This could not be a virus, right?

Status
Not open for further replies.

MotionMan

Lifer
Jan 11, 2006
17,312
12
81
Here is a new twist. I received the following e-mail:

Hello!

We were not able to deliver postal package you sent on the 14th of March in time
because the recipient?s address is not correct.
Please print out the invoice copy attached and collect the package at our office.

Your personal manager: Deirdre Hand,
Customer Service: 1-800-CALL-DHL
Fax: 888-221-6211
DHL International, Ltd. All Rights Reserved.


Attached is a file named "DHL_DOC.zip"

The e-mail came from "Deirdre Hand" at hicksdd@[b]varnalife.com[/b]

Other than the fact that I did not ship anything on March 14th and never use DHL, it seems legit to me!

MotionMan
 

Gamingphreek

Lifer
Mar 31, 2003
11,679
0
81
It could be a virus. The .zip might not actually be a .zip. If you have a Linux partition or LiveCD, boot up into it and extract it there. Look around at the files and see what comes out. In Windows, if you are concerned, scan it with antivirus software before you open it.

Also, you can look at the message headers and see if the E-Mail does, in fact, come from DHL.

Finally, given that you don't use DHL and didn't ship anything - it sounds like it is probably bogus. Unless you know what you are doing, don't do the stuff above.

-Kevin
 

jlee

Lifer
Sep 12, 2001
48,513
221
106
I got something like that "from" UPS or Fedex not too long ago..can't remember if it was a zip or exe.
 

Chronoshock

Diamond Member
Jul 6, 2004
4,860
1
81
My spam folders get hundreds of "you missed your shipment" emails every month. I'm surprised you've never seen this before
 

Iron Woode

Elite Member
Super Moderator
Oct 10, 1999
30,938
12,440
136
Originally posted by: Gamingphreek
It could be a virus. The .zip might not actually be a .zip. If you have a Linux partition or LiveCD, boot up into it and extract it there. Look around at the files and see what comes out. In Windows, if you are concerned, scan it with antivirus software before you open it.

Also, you can look at the message headers and see if the E-Mail does, in fact, come from DHL.

Finally, given that you don't use DHL and didn't ship anything - it sounds like it is probably bogus. Unless you know what you are doing, don't do the stuff above.

-Kevin
or just use sandboxie, in which you can open a zip or run an app that is isolated from the OS.
 

santuitman

Platinum Member
Mar 6, 2001
2,355
0
0
They have a warning right on their telephone line. I happened to be calling about something else and the first thing you hear is something about boug email messages
 

MotionMan

Lifer
Jan 11, 2006
17,312
12
81
Originally posted by: Chronoshock
My spam folders get hundreds of "you missed your shipment" emails every month. I'm surprised you've never seen this before

Maybe my server-side spam scanner has caught them all before now (My e-mail runs through my bro-in-laws server). This is the first one I've seen like this.

MotionMan
 

MotionMan

Lifer
Jan 11, 2006
17,312
12
81
I just received the following e-mail from Michal Ambroz (DHL CZ)():

Hello MotionMan,
Please I have found your message in the forum of
http://forums.anandtech.com/me...id=38&threadid=2288328

Please would you happen to be still in possession of this email with a
original DHL_DOC.zip?
I am trying to track activities of these attackers and I am still
missing this
sample.

If you have the original email, please could sent it to me via email?
Please zip it with password to avoid that some antivirus on the way will
delete it ?

Thank you

Michal Ambroz
IT Security Consultant

Information Security Management
Production Services Prague
DHL Information Services (Europe) s.r.o.
IT Services Center
V Parku 2308/10
148 00 Praha 4 - Chodov
Czech Republic

Phone:
Mobile:
http://www.dhl.com
mailto:

However, I deleted the e-mail, so I do not have the file to send him.

MotionMan

7/21/11 EDIT: Edited Mr. Ambroz e-mail address at his request.

MotionMan
 
Last edited by a moderator:

Dualist

Platinum Member
Dec 5, 2005
2,395
0
86
Try scanning it with an antivirus or antispyware software before extracting it, or vice versa. It should tell you rather or not it's a virus, spyware or adware.
 

Chronoshock

Diamond Member
Jul 6, 2004
4,860
1
81
My yahoo mail spam folder was cleared recently, and my gmail only has two fake shipment emails, one is a standard 401 scam and the other has a link to a spam site, neither have attachments. It's interesting you were contacted
 

CZroe

Lifer
Jun 24, 2001
24,195
856
126
MotionMan: Even if you had never seen it before nor heard of it, there should be NO reason to make a post like this because the answer to your question is right in front of you, Google NOT required.

Stop being a pussy. You know a zip file isn't executable, right? Just open with an alternative decompression app to avoid the possibility of a buffer overflow in XP compressed folder support. Only worry about document data files if it is a format that can contain macros (in that case, open it in WORDPAD). If it's a PDF, well, then I don't know of any executable PDF files or Adobe Acrobat buffer overflow exploits so it would be safe to say that it's not a virus. If it's an executable or some kind of script, then DON'T OPEN IT. DHL has no reason to send you executable files or scripts and it would be entirely unprofessional to do so

Originally posted by: wiredspider
They use .zip because some scanners do not look in "compressed" files.

It still doesn't explain why a user would willy-nilly run executable files inside... oh yeah! Because Microsoft not only fails to educate users as to the difference, but they actively HIDE this information. Way to go EMM ESS!
 

MotionMan

Lifer
Jan 11, 2006
17,312
12
81
Originally posted by: CZroe
MotionMan: Even if you had never seen it before nor heard of it, there should be NO reason to make a post like this because the answer to your question is right in front of you, Google NOT required.

Stop being a pussy. You know a zip file isn't executable, right? Just open with an alternative decompression app to avoid the possibility of a buffer overflow in XP compressed folder support. Only worry about document data files if it is a format that can contain macros (in that case, open it in WORDPAD). If it's a PDF, well, then I don't know of any executable PDF files or Adobe Acrobat buffer overflow exploits so it would be safe to say that it's not a virus. If it's an executable or some kind of script, then DON'T OPEN IT. DHL has no reason to send you executable files or scripts and it would be entirely unprofessional to do so

Originally posted by: wiredspider
They use .zip because some scanners do not look in "compressed" files.

It still doesn't explain why a user would willy-nilly run executable files inside... oh yeah! Because Microsoft not only fails to educate users as to the difference, but they actively HIDE this information. Way to go EMM ESS!

I am going to assume that you are not an incredible dick and, instead, I will assume that you simply missed the sarcasm/humor aspect of the OP.

But, thanks for playing anyway.

MotionMan
 

CZroe

Lifer
Jun 24, 2001
24,195
856
126
Originally posted by: MotionMan
Originally posted by: CZroe
MotionMan: Even if you had never seen it before nor heard of it, there should be NO reason to make a post like this because the answer to your question is right in front of you, Google NOT required.

Stop being a pussy. You know a zip file isn't executable, right? Just open with an alternative decompression app to avoid the possibility of a buffer overflow in XP compressed folder support. Only worry about document data files if it is a format that can contain macros (in that case, open it in WORDPAD). If it's a PDF, well, then I don't know of any executable PDF files or Adobe Acrobat buffer overflow exploits so it would be safe to say that it's not a virus. If it's an executable or some kind of script, then DON'T OPEN IT. DHL has no reason to send you executable files or scripts and it would be entirely unprofessional to do so

Originally posted by: wiredspider
They use .zip because some scanners do not look in "compressed" files.

It still doesn't explain why a user would willy-nilly run executable files inside... oh yeah! Because Microsoft not only fails to educate users as to the difference, but they actively HIDE this information. Way to go EMM ESS!

I am going to assume that you are not an incredible dick and, instead, I will assume that you simply missed the sarcasm/humor aspect of the OP.

But, thanks for playing anyway.

MotionMan

I just needed a place to discuss my disappointment with Microsoft's policies and defaults. Looks like it made the news since yesterday.

http://www.dailytech.com/article.aspx?newsid=15061

Of course, I already commented.
 

randay

Lifer
May 30, 2006
11,019
216
106
Originally posted by: MotionMan
I just received the following e-mail from Michal Ambroz (DHL CZ)():

Hello MotionMan,
Please I have found your message in the forum of
http://forums.anandtech.com/me...id=38&threadid=2288328

Please would you happen to be still in possession of this email with a
original DHL_DOC.zip?
I am trying to track activities of these attackers and I am still
missing this
sample.

If you have the original email, please could sent it to me via email?
Please zip it with password to avoid that some antivirus on the way will
delete it ?

Thank you

Michal Ambroz
IT Security Consultant

Information Security Management
Production Services Prague
DHL Information Services (Europe) s.r.o.
IT Services Center
V Parku 2308/10
148 00 Praha 4 - Chodov
Czech Republic

Phone:
Mobile:
http://www.dhl.com

However, I deleted the e-mail, so I do not have the file to send him.

MotionMan

thats pretty funny. hope this guy realizes how worms work and palmface himself.
 
Last edited by a moderator:

MotionMan

Lifer
Jan 11, 2006
17,312
12
81
7/21/11 Necro update:

Just got this e-mail:

Dear MotionMan,
please do you still have got access to the forum here?
http://forums.anandtech.com/showpost.php?p=27895967&postcount=12

I would like to kindly ask you, whether you could edit this post and
remove my email address and phone from it.

I understand that at the time of this virus campaign it could have been
useful for the followers
of the forum to have the direct contact to me there.
Now after 2 years I am just receiving spam because of that post.

Thank you for understanding.

Best regards

Michal Ambroz
IT Security Consultant, gsm: , tel: (Prague)

I have edited the post.

MotionMan
 
Last edited by a moderator:

ElFenix

Elite Member
Super Moderator
Mar 20, 2000
102,425
8,388
126
i think spam bots are probably smart enough to parse username at domain dot com. i'm going to delete the whole thing. i can put it back later if need be. also deleting from the quoted post. deleted phone numbers too (thanks seepy!).
 
Last edited:
Status
Not open for further replies.
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |