“DHL Service. Error in delivery addres number 452” contains a trojan

MX Lab started to intercept a new trojan distribution campaign by email with the subject “DHL Service. Error in delivery addres number 452” – number at the end may vary.

The email is send from the spoofed address “DHL Global Mail <services.id8852@dhl.com>” and has the folowing body:

Dear customer.

We were not able to deliver your package to your address.

Reason: Error in delivery address.

Please attention!
Get your parcel in your local post office.
The postal label is attached to this e-mail.
We kindly ask you to print it and take it to the post office to pick up the package.

Thank you!
DHL Customer Service.

The attached zip file has the name DHL_Print_Label_ID4114.zip and contains the 36 kB large file DHL_Print_Label_ID4114.exe.

The trojan is known as Win32:Trojan-gen (Avast), Trojan-Downloader:W32/Oficla.HR (F-Secure), TrojanDropper:Win32/Oficla.T (Microsoft), Trojan-Dropper/W32.Agent.36864.GH (Norman).

Virus Total permlink and MD5: 9ffc6994a66be0d8667550a0e9ed80ea.

3 thoughts on ““DHL Service. Error in delivery addres number 452” contains a trojan

  1. Some transport headers of this message I just received:

    From: “DHL Global Mail”
    X-Mailer: Microsoft Outlook Express 6.00.2900.2180
    X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
    Received: from by mail.realvestcorp.com; Fri, 3 Sep 2010 13:36:57 +0100

  2. My wife got this on 11/15/10 , didn’t open it thank goodness and forwarded it to me to take care of. Yahoo mail caught it so it didn’t get opened. Funny thing is we are waiting for an appliance part and she thought this was it.

    From: DHL Express Services
    Subject: Error in the delivery address S.NR1756008
    Date: Monday, November 15, 2010, 10:56 AM

    The company could not deliver your package to your address.
    The package was returned to DHL office.
    Information about your package is attached to the letter.
    Look through the information about your package thoroughly.

    Thank you for attention.
    DHL Global Mail.

Comments are closed.