Site icon WinCert

Your order has been paid! Parcel NR.5748

<p><a href&equals;"http&colon;&sol;&sol;wincert&period;net&sol;wp-content&sol;uploads&sol;2015&sol;01&sol;security2&period;jpg"><img class&equals;"alignnone size-full wp-image-545" src&equals;"http&colon;&sol;&sol;wincert&period;net&sol;wp-content&sol;uploads&sol;2015&sol;01&sol;security2&period;jpg" alt&equals;"security box&comma;usps&comma;virus&comma;malware" width&equals;"720" height&equals;"340" &sol;><&sol;a><&sol;p>&NewLine;<p>From what I can see&comma; variations of BredoLab virus keeps on coming&period; I&&num;8217&semi;ve already wrote two articles about suspicious e-mails that I&&num;8217&semi;ve received&period; Those mails contained a virus that wasn&&num;8217&semi;t detected by my antivirus software &lpar;Microsoft Security Essentials&rpar;&period;<&sol;p>&NewLine;<p>Both mails came from spoofed ups&period;com domain&period; This time&comma; we have a spoofed amazon&period;com domain&comma; so be careful&period;<&sol;p>&NewLine;<p><&excl;--more--><&sol;p>&NewLine;<p>I&&num;8217&semi;ve received this suspicious mail this morning and I am sure that it contains a virus&comma; probably another variant of Bredolab trojan&period; The problem is that this variant still isn&&num;8217&semi;t recognized by some of the most popular Anti Virus applications like <span style&equals;"color&colon; &num;003366&semi;">Microsoft Security Essentials&comma; Avast&comma; NOD32&comma; Panda&comma; Kaspersky <&sol;span>etc&period; According to virustotal&period;com&comma; only 20&percnt; of tested antivirus applications managed to detect a thread which includes <span style&equals;"color&colon; &num;003366&semi;">Sophos&comma; Symanted&comma; Trendmicro<&sol;span> etc&period;&period;<&sol;p>&NewLine;<p>Here are the contents of this mail&colon;<&sol;p>&NewLine;<p>From&colon; <strong>Shop Support Dolly Davison &lbrack;support&period;shop&commat;amazon&period;com&rsqb;<&sol;strong><&sol;p>&NewLine;<p>Subject&colon; <strong>Your order has been paid&excl; Parcel NR&period;5748<&sol;strong> <span style&equals;"color&colon; &num;993300&semi;">&lpar;Note&colon; it can contain different numbers as those are generated randomly&rpar;<&sol;span><&sol;p>&NewLine;<p>Attachment&colon; <strong>Print&lowbar;label&lowbar;6387&period;zip<&sol;strong> <span style&equals;"color&colon; &num;993300&semi;">&lpar;contains Print&lowbar;label&lowbar;6387&period;exe&rpar;<&sol;span><&sol;p>&NewLine;<p>Body&colon;<&sol;p>&NewLine;<p style&equals;"padding-left&colon; 30px&semi;">Hello&excl;<&sol;p>&NewLine;<p style&equals;"padding-left&colon; 30px&semi;">Thank you for shopping at Amazon&period;com<&sol;p>&NewLine;<p style&equals;"padding-left&colon; 30px&semi;">We have successfully received your payment&period;<&sol;p>&NewLine;<p style&equals;"padding-left&colon; 30px&semi;">Your order has been shipped to your billing address&period;<&sol;p>&NewLine;<p style&equals;"padding-left&colon; 30px&semi;">You have ordered &&num;8221&semi; Dell Inspiron Mini 1011 &&num;8220&semi;<&sol;p>&NewLine;<p style&equals;"padding-left&colon; 30px&semi;">You can find your tracking number in attached to the e-mail  document&period;<&sol;p>&NewLine;<p style&equals;"padding-left&colon; 30px&semi;">Print the postal label to get your package&period;<&sol;p>&NewLine;<p style&equals;"padding-left&colon; 30px&semi;">We hope you enjoy your order&excl;<&sol;p>&NewLine;<p style&equals;"padding-left&colon; 30px&semi;">Amazon&period;com<&sol;p>&NewLine;<p>&&num;8212&semi;&&num;8212&semi;&&num;8212&semi;&&num;8212&semi;&&num;8212&semi;&&num;8212&semi;&&num;8212&semi;&&num;8212&semi;&&num;8211&semi;<&sol;p>&NewLine;<p>I have reported suspicious file to Microsoft and will update this article once I get results&period;<&sol;p>&NewLine;<p><span style&equals;"color&colon; &num;339966&semi;">UPDATE&colon;<&sol;span> Microsoft confirmed that this is another variant of <span style&equals;"color&colon; &num;993300&semi;">Trojan&colon;Win32&sol;Oficla&period;M<&sol;span>&period; Please update your virus definitions so you can be fully protected&period;<&sol;p>&NewLine;<p>More information <a href&equals;"https&colon;&sol;&sol;www&period;microsoft&period;com&sol;security&sol;portal&sol;Threat&sol;Encyclopedia&sol;Entry&period;aspx&quest;name&equals;Trojan&colon;Win32&sol;Oficla&period;M" target&equals;"&lowbar;blank">HERE<&sol;a>&period;<&sol;p>&NewLine;

Exit mobile version