08 Mar 2011, 13:42
23 Sep 2011, 21:22
"IMPORTANT: Royal Mail Delivery Invoice #1092817" Virus / Trojan
The wording may vary, but this is a PDF exploit currently doing the rounds pretending to be from Royal Mail. Sophos, F-Secure and Avast detect it along with some other products (VT results here) but otherwise detection is patchy.
Subject: IMPORTANT: Royal Mail Delivery Invoice #1092817
From: "Royal Mail" <delivery@royalmail.com>
Date: Wed, April 14, 2010 11:28 am
We missed you, when trying to deliver.
Please view the invoice and contact us with any questions.
We will try to deliver again the following business day.
Royal Mail.
Attachments:
Royal_Mail_Delivery_Invoice_1092817.pdf
Error in the delivery address No27118
Dear customer.
A courier did not deliver the package to your address.
Reason: ncorrect delivery address of the package.
Information about your package is attached to the letter.
Read all information carefully and come to the "Royal Mail" office to receive your package.
Thank you for attention.
Royal Mail Service.
Royal Mail Delivery refuse
Dear customer.
A courier did not deliver the package to your address.
Reason: The package is too large
Information about your package is attached to the letter.
Read all information carefully and come to the "Royal Mail" office to receive your package.
Thank you for using our delivery company.
Royal Mail Service.
Jess wrote:The one I got this week was:-
From:- support_id.3521@royalmail.comDear customer.
A courier did not deliver the package to your address.
Reason: The delivery address is wrong
Please find the attached document containing detailed information about delivery failure.
Read all information carefully and come to the "Royal Mail" office to receive your package.
Thank you.
Australia Post Service.
with attachment :- Delivery_Information#89116.zip
My virus scan says OK, but I wouldn't open it in a month of Sundays.
A customer asked me today about this email, so it must be pretty widespread.
24 Sep 2011, 11:31
26 Sep 2011, 21:10
Dear customer.
A courier did not deliver the package to your address.
Reason: Your address is in the stop-list of the delivery
Information about your package is attached to the letter.
Read all information carefully and come to the "Parcelforce Service" office to receive your package.
Thank you.
Parcelforce Service.
03 Oct 2011, 11:25
Dear customer.
Your package has been returned to the DHL office.
Reason: The delivery address is wrong
Information about your package is attached to the letter.
Read all information carefully and come to the DHL office to receive your package.
Thank you.
Customer service.
19 Oct 2011, 12:47
13 Jun 2012, 17:01
Royal Mail Notification,
We couldn’t deliver your parcel at your address.
Reason:It’s not right specified size and the weight of parcel.
LOCATION:Oklahoma City
STATUS OF YOUR ITEM: sort order
SERVICE: Expedited Shipping
NUMBER OF YOUR PARCEL:U292655027NU
INSURANCE: No
The label of your parcel is enclosed to the letter.
Print your label and show it in the nearest post office of USPS
Information in brief:
If the parcel isn’t received within 30 working days our company will have the right to claim compensation from you for it's keeping in the amount of $21.48 for each day of keeping over limited time.
You can find the information about the procedure and conditions of parcels keeping in the nearest office.
Thank you for attention.
Royal Mail Customer Services.
20 Aug 2012, 20:58
TrueBlueTerrier wrote: http://nakedsecurity.sophos.com/2012/08 ... l-malware/
It's wise to be wary when it comes to unsolicited email, even when the email appears to come from a legitimate organisation.
Today we're warning internet users to be careful not to be tricked into open attachments that have been spammed out, posing as communication from the British Royal Mail.
A typical email reads:
Royal Mail Group Shipment Advisory
The following 1 piece(s) have been sent via Royal Mail on Mon, 20 Aug 2012 15:43:14 +0530, REF# 5646597645
SHIPMENT CONTENTS: Documents
SHIPPER REFERENCE: PLEASE REFER TO ATTACHED FILE
ADDITIONAL MESSAGE FROM SHIPPER: PLEASE REFER TO ATTACHED FILE
Royal Mail Group Ltd 2012. All rights reserved
It should go without saying that the emails are not connected with the real Royal Mail in anyway, despite them appearing to arrive from noreply@royalmail.com and containing the Royal Mail's logo.
The cybercriminals who have distributed the attack are hoping that your curiousity will be piqued, and you will be tempted to open the attached ZIP file in the mistaken belief that a parcel is winging its way to you.
Contained within, however, is not a Royal Mail shipping advisory but a file called royal_mail_shipping.exe, detected by Sophos as the Troj/Backdr-HE Trojan horse.
The technique of disguising a malware attack as an email from a delivery company is nothing new, of course. Many internet users will be aware of the attacks we have seen in the past that have pretended to come from the likes of DHL, FedEx and USPS for example.
Chances are that a malware attack that is less likely to be as successful as those which abuse the name of global delivery companies, but there is always the danger that some people will click without thinking and have their computers infected as a result.
28 Jan 2013, 21:40
29 Jan 2013, 12:52
18 Feb 2013, 10:01
27 Aug 2013, 14:45
28 Feb 2014, 10:26
28 Feb 2014, 10:28
Notification
Our company’s courier couldn’t make the delivery of package.
REASON: Postal code contains an error.
LOCATION OF YOUR PARCEL: London
DELIVERY STATUS: sort order
SERVICE: One-day Shipping
NUMBER OF YOUR PARCEL: WZGMNKR97Z
FEATURES: No
Label is enclosed to the letter.
Print a label and show it at your post office.
An additional information:
If the parcel isn’t received within 30 working days our company will have the right to claim compensation from you for it’s keeping in the amount of $9.26 for each day of keeping of it.
You can find the information about the procedure and conditions of parcels keeping in the nearest office.
Thank you for using our services.
DHL Global.
--------------------------------------------------------------------------------
Viruses found in the attached files
DHL-88921772-9200-9173.zip: Virus found FakeAlert
15 Jun 2015, 13:27