We are currently seeing a large number of malicious emails purporting to be sent from FedEx or DHL, but containing attachments designed to infect your computer.
It’s a familiar story. In the case of the malware attached to the emails coming from DHL, the communication claims that there has been an error in the delivery address, and so you are invited to pick up the parcel “at our post office personaly” (spelling has often been the downfall for would-be hackers).
If the poor spelling doesn’t set your alarm bells ringing then you might be foolish enough to open the attached shipping label (we have seen examples where this can be called DHL_print_label_75ba9.zip or DHL_print_label_9731b.zip)
Sophos detects the attached malware as Troj/BredoZp-A or Mal/Bredo-A.
On the SophosLabs blog, Prashant has…
Read more in my article on the Naked Security website.
Found this article interesting? Follow Graham Cluley on Twitter or Mastodon to read more of the exclusive content we post.