader:Win32/Bredolab.X (Microsoft), Mal/Behav-340 (Sophos).

Only  8 of the 41 AV engines at Virus Total detected the trojan at the time of investigating this new threat so be carefull because it is likely that your AV engine isn’t up to date yet.

VirusTotal permlink and MD5: e9a23f7e7850257398b2021b927f706b.

MX Lab Summer Sales, only €8 per mailbox per year!

MX Lab is offering the Zero Hour Anti Virus and Managed Anti Spam for your mail server for € 8 per mailbox per year. For more information visit http://www.mxlab.eu/ and contact us.