Statement of Fees
We’re continuing to see high volumes of Fedex and UPS spam at the moment, and we’ve just started to see a parallel campaign by the same authors with the subject “Statement of fees 2008/09″ and the following message body:
Please find attached a statement of fees as requested, this will be posted today.
The accommodation is dealt with by another section and I have passed your request on to them today.
Kind regards.
The attachment is called Fees_2008-2009.zip, containing a file called Fees_2008-2009.doc______________.exe which we detect proactively as Mal/EncPk-ES.
We’ve seen this same family of malware in campaigns from bogus contractual agreements to flight ticket notifications. Don’t let curiosity get the better of you - don’t open the attachment if you didn’t order the package, or the tickets, or the contract, or the accommodation … or whatever else they’ll come up with next.
Posted on August 23rd, 2008 by Richard Cohen, SophosLabs CanadaFiled under: Malware, Spam














