Services Partners Contact About Help Support Blog Login

Presidents Blog


Responding to UPS pattern SPAM
Posted: 12:04 pm
July 22nd, 2008
Post a comment
ExchangeDefender

It has been quite an evening at ExchangeDefender as we continue to fight the outbreak of the UPS trojan. You may have seen this:

Warning: This message has had one or more attachments removed

Warning: (UPS_INVOICE_978172.exe, UPS_INVOICE_978172.zip).

Warning: Please read the “ExchangeDefender-Attachment-Warning.txt” attachment(s) for more information.

Subject: UPS Tracking Number 6431834482

Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office

Your UPS

What is interesting about this is that the message does look fraudulent to the casual observers and people that do domestic business with UPS. However, we have encountered this format (with attachments and all) being used by UPS Commercial shipping departments in the past, which is why messages with the specific patterns received lower SPAM scores and were allowed through.

We still stripped the attachments but the attachments inside the ZIP file are passing through AV scanners as the variants change. We are now up to over thirty definitions used to track this specific worm and have taken the following steps:

UPS messages are only processed if they come from UPS.

UPS Tracking numbers are only accepted as valid if they start with 1Z.

UPS messages instigate a callback function against UPS servers.

Dealing with these extended rulesets and checks has made mail move a little slower today as we’ve dealt with onslaught of messages while this worm becomes more prevalent. UPS is also issuing a warning on their behalf:

brownbulletin

We currently have this issue under control and it should not pose any further problems. However, expect the UPS messages to be taken with higher scrutiny and always warn users not to open executable attachments.

Own Web Now Blog

Own Web Now Corp blog is written by our staff to communicate with you, our customer, on the latest developments and events in our business and get feedback on how we're working for you.


News & Events

The best way to stay in touch with us is through our blog, but from time to time we do special things that we feel you might find interesting. Check them out!

July 17, 2008
OWN Partner Call 5
Dana Epp talks about a new security solution offering for SMB.

Alternative content



July 11, 2008
OWN Partner Call 4
Matt Makowicz talks about maturity of the partner business at WPC.

Alternative content