New WSF malware with subject “Emailing: Label” from UPS


MX Lab, http://www.mxlab.eu, started to intercept a new malware distribution campaign by email with the subject “Emailing: Label”.

This fake email is send from the spoofed addresses  in the format *******@ups.es”, giving an impression that the email is from UPS, and has the following body:

Good afternoon

The office printer is having problems so I’ve had to email the UPS label, sorry for the inconvenience.

Cheers

Erwin farquhar

The attached file Label589.zip contains the file 556275730809.wsf which is a Windows Script File document.

The malware is detected by 4/55 AV engines at Virus Total and the analysis is available on Malwr.