Spamvertised 'DHL Tracking Notification' emails serve malware
Summary: Security researchers from Sophos have intercepted a currently circulating malware campaign that's using 'DHL Tracking Notification" themed emails in order to serve malware.
Security researchers from Sophos have intercepted a currently circulating malware campaign that's using 'DHL Tracking Notification" themed emails in order to serve malware.
The emails contain a ZIP attachment -- DHL-Express-Delivery-Notification-Details_03-2012_[random string].zip -- that's containing the actual malicious code. The malware is currently detected as Mal/BredoZp-B and Mal/Zbot-FV.
This isn't the first time that cybercriminals are impersonating DHL. In the past, they have also impersonated UPS and FedEx, once again in an attempt to trick end and corporate users into downloading and executing a malicious attachment.
End and corporate users are advised to avoid interacting with the emails, and to report them as spam/fraudulent immediately.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback
Just to confirm
1. You get an email with a zip file attached.
2. You have to open the zip file and in there is an executable file.
3. You then have to run the executable file.
4. Finally, you have to elevate the permissions on the executable file.
Is that about right or did I miss something?
What I don't understand is why malware authors require users to go through so many steps in order to get infected with this stuff? Since we are constantly told that Windows has swiss cheese security, why don't these malware authors simply use one of the millions of easy ways out there to automatically gain admin rights on these Windows machines?
Or is it possible we've all been lied to regarding how easy it is to infect a Windows machine?
You left out the most important bit...
1. This applies to MS Windows users only!
2. You get an email with a zip file attached.
3. You have to open the zip file and in there is an executable file.
4. You then have to run the executable file.
5. Finally, you have to elevate the permissions on the executable file.
Of course it does
ease
Nothing really new
Same as you aren't expecting a package at Heathrow, and should not send your passport as identification, and all the other bank or other scams.
A non new story, unless you are a serial idiot.
well.....