<p><a href="http://wincert.net/wp-content/uploads/2015/01/security2.jpg"><img class="alignnone size-full wp-image-545" src="http://wincert.net/wp-content/uploads/2015/01/security2.jpg" alt="security box,usps,virus,malware" width="720" height="340" /></a></p>
<p>From what I can see, variations of BredoLab virus keeps on coming. I&#8217;ve already wrote two articles about suspicious e-mails that I&#8217;ve received. Those mails contained a virus that wasn&#8217;t detected by my antivirus software (Microsoft Security Essentials).</p>
<p>Both mails came from spoofed ups.com domain. This time, we have a spoofed amazon.com domain, so be careful.</p>
<p><!--more--></p>
<p>I&#8217;ve received this suspicious mail this morning and I am sure that it contains a virus, probably another variant of Bredolab trojan. The problem is that this variant still isn&#8217;t recognized by some of the most popular Anti Virus applications like <span style="color: #003366;">Microsoft Security Essentials, Avast, NOD32, Panda, Kaspersky </span>etc. According to virustotal.com, only 20% of tested antivirus applications managed to detect a thread which includes <span style="color: #003366;">Sophos, Symanted, Trendmicro</span> etc..</p>
<p>Here are the contents of this mail:</p>
<p>From: <strong>Shop Support Dolly Davison [support.shop@amazon.com]</strong></p>
<p>Subject: <strong>Your order has been paid! Parcel NR.5748</strong> <span style="color: #993300;">(Note: it can contain different numbers as those are generated randomly)</span></p>
<p>Attachment: <strong>Print_label_6387.zip</strong> <span style="color: #993300;">(contains Print_label_6387.exe)</span></p>
<p>Body:</p>
<p style="padding-left: 30px;">Hello!</p>
<p style="padding-left: 30px;">Thank you for shopping at Amazon.com</p>
<p style="padding-left: 30px;">We have successfully received your payment.</p>
<p style="padding-left: 30px;">Your order has been shipped to your billing address.</p>
<p style="padding-left: 30px;">You have ordered &#8221; Dell Inspiron Mini 1011 &#8220;</p>
<p style="padding-left: 30px;">You can find your tracking number in attached to the e-mail document.</p>
<p style="padding-left: 30px;">Print the postal label to get your package.</p>
<p style="padding-left: 30px;">We hope you enjoy your order!</p>
<p style="padding-left: 30px;">Amazon.com</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>I have reported suspicious file to Microsoft and will update this article once I get results.</p>
<p><span style="color: #339966;">UPDATE:</span> Microsoft confirmed that this is another variant of <span style="color: #993300;">Trojan:Win32/Oficla.M</span>. Please update your virus definitions so you can be fully protected.</p>
<p>More information <a href="https://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?name=Trojan:Win32/Oficla.M" target="_blank">HERE</a>.</p>