Thursday, June 4, 2009

X.W32.troj.ob.OH.b


Subject: Delivery problem
Attachment: FILE_NR98671201.zip
AVs: 2/40 (5%) cat, mic


Dear customer!

Unfortunately we failed to to deliver the postal package you have sent on the 8th of March (random date) in time
because the addressee's address is wrong.
Please print out the invoice copy attached and collect the package at our department.

Your United Parcel Service

3 comments:

SBW said...

Running this thing breaks terminal services client.

...phread said...

Thanks for your addition, it would appear to that it is also looking for removable media devices to hitch a ride on.

SparkyPine said...

Someone in my organization fell for this today. It installed a ton of malware that Malwarebytes found. Also, two running processes: cmd.exe and svchost.exe completely maxed out the cpu rendering the machine unusable. Will end up doing a reformat on the machine as I bet there are some rootkits involved.