Categorized | Security

FedEx emails with new trojan variant

MX Lab intercepted a new campaign of FedEx emails that have a trojan attached to the message. The email is sent from the spoofed address ”Fedex Support, Trisha Kimble” <kyeagl@fedex.com> – please note that the name of the person can change.

Possible subjects:

Fedex Invoice Copy N25524750
Fedex Item Status N4347526
Fedex Shipment Status N0919106
Fedex Tracking Number N7897143

The body of the email does not contains any text but only an embedded image.

The email has the attachment  FEDEXInvoiceEE438252OP.zip. The 36 kB large file FedexInvoice_EE776129.exe is extracted from the zip archive.

At the time of writing, only 8 of the 42 AV engines at Virus Total did detect the trojan. The trojan is known as W32/Agent.JBI (Authentium), Suspicious:W32/Malware!Gemini (F-Secure), TrojanDropper:Win32/Oficla.T (Microsoft), a variant of Win32/Kryptik.GHC (NOD32).

Virus Total permlink and MD5: 2587d5dc4b18e652532e556ac26f2290

View full post on mxlab – all about anti virus and anti spam

Related Posts

6 Responses to “FedEx emails with new trojan variant”

  1. Robert says:

    Hy
    i recived a mail from FedEx service”

    Subject : FedEx notice #8263351

    No text just the attachment FedEx.zip , the yahoo antivirus scanned but not detected anything .
    I have suspicion because i don`t have buyed anything and i searched in google and i see now this attachement it`s probably a trojan.

  2. Andrew says:

    I fell for it. Which was pretty stupid considering i just removed this virus from a friends computer earlier today. Never heard of using FedEx as a base though, alright, time to fix my compy.

  3. Roni says:

    do not click the zip file I believe it is a virus

  4. Prakashbabu says:

    I’d no idea what has it brought…..! the yahoo scanner didn’t detect any virus while downloading from inbox….. later on I scaned the downloaded zip file with bitdefender, it didn’t show any threat either. Finally I opened the zip folder and dragged the exe file from it to the desktop and scanned with bitdefender…. Obviously! It detected no threat. Then I executed the file…..and it just disappeared…… I checked the quarantinne of bitdefender. I couldn’t find that there….. I think it has secured itself in the system of my pc somewhere!

    So is there any good chance that I can remove it from my pc?

  5. fafa says:

    i believe is a virus

  6. Phantom says:

    Try either a system restore or use any antivirus that scans the boot sector.

Trackbacks/Pingbacks


Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago