<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; tracking number</title>
	<atom:link href="http://blog.mxlab.eu/tag/tracking-number/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; tracking number</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>ZBot trojan attached to contract</title>
		<link>http://blog.mxlab.eu/2008/07/26/zbot-trojan-attached-to-contract/</link>
		<comments>http://blog.mxlab.eu/2008/07/26/zbot-trojan-attached-to-contract/#comments</comments>
		<pubDate>Sat, 26 Jul 2008 20:31:25 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[parcel trojan]]></category>
		<category><![CDATA[parcel virus]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[tracking number]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[UPS virus]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=123</guid>
		<description><![CDATA[A new variant of the ZBot trojan is attached to an email with your contract details. Possible subject lines are: Contract of settlements Contract of retirements Permit for retirement Loan contract The contents of the message: Dear customers, We have prepared a contract and added the paragraphs that you wanted to see in it. Our lawyers [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=123&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A new variant of the ZBot trojan is attached to an email with your contract details. Possible subject lines are:</p>
<blockquote><p>Contract of settlements<br />
Contract of retirements<br />
Permit for retirement<br />
Loan contract</p></blockquote>
<p>The contents of the message:</p>
<blockquote><p>Dear customers,</p>
<p>We have prepared a contract and added the paragraphs that you wanted to see in it. Our lawyers made alterations on the last page. If you agree with all the provisions we are ready to make the payment on Friday for the first consignment. We are enclosing the file with the prepared contract. If necessary, we can send it by fax. </p>
<p>Looking forward to your decision.<br />
Israel Bender</p></blockquote>
<p>Virus Total <a href="http://www.virustotal.com/analisis/fabdaf3dd6b155364dc2f50c38359874" target="_blank">permalink</a> and MD5 hash: c0a907c8bf64d60bec0cce934ca60a34</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/123/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/123/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/123/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=123&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/07/26/zbot-trojan-attached-to-contract/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>UPS Tracking number trojan &#8211; another variant and Hallmark e-card</title>
		<link>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/</link>
		<comments>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/#comments</comments>
		<pubDate>Wed, 23 Jul 2008 18:59:56 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[e-card virus]]></category>
		<category><![CDATA[hallmark e-card virus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[tracking number]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[UPS virus]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=114</guid>
		<description><![CDATA[There is a new variant of the UPS Tracking number trojan on route. The subject is now &#8220;[RE] UPS Tracking Number 7056968807&#8243; but the contents remains the same. The URL that is used by the trojan is slightly different, the host remails the same, the folder structure and the .bin file on the site is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=114&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>There is a new variant of the UPS Tracking number trojan on route. The subject is now &#8220;[RE] UPS Tracking Number 7056968807&#8243; but the contents remains the same. The URL that is used by the trojan is slightly different, the host remails the same, the folder structure and the .bin file on the site is different: http://***********.ru/offshore/denis.bin. The number in the subject and file can be random.</p>
<p>The new variant is detected by 13 of the 35 anti virus engines at <a href="http://www.virustotal.com/analisis/fcf90df882b41b4a33821cca8461e663" target="_blank">Virus Total</a>. The MD5 hash is 488d34cd86e252abca560416413a595d.</p>
<p>Also, if you receive an Hallmark E-Card as attachment it&#8217;s also another <a href="http://www.virustotal.com/analisis/de926ad78b01c9e28f011138a195dd03" target="_blank">variant of a Trojan-Dropper.Win32</a> also known as W32/P2Pworm.E.worm or Trojan.Delf.Inject.F. The chances for infection are much less, 24 of the 35 engines provide protection, so there&#8217;s a good chance that it&#8217;s captured.</p>
<p>When reading the comments on this blog and also on other resources and web site, I am amazed how many people have double clicked the attachment and have indeed infected their computer.</p>
<p>Now, a very simple tip for the future that is also mentioned on some other web sites as well is <strong>don&#8217;t open attachments without checking the content and senders first</strong>. Handle each email with attachments carefully and don&#8217;t start to extract them and click on executables and files with exotic extensions.</p>
<p>Large companies like UPS, Hallmark and others don&#8217;t send you an executable in a zip file. So this is something that you should be aware of. This is the first &#8220;red light&#8221;.</p>
<p>UPS tracking is done online on their web site and after all, think about it, a message stating that a delivery from July the 1st can&#8217;t be delivered while we are in fact July 23 is not a very good UPS service, right?</p>
<p>For Hallmark e-cards you also need to visit their web site to get your lovely e-card.</p>
<p>Following this simple guideline can avoid troubles of getting an infected computer. This applies for everyone. If you work from home, you are an individual, you are in a business environment, it&#8217;s a good tip for everyone.</p>
<p>Now, if you have a business with employees and multiple workstations, servers and computers and you have an infection on your network then you might ask yourself if your anti virus protection is up to the task of providing protection after all. It appears that it is not.</p>
<p>You are missing a good protection on the internet perimeter that is capable of responding faster to email based threats like viruses and trojans.</p>
<p>In that case, let me promote my company for once, contact <a href="http://www.mxlab.eu/en/contactus/index.html" target="_blank">MX Lab</a>, get a <a href="http://www.mxlab.eu/en/contactus/15day_audit.html" target="_blank">15 day trial</a> of our <a href="http://www.mxlab.eu/en/zero_hour_anti_virus.html" target="_blank">zero hour anti virus</a> and <a href="http://www.mxlab.eu/en/managed_anti_spam.html" target="_blank">anti spam</a> security services and notice the difference.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/114/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/114/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/114/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=114&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>UPS Tracking number trojan &#8211; new variant</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/</link>
		<comments>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comments</comments>
		<pubDate>Mon, 21 Jul 2008 23:05:55 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[tracking number]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[UPS virus]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99</guid>
		<description><![CDATA[Around 00:02 AM, local Belgian time, MX Lab detected an outbreak of a new UPS tracking number trojan. The email itself remains the same but the attachment name contains now a tracking number like UPS_INVOICE_978172.exe. The .exe is a new variant and when submitting an example to Virus Total only 3 of the 34 anti [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=99&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Around 00:02 AM, local Belgian time, MX Lab detected an outbreak of a new UPS tracking number trojan.</p>
<p>The email itself remains the same but the attachment name contains now a tracking number like UPS_INVOICE_978172.exe.</p>
<p>The .exe is a new variant and when submitting an example to Virus Total only <strong>3 of the 34 anti virus engines detected this new variant</strong>. More details below in the table.</p>
<blockquote>
<table id="tablaMotores" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<th>Antivirus</th>
<th>Version</th>
<th>Last Update</th>
<th>Result</th>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>2008.7.21.1</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>AntiVir</td>
<td>7.8.1.11</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>Authentium</td>
<td>5.1.0.4</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Avast</td>
<td>4.8.1195.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>AVG</td>
<td>8.0.0.130</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>BitDefender</td>
<td>7.2</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>9.50</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>ClamAV</td>
<td>0.93.1</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>DrWeb</td>
<td>4.44.0.09170</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>eSafe</td>
<td>7.0.17.0</td>
<td>2008.07.21</td>
<td class="positivo">Suspicious File</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>31.6.5971</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Ewido</td>
<td>4.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>F-Prot</td>
<td>4.4.4.56</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>F-Secure</td>
<td>7.60.13501.0</td>
<td>2008.07.21</td>
<td class="positivo">Suspicious:W32/Malware!Gemini</td>
</tr>
<tr>
<td>Fortinet</td>
<td>3.14.0.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>GData</td>
<td>2.0.7306.1023</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>Ikarus</td>
<td>T3.1.1.34.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Kaspersky</td>
<td>7.0.0.125</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>McAfee</td>
<td>5343</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Microsoft</td>
<td>1.3704</td>
<td>2008.07.22</td>
<td>-</td>
</tr>
<tr>
<td>NOD32v2</td>
<td>3284</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Norman</td>
<td>5.80.02</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>Panda</td>
<td>9.0.0.4</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>PCTools</td>
<td>4.4.2.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>Prevx1</td>
<td>V2</td>
<td>2008.07.22</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Rising</td>
<td>20.54.02.00</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.31.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Sunbelt</td>
<td>3.1.1536.1</td>
<td>2008.07.18</td>
<td>-</td>
</tr>
<tr>
<td>Symantec</td>
<td>10</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>TheHacker</td>
<td>6.2.96.385</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>8.700.0.1004</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>VBA32</td>
<td>3.12.8.1</td>
<td>2008.07.21</td>
<td class="positivo">suspected of Malware-Cryptor.Win32.General.2</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>4.5.11.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Webwasher-Gateway</td>
<td>6.6.2</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
</tbody>
</table>
</blockquote>
<p>The file contains threat characteristics of ZBot &#8211; a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system. It opens backdoors on infected computer to allow malicious attacker unauthorized access.</p>
<p>On an infected computer the trojan will create a new files like %System%\ntos.exe, %System%\wsnpoem\audio.dll, %System%\wsnpoem\video.dll and creates a new directory %System%\wsnpoem.</p>
<p>It also adds and modifies entries in the Windows registry and make connection with a server for http://*********.ru/******/odessa.bin. It opens random TCP ports in order to provide backdoor capabilities.</p>
<p><strong>Update 10:00 AM Belgian time:</strong></p>
<p>The MD5 on Virus Total is da4b7ef93c588ad799f1a1c5afb6cfad and the trojan is now detectedby 12 virus engines. Permalink: <a href="http://www.virustotal.com/analisis/69a8553eb41687126314099d97f7dcdf" target="_blank">http://www.virustotal.com/</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/99/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/99/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/99/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=99&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/feed/</wfw:commentRss>
		<slash:comments>36</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>UPS Tracking number trojan</title>
		<link>http://blog.mxlab.eu/2008/07/20/ups-tracking-number-trojan/</link>
		<comments>http://blog.mxlab.eu/2008/07/20/ups-tracking-number-trojan/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 15:28:39 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[tracking number]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[UPS virus]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=94</guid>
		<description><![CDATA[When you receive an email from UPS regarding a package that can&#8217;t be delivered due to an incorrect recipients address you better watch out. The chance is very likely that this is a new variant of a trojan trying to get your attention and to infect your computer.   The messages contains the text: Unfortunately we [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=94&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>When you receive an email from UPS regarding a package that can&#8217;t be delivered due to an incorrect recipients address you better watch out. The chance is very likely that this is a new variant of a trojan trying to get your attention and to infect your computer.</p>
<p> <img src="http://www.mxlab.eu/img_news/20080720_UPSVirus.jpg" alt="null" /></p>
<p>The messages contains the text:</p>
<blockquote><p>Unfortunately we were not able to deliver postal package you sent on July the 1st in time<br />
because the recipients address is not correct.<br />
Please print out the invoice copy attached and collect the package at our office</p>
<p>Your UPS</p></blockquote>
<p>The messages includes an attachment ups_invoice.zip which extracts the ups_invoice.exe file.  This file contains a trojan known as W32/Agent.HFN by F-Prot. We couldn&#8217;t resist to submit this file to Virus Total and to see how many signature based anti virus engine will detect this malware. This time there where only <strong>8 of the 34 anti virus engines detecting the trojan</strong>.</p>
<p>Here are the complete results from Virus Total:</p>
<blockquote>
<table id="tablaMotores" border="0" cellspacing="1" cellpadding="1">
<tbody>
<tr>
<th>Antivirus</th>
<th>Version</th>
<th>Last Update</th>
<th>Result</th>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>2008.7.17.0</td>
<td>2008.07.18</td>
<td>-</td>
</tr>
<tr class="odd">
<td>AntiVir</td>
<td>7.8.1.11</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>Authentium</td>
<td>5.1.0.4</td>
<td>2008.07.20</td>
<td class="positivo">W32/Agent.HFN</td>
</tr>
<tr class="odd">
<td>Avast</td>
<td>4.8.1195.0</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>AVG</td>
<td>8.0.0.130</td>
<td>2008.07.19</td>
<td class="positivo">Dropper.Generic.VGK</td>
</tr>
<tr class="odd">
<td>BitDefender</td>
<td>7.2</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>9.50</td>
<td>2008.07.18</td>
<td>-</td>
</tr>
<tr class="odd">
<td>ClamAV</td>
<td>0.93.1</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>DrWeb</td>
<td>4.44.0.09170</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr class="odd">
<td>eSafe</td>
<td>7.0.17.0</td>
<td>2008.07.20</td>
<td class="positivo">Suspicious File</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>31.6.5966</td>
<td>2008.07.18</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Ewido</td>
<td>4.0</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>F-Prot</td>
<td>4.4.4.56</td>
<td>2008.07.20</td>
<td class="positivo">W32/Agent.HFN</td>
</tr>
<tr class="odd">
<td>F-Secure</td>
<td>7.60.13501.0</td>
<td>2008.07.20</td>
<td class="positivo">Suspicious:W32/Malware!Gemini</td>
</tr>
<tr>
<td>Fortinet</td>
<td>3.14.0.0</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr class="odd">
<td>GData</td>
<td>2.0.7306.1023</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>Ikarus</td>
<td>T3.1.1.34.0</td>
<td>2008.07.20</td>
<td class="positivo">Trojan-Dropper.Win32.Delf.aef</td>
</tr>
<tr class="odd">
<td>Kaspersky</td>
<td>7.0.0.125</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>McAfee</td>
<td>5342</td>
<td>2008.07.18</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Microsoft</td>
<td>1.3704</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>NOD32v2</td>
<td>3282</td>
<td>2008.07.19</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Norman</td>
<td>5.80.02</td>
<td>2008.07.18</td>
<td>-</td>
</tr>
<tr>
<td>Panda</td>
<td>9.0.0.4</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Prevx1</td>
<td>V2</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>Rising</td>
<td>20.53.62.00</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Sophos</td>
<td>4.31.0</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>Sunbelt</td>
<td>3.1.1536.1</td>
<td>2008.07.18</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Symantec</td>
<td>10</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>TheHacker</td>
<td>6.2.96.385</td>
<td>2008.07.19</td>
<td>-</td>
</tr>
<tr class="odd">
<td>TrendMicro</td>
<td>8.700.0.1004</td>
<td>2008.07.18</td>
<td>-</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.12.8.1</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr class="odd">
<td>VirusBuster</td>
<td>4.5.11.0</td>
<td>2008.07.19</td>
<td class="positivo">Packed/Pohernah</td>
</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>6.6.2</td>
<td>2008.07.20</td>
<td class="positivo">Win32.Malware.gen#ASPack (suspicious)</td>
</tr>
</tbody>
</table>
</blockquote>
<p>Again, this is showing the importance of <a href="http://www.mxlab.eu/en/zero_hour_anti_virus.html" target="_blank">a zero hour anti virus protection like MX Lab</a> is offering.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/94/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/94/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/94/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=94&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/07/20/ups-tracking-number-trojan/feed/</wfw:commentRss>
		<slash:comments>46</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20080720_UPSVirus.jpg" medium="image">
			<media:title type="html">null</media:title>
		</media:content>
	</item>
	</channel>
</rss>