
SonicWALL UTM Research team has observed an increase in spam campaigns involving new variants of Oficla Trojan in the last two weeks. These spam campaigns included tracking notices and delivery failure notices from various Mailing services.
SonicWALL has received more than 700,000 e-mail copies from these spam campaigns till now. The email messages in all these spam campaigns have a zip archived attachment which contains the new variants of Oficla Trojan executable. The sample e-mail format from each spam campaign is shown below:
Campaign #1 - United Parcel Service (UPS) tracking number spam starting March 28, 2011
- Fake UPS tracking notices with slightly different subject and body.
Campaign #2 - Post Express notification spam starting March 28, 2011
- Fake deilvery failure message containing mailing label and invoice copy to pickup a package. Below is an example of one such e-mail:
Campaign #3 - DHL Express spam March 30, 2011
- Fake DHL tracking notices
Campaign #4 - Express Delivery notification spam starting April 6, 2011
- Fake Express Delivery tracking notices
The executable files inside the attachment masquerades the icon of popular formats like MS Word, PDF to trick the user:
If the user downloads and executes the malicious executable inside the zip attachment, it performs the following activity:
If the user attempts to open any of the Application executable,it will show a fake infection warning as seen below:
More fake infection warnings forcing user to buy the rogue application:
SonicWALL Gateway AntiVirus provides protection against above spam campaigns by following signatures:
Share This Article

An Article By
An Article By
Security News
Security News