<br />
<b>Deprecated</b>:  Function create_function() is deprecated in <b>/home/hidefide/public_html/blog/wp-content/plugins/wr-pagebuilder/core/core.php</b> on line <b>127</b><br />
{"id":492,"date":"2017-12-16T15:38:29","date_gmt":"2017-12-16T15:38:29","guid":{"rendered":"https:\/\/icaruspressblog.wordpress.com\/?p=492"},"modified":"2019-04-17T11:40:02","modified_gmt":"2019-04-17T11:40:02","slug":"capitalizing-on-the-holidays-fedex-malware-spam","status":"publish","type":"post","link":"https:\/\/hidefideas.com\/blog\/2017\/12\/16\/capitalizing-on-the-holidays-fedex-malware-spam\/","title":{"rendered":"Capitalizing on the Holidays: FedEx Malware Spam"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"  wp-image-493 alignleft\" src=\"http:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/christmas-gifts-13831.jpg\" alt=\"Christmas-gifts-13831\" width=\"408\" height=\"255\" srcset=\"https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/christmas-gifts-13831.jpg 1680w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/christmas-gifts-13831-300x188.jpg 300w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/christmas-gifts-13831-768x480.jpg 768w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/christmas-gifts-13831-1024x640.jpg 1024w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/christmas-gifts-13831-240x150.jpg 240w\" sizes=\"auto, (max-width: 408px) 100vw, 408px\" \/>Like Santa Claus and his cadre of industrious elves, spammers don\u2019t take time off for the holidays. Unlike the jolly old elf and his posse, however, the email-happy scam artists are devious, black hearted little children who deserve giant lumps of coal. This is no truer than this time of the year, when retail sales explode, and the average gift <!--more-->buyer tries to stay ahead of the game by stumbling through the dizzying maze of online shopping opportunities. Online purchases require shipping, and the spammers know that, too. So it shouldn\u2019t be surprising, even if it <em>is<\/em> disheartening, that there are dark souls out there capitalizing on the probability that their targets might have ordered something \u2013 perhaps the <a href=\"http:\/\/www.amazon.com\/The-Clapper-Sound-Activated-Switch\/dp\/B0000CGKLR\">Clapper<\/a> or <a href=\"http:\/\/www.chiapet.com\/\">Chia Pet<\/a> that I clamor for every year and sadly, never get \u2013 and will become the proverbial fly to the spammer\u2019s spider.<\/p>\n<p>That\u2019s why, in the confusing mayhem of the holiday season, anyone who uses email should be aware of the latest scam, this one in the form of a very realistic looking email that appears to come from Federal Express. Being reported by several <a href=\"http:\/\/www.1011now.com\/home\/headlines\/Fed-Ex-Beware-of-Bogus-Email-183104661.html\">sources<\/a>, the bogus email appears to be the real thing, FedEx logo and all, with a notification that the recipient has a parcel they need to pick up, perhaps a care package from nana with her delightful plum preserves and cranberry pudding (okay, that last part was all me. So sue me. I miss my nana\u2019s cranberry pudding).<\/p>\n<p>\u201cDear Customer, Your parcel has arrived at the post office at December 4.Our postrider was unable to deliver the parcel to you. To receive a parcel, please, go to the nearest our office and show this postal receipt,\u201d the email states, <a href=\"http:\/\/news.softpedia.com\/news\/Malicious-FedEx-Postal-Receipts-Hide-Cobra-Trojan-312567.shtml\">according to Softpedia.com<\/a>. The so-called postal receipt is a clickable icon that uses a document icon to make it appear more\u2026well, document-y. And when it\u2019s clicked, a \u2018document reader\u2019 application launches, giving the appearance that everything is good in Chia Pet land. However, Softpedia reports, \u201cin the background, the malicious element injects code into svchost.exe and contacts its remote command and control server in an attempt to download the payload.\u201d<\/p>\n<p><a href=\"http:\/\/www.gfi.com\/blog\/fake-delivery-notification-gets-confused-has-nice-lie-down\/\">Chris Boyd over at GFI Labs<\/a> notes that some browsers will pick up the dirty little piece of code and give you the option to block its download, but also that the resulting file may still end up on your system as a Word Document file pretending to be a zip file. \u201cOpening the \u201cWord document\u201d (which is actually just an executable file in disguise) will infect your PC with a little something we detect as Trojan.Win32.Generic.pak!cobra,\u201d Chris tells us. \u201cBefore you know it, your Trojan chum will delete the original file, create hidden files and make network connections\u2026generally not typical behaviour where a postal receipt is concerned (unless you live in the&nbsp;Eighth Circle of Hell).\u201d<\/p>\n<p>Firmly convinced that the real estate costs are artificially inflated and that the neighborhood is overly pretentious, I personally do not live in the Eighth Circle of Hell, but I get Chris\u2019 point. Do not click this link, ever. Boyd points out that GFI research has linked this type of infection to ransomware, so getting nailed by this email may turn your PC into a package that no amount of ripping and tearing will open. \u201cThese infection files have been linked to Ransomware, in this case something called \u201c<a href=\"http:\/\/blogs.technet.com\/b\/mmpc\/archive\/2012\/12\/04\/msrt-november-12-weelsof-around-the-world.aspx\">Wheelsof<\/a>\u201d and you may well find yourself locked out of your PC if unfortunate enough to fall for this one.\u201d<\/p>\n<p>It\u2019s pretty clear that spammers, no matter how slippery they might be, are still just about as stupid as the people they hope to trick. Maybe stupider. In an ROTFLMAO moment, Chris points out that the email message appears to come from \u201cUPS Office\u201d but closes with \u201cThe FedEx Team.\u201d (you can read the full text of the email on the <a href=\"http:\/\/www.gfi.com\/blog\/labs\/\">GFI Labs blog<\/a>) As Forrest Gump\u2019s mother used to say, \u201cstupid is as stupid does,\u201d and Boyd gives the spammers an F for flumped. \u201cA lot of these fake delivery notices are pretty convincing, but hopefully the peculiar mashup of FedEx and UPS is the kind of tip-off that\u2019s up there with Pippin lighting the Warning Beacons of Gondor.\u201d<\/p>\n<p>Lord of the Rings reference aside, this is a dangerous email. It should also be noted that shipping company spam messages aren\u2019t unusual. In fact, a quick Google search shows that spams pretending to be FedEx shipping notices are quite common, giving us comfort in the knowledge that spammers are douchebags all year long.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Like Santa Claus and his cadre of industrious elves, spammers don\u2019t take time off for the holidays. Unlike the jolly old elf and his posse,&hellip; <\/p>\n","protected":false},"author":3,"featured_media":493,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,14],"tags":[11,9,10,8,7],"class_list":["post-492","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-spam","tag-allspammedup","tag-bot","tag-botnet","tag-malware","tag-spam","jsn-master"],"_links":{"self":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/comments?post=492"}],"version-history":[{"count":2,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/492\/revisions"}],"predecessor-version":[{"id":1776,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/492\/revisions\/1776"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media\/493"}],"wp:attachment":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media?parent=492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/categories?post=492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/tags?post=492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}