IT Security Blog

22 August 2008

Fake FedEx Email Borne Malware Alert


Over the last 24 hours we have seen a large influx of a new email borne malware campaign alleging to be a notification of non-delivery from FedEx.  
The email alleges that you sent a package on July 25, but because the recipient's address was not correct when it was shipped it had not been delivered.  It then asks the user to print out a copy of the attached invoice (a .zip file which contains malware) and to collect a copy of the package at the FedEx Office (address of office not given, which should be one clear indicator that something is fishy about the email).

Sample subject lines that we have seen in our Threat Operations Center include:

You Have A Package!!!
Tracking N <fake tracking number>

Volumes have been pretty high as we have seen over 21M of these fakes hit our systems within the last 24 hours, accounting for about 80% of all of the email borne malware that we have seen over that same period.

It's times like this that we are reminded that although many of the large scale malware campaigns that we now see are hosted on infected web sites, static malware distributed over email is still an active, viable tactic being employed by cyber criminals.

Posted by smasiello at 10:37 AM | Link | 11 comments
Re: Fake FedEx Email Borne Malware Alert
I've received a fraud Email using your name. Please sdvise where to Email the copy. My home phone #(520) 573-6580. Please advise.
Posted by Jacob Tedla on September 14, 2008 at 10:21 AM

Re: Fake FedEx Email Borne Malware Alert
I have received a fake email, where could I forward it to you so you could investigate it. It hurts the company name. This has got to be mail fraud!!!
Posted by Mark Braun on November 10, 2008 at 4:28 PM

Re: Fake FedEx Email Borne Malware Alert
I received the following email, where can i send it to be investigated.
Greetings!

I have been waiting for you to contact me as regards your Bank Draft of
$800.000.00 United States Dollars, Donated by World Foundation to you, but I
did not hear from you. so I went and deposited the Draft
with FedEx COURIER SERVICE, West Africa, I traveled out of the country for
a 3Months Course. For your information, I have paid for the delivery
Charge.The only money you will send to the FedEx WEST AFRICA COURIER SERVICE
to deliver your Draft direct to your postal Address in your country is
($180.00USD) only, being Security Keeping Fee of the Courier Company so
far. .You have to contact the FedEx COURIER SERVICE now for the delivery of
your Draft with this information bellow.

Contact Person: Mr. Paul Harrison
Email Address:fedex_delivery_235@live.com
Telephone: +2348069352086

Finally, make sure that you confirm your Postal address,
Direct telephone
number.

Yours Faithfully,
Mr Leonard Jefferson
Posted by michael steiner on November 24, 2008 at 2:09 AM

Re: Fake FedEx Email Borne Malware Alert
This is a message I recieved Today

Return-Path:
Received: from mx08.vgs.untd.com (mx08.vgs.untd.com [10.181.44.38])
by maildeliver02.dca.untd.com with SMTP id AABEW8BJ4A5DV2P2
for (sender );
Sun, 21 Dec 2008 19:10:19 -0800 (PST)
Received: from sur.dicle.edu.tr (www.dicle.edu.tr [193.140.240.3])
by mx08.vgs.untd.com with SMTP id AABEW8BJ4AB5YYUS
(sender );
Sun, 21 Dec 2008 19:10:18 -0800 (PST)
Received: from www.dicle.edu.tr (localhost.localdomain [127.0.0.1])
by sur.dicle.edu.tr (8.12.5/8.12.5) with ESMTP id mBM2kWSK009270;
Mon, 22 Dec 2008 04:46:32 +0200
Received: from 72.52.66.10
(SquirrelMail authenticated user yakgun)
by www.dicle.edu.tr with HTTP;
Mon, 22 Dec 2008 10:46:34 +0800 (HKT)
Message-ID: <2be84bdafd730ba6a9674efe65941fc0.squirrel@www.dicle.edu.tr>
Date: Mon, 22 Dec 2008 10:46:34 +0800 (HKT)
Subject: Dear: Beneficiary
From: "=?iso-8859-9?Q?=A9FedEx_Online_Management_Team.?="
Reply-To: fedexcouriersservices_plc@hotmail.com
User-Agent: SquirrelMail/1.4.15
MIME-Version: 1.0
Content-Type: text/plain;charset=iso-8859-9
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
Importance: Normal
To: Undisclosed-recipients:;
X-ContentStamp: 16:8:501423447
X-MAIL-INFO:4c05ed3871717159ec599cec251ce855e9785dd57d259cac79097db16cdde5652965e9082111198dbd
X-UNTD-Peer-Info: 193.140.240.3|www.dicle.edu.tr|sur.dicle.edu.tr|idealtas1955@yahoo.com
X-UNTD-UBE:-1
X-Antivirus: AVG for E-mail 7.5.552 [270.9.19/1853]

----- Original Message -----
From: "©FedEx Online Management Team."
To:
Sent: Sunday, December 21, 2008 8:46 PM
Subject: Dear: Beneficiary


>
>
>
> Dear: Beneficiary
>
>
> Courage my dear, I know you will be waiting for the arrival of
> yourConsignment containing the total amount of your ( 1 ,1000,000.00 )
> cash payment compensation which was sent to you and later returned back
> due to wrong address provided, I think there is a mistake in the address
> giving to me and that has cost me a lot of strength,thank God that it
> returned back safely. The only thing left for you to do now is to contact
> ( FedEx Courier Express Company) this is the company in charge of
> delivering your consignment box containing the ($ 1,000,000.00 ) Again let
> me repeat.
>
>
> Contact Person: Mr.Robert Bethel ( Delivery Department Managing Director )
>
> E-mail :(fedexcouriersservices_plc@hotmail.com).
> Telephone: +234-802-262-8690
>
>
>
> For the purpose of clarification, It is advised that the entire fee has
> been paid for the delivery so all that you will have to pay is only $105
> dollar that you will have to send to their security office as charges for
> the safe keeping fee of your returning box.Please do not be deceived by
> anyone and be advised to reconfirm.
>
>
> YOUR COUNTRY................
> YOUR FULL NAME..............
> HOME ADDRESS.................
> MOBILE PHONE NUMBER...........
> OFFICE NUMBER........................
> HOME NUMBER........
> AGE...........
> SEX...........
>
>
> In addition to what I said earlier,please do not dispose the content of
> the box to them to avoid delay and finally endeavor to indicate this CODE
> N°(GL-14160) This is the box code and it shows that you are the rightful
> owner of the box deposited in their company,you will use it as your
> subject when contacting them.
>
>
> After sending the security keeping fee ask them to give you the tracking
> number to enable you track your package over there and know when it will
> get to your address. Let me repeat again,Try to contact them as soon as
> you receive this mail and ask them how you will make the security fee of
> $105 usd to them to avoid any further delay and remember to pay them their
> Security Keeping fee of $105 US Dollars for their immediate action.
>
>
>
> Yours Faithfully,
> Mrs. Margaret Blaire.
> ©FedEx Online Management Team.
> All rights reserved. © 1995-2008 FedEx
>
>
>
Posted by Lyman E. Bertsch on December 21, 2008 at 8:54 PM

Re: Fake FedEx Email Borne Malware Alert
FEDERAL EXPRESS (FedEx), WEST AFRICA
DELTA STATE, NIGERIA. Attn: Jamie Mccormick , Good day to you and thanks for the mail.But i want you to no that you have no problem with your package because our dispatch officer will be delivering your draft to you and is going to follow you down to your bank to deposit it with you, that we are assuring you.

But before this can commence you have to pay for the Security Keeping Fee charges which you are expected to pay before we can deliver your draft to you.Without that we can not take delivery of your draft to you.

You are welcome to FedEx West Africa. In respect to your mail which indicates for the release of your package, Mr. Wellington told me he was going to contact you regarding the package he dropped with you at our branch office here in West Africa . The package which inside it is a check of $800.000.00 United States Dollars is right here on my desk waiting for it to be dispatched.

You can as well come down to this branch to pick up your package or even send someone to pick it up on your behalf. Mr. Wellington came to our branch office last week to place your check on out going 24Hours delivery; he has already paid for the insurance fee and the delivery charges. But he did not pay for the security keeping fee which serves as demurrage due to the fact that we did not know when you will be contacting us via mail or phone to inform us that we have your enveloped type package in which the check is included, so we advised him not to pay for the security keeping fee of the package to the company yet but we informed him to contact you on time so you will not have to pay more than ($215.00 USD) US Dollars on demurage. Please we do not operate COD (Cash-On-Delivery) on this type of fee. (This serves as the demurrage fee) All you need to do right now to get your enveloped type package in which the check is included delivered to your door step is to go ahead and pay the security keeping fee of the company so far, the fee is ($215.00 USD) US Dollars only; you are to come up with this fee as to process the delivery of your package for immediate dispatch. Once you make the payment of the security keeping fee, I shall send to you the Scan Copy of the Airway Bill and the package order number as well as the package tracking number in which you can use to check your package status at the FedEx branch nearest to you and also on our website online. Payment should be made via western union money transfer only for security purpose in our accounting officers name. The payment details are listed below. Name: DICKSON SAMUELAddress: #105 Bola Johnson RoadDelta State,Nigeria .
Text Question: BlackText Answer: White Once you make the payment you are required to send the following for the final processing of the package airway bill and tracking number. Name of Sender as it appears on the Western Union receipt:Address of Sender as it appears on the Western Union receipt:Amount Sent as it appears on the Western Union receipt:The MTCN (Money Transfer Control Number) as it appears on the Western Union receipt:Test Question as it appears on the Western Union receipt:Test Answer as it appears on the Western Union receipt:Name of Receiver as it appears on the Western Union receipt:Your Phone Number: Get back to me with the information requested above, So that your package can be released for dispatch. Note that your tracking number and the scan copy of the airway bill would be provided to you as soon as the payment has been confirmed by us. Have a wonderful time. Please call me anytime you need any assistance.+2348082438640 Regards.Mr. JOHN MARTINSSenior Dispatch Director

is it bull sh-t or what?
Posted by jamiE on January 19, 2009 at 5:49 PM

Re: Fake FedEx Email Borne Malware Alert
I received this, thought you should know.

Date: Wed 18 Mar 12:35:13 CDT 2009
From: "Fedex Courrier Company" Add To Address Book | This is Spam
To: undisclosed-recipients:;

CONFIRM OWNERSHIP (PARCEL)

Dear Customer!
We have been waiting for you to contact us for your Confirmable Package
that is registered with us for shipping to your residential location. We had
thought that your sender gave you our contact details. It may interest you to
note that a letterer is also added to your package. However, we can not quote
its content to you via email for Privacy reasons we understand that the
content of your package itself is a Bank Draft which worth over
$500,000.00.usd As you know,FedEx do not ship money in CASH or in CHEQUES but
Bank Drafts are shippable.The package is registered with us for mailing by
your colleague, and your colleague explained that he is from the United
States but he is here in Nigeria for three (3) months Surveying Project as he
works with a construction firm in the Nigeria West Africa region, We are
sending you this email because your package is been registered on a Special
Order.What you have to do now, is to contact our Delivery Department for
immediate dispatch of your package to your residential address.Note that as
soon as our Delivery Team confirms your information's will take only one
working day (24 hours) for yourpackage to arrive its designated address.For
your information, the VAT & Shipping charges as well as Insurance fees have

been paid by your colleague Mr.James Smith before your package was
registered. Note that the payment that is made on the Insurance,Premium &
Clearance Certificates, you are to certify that the Bank Draft is not a Drug
AffiliatedFund (DAF) neither is it funds to sponsorTerrorism in your country.
This will help you avoid any form of query from the Monetary Authority of
your country. How ever, you will have to pay a sum of $200.00 USD to the
FedEx Delivery Department being full payment for the Security Keeping Fee of
the FedEx Company as stated in our privacy terms & condition page. Also be
informed that your colleague Mr.James Smith wished to pay for the Security
Keeping charges, but we do not accept such payment considering the facts that
all items & packages that is registered with us having a time limitation and
we cannot accept payment having known not when you will be picking up the
package or even responding to us.Kindly contact the delivery department
(FedEx Delivery Office) with the details given below: FedEx Delivery Office
Contact Person:

Mr. Robert Schoonheydt
Tel: +234-7033-244-726
Email:fedex_customerd@8u8.com

Kindly complete the below form and send it to the email address given above.

FULL NAMES:...
TELEPHONE:..
POSTAL ADDRESS:..
CITY:..
STATE:..
COUNTRY:..

Kindly complete the above form and summit it to the delivery manager on:
department_fedexdelivery@yahoo.com.hk As soon as your details are received,
our delivery team will give you the necessary payment procedure so that you
can effect the payment for the Security Keeping Fees.

Yours Faithfully,
Mrs Victoria Wallison
FedEx Online Team Management
All rights reserved. © 1995-2009 FedEx.
Posted by watts on March 22, 2009 at 8:27 AM

Re: Fake FedEx Email Borne Malware Alert
I of course had received this email just a few days after I had sent a large check to my bank for an in-mail deposit. It was the only time in my life that I ever had done such a thing and the only time in my life I ever received an email like this. I remember having a huge heart attack, seriously, what are the chances of those two events happening so close together (ultimately my check got to my bank fine, thankfully, but boy was I freaked out).
Posted by Jeff on April 17, 2009 at 9:45 PM

Re: Fake FedEx Email Borne Malware Alert
Dear Recipient,

I am Barr. Cole Williams Chief Operations Officer to FedEx Courier Express
Service. We just concluded our java script random email selection promo for
this quarter and your E-mail ID has been picked as our of the finalist in the
5th category.

Due to the fact that we do not know if your email ID is still active or has
been short down or even blocked, much details are not given in this email
notification resultant to the fact that the email addresses are selected
randomly by our java script programming machine. You are required to confirm
your E-mail ID by sending your response to the email address below.

SECURITY INFO: You are advised to keep your winning information completely
personal for security reasons to avoid any kind of impersonation or double
claim. We have handled such cases before so please be warned.

Regards
Barr. Cole Williams
Chief Operations Officer to FedEx Courier Express Service
Monomarks House, 27 Old Gloucester Street,
London WC1N 3AX United Kingdom.
Telephone :+447011150149
Fax : +44-0872 115 6551
: +44-0872 115 6552
E-mail: barrcolewilliams@aol.co.uk

This E-MAIL is protected by copyright and trademark laws under UK and
International law. All rights reserved. © 1995-2009 FedEx
Posted by mboyd on July 27, 2009 at 1:37 AM

Re: Fake FedEx Email Borne Malware Alert
Thank you for contacting FedEx. We appreciate your taking the time to send
us this information.

Here are tips on how to recognize a fraudulent e-mail:
-- The e-mail asks for your personal information or a payment. FedEx does
not request personal information or payments via unsolicited mail or e-mail
for goods being shipped or held.
-- The e-mail claims to be from FedEx regarding a package that could not be
delivered. These e-mails ask you to open an attachment to obtain the
airbill or invoice for picking up the package. FedEx tracking updates for
undeliverable packages do not include attachments. The attachment
contained in this type of e-mail activates a virus. DO NOT OPEN the
attachment. Instead, delete the e-mail immediately.

Fraudulent e-mails are the unauthorized actions of third parties not
associated with FedEx. You can help us make your online experience with
FedEx safe and efficient by reporting suspicious e-mails.

The following types of e-mails will be routed to our fraudulent e-mail unit:
-- Unsolicited e-mails that claim to come from FedEx.
-- E-mails that include attachments.
-- E-mails requesting your personal information.
-- E-mails that request a payment.
-- E-mails that misuse the FedEx logo.

Please note that questions about rates, package tracking and other FedEx
service related questions submitted to abuse@fedex.com will not be reviewed
or receive a response. Please direct service related questions to
customerservice@fedex.com or FedEx Customer Service by calling
1.800.GoFedEx 1.800.463.3339.
Posted by mboyd on July 27, 2009 at 1:39 AM

Re: Fake FedEx Email Borne Malware Alert
DATE: 08th November 2009.

Dear Customer,
We have been waiting for you to contact us for your Package that is been
registered with us for shipping to your residential location. The content of
your parcel includes a Bank Draft worth of $800,000 (Eight Hundred Thousand US
Dollars).
You are required to send us your Complete Name, Country, Address and Phone for
confirmation purposes so that we can commence with the delivery of
your parcel.
You are to send the information to: Mr. Richard Raynor (FedEx Ship Manager) E-
mail Address: fedex.nig_4@live.com, Tel: +2348071208793.
Yours faithfully,
Mrs. .Mary Maxwell
FedEx Management Team.
All rights reserved. © 1996-2009 FedEx
Posted by nathan stewart on November 8, 2009 at 6:26 PM

Re: Fake FedEx Email Borne Malware Alert
i had the above email today and im getting sick of them, i also have a foren number that keeps ringing me whilst i am at work. is there any way of getting them stopped ?
Posted by nathan stewart on November 8, 2009 at 6:28 PM

Commenting has been disabled for this entry.