Emails Western Union Service contains Bredolab


After a relative low virus detection for more than a week, MX Lab started to intercepted a new virus outbreak of Bredolab in emails regarding a Western Union money transfer. The malware is named Bredolab.gen.a (McAfee), TrojanDownloader:Win32/Bredolab.X (Microsoft),  Mal/Krap-B (Sophos) or Trojan.Bredolab!gen3 (Symantec). The spoofed from address is in the form of Manager Ginger Patrick <customer@westernunion.com> … Continue reading Emails Western Union Service contains Bredolab

Emails regarding updating your mailbox leads to the malware flashinstaller.exe


MX Lab intercepts emails with an embedded URL that leads to a web site where  you will have the notice "You don't have the latest version of Macromedia Flash Player." and you can download the file flashinstaller.exe. The file itself is malware and listens to the name Win32:Zbot-MGA (Avast), W32/Bifrost.C.gen!Eldorado (F-Prot), PWS-Zbot.gen.v (McAfee) or PWS:Win32/Zbot.gen!R … Continue reading Emails regarding updating your mailbox leads to the malware flashinstaller.exe

MySpace subject to phishing campaign


Social networks are often subject to phishing and today MySpace is the target. MX Lab intercepted some messages from MySpace <message-*********@message.myspace.com> - where * stands for random letter and number combination. The from address is obviously spoofed. The body of the email: Dear MySpace user! Please be informed that you are required to update your … Continue reading MySpace subject to phishing campaign

DHL Tracking Number 3YMH6JJY contains trojan


MX Lab intercepted a large amount of emails with the subject "DHL Tracking Number 3YMH6JJY" containing the trojan TrojanDownloader:Win32/Cutwail.gen!C (Microsoft), Trojan.Kobka.E (GData), AVG (SHeur2.BQSN() or Troj/Agent-LQA (Sophos). The contents of the email: Dear customer! The courier company was not able to deliver your parcel by your address. You may pickup the parcel at our post office … Continue reading DHL Tracking Number 3YMH6JJY contains trojan