Online Connections News

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 27 November 2012

Alert: Malware FedEx Shipment Notification from reveals a number of bugs in Windows 8 and/or Outlook 2010.

Posted on 19:45 by Unknown

NOTE: If you receive an email from FedEx with an attachment treat the email as malware. In this case the email did have malware attached. But to my surprise, as part of my reviewing the malware attachment I found a number of issues with Windows 8 and/or Outlook 2010 which to me are just as important.

The investigation of the malware received via email with the subject “FedEx Shipment Notification” started off in the same way as usual. When I see multiple emails sent to my email addresses I let others know via my blog. New malware is rarely handled by antivirus software so it represents an exposure for clients.

Using Windows 8/Outlook 2010 I saved the file to a folder on my desktop. The structure of the attachment is typical of malware. A file which looks like a potentially harmless file (in this case a PDF) but with the extension exe which means it is actually a program and usually malicious.

I then submitted the file for analysis and it was not identified as malware. That was strange. I then attempted to extract the contents of the zip file which failed. Again strange. But I just assumed this was a poorly formed file and the author of the email/malware had not created a correctly structure file. I’ve seen this before. But something didn’t feel right. More emails arrived so I decided to investigate further.

I pulled out my Windows XP computer running Outlook 2007 and performed the same steps. This time the attachment was reported as malware and I could extract the contents of the zip file. Windows 8 was for some reason failing to save the file correctly. In one way that is good because the file is thus corrupted and can’t be used to infect the user’s computer. But bad in that Windows 8 is not operating as expected. (It appears the zip file has been created as a multi-volume archive which fails in Windows 8 but is acceptable in Windows XP.)

In addition, when saving the file the first time, as expected for a new file, I wasn’t prompted after I pressed the Save button. But then I went to save the file a second time to replace the file I had already saved and there was no warning the file existed. On the Windows XP computer saving over an existing file gave the prompt asking if I wanted to overwrite the existing file.

I created a new file in Windows 8 with the filename the same as the malware (“Tracking_results_as_of_Nov28.pdf.zip”) but with my own content and sent the file to myself via email. I saved once and as expected no prompt. I save a second time and there was no prompt to overwrite the existing file.

To me this is a real concern. Potentially if a file has a certain name users may inadvertently overwrite an existing file without warning and that is not good. I did some testing and don’t yet know which filenames will overwrite without warning so at this stage all I can do is warn people to be careful when saving a file to your computer. At this stage I’ve only found the problem to occur when saving from Outlook 2010.

In summary;

- The FedEx Shipment Notification I received and currently being sent via email does contain attached malware.
- Under Windows 8 the attached file does not open and appears corrupted but does open correctly under Windows 8. This raises the question as to why files can be extracted under Windows XP but not under Windows 8.
- When saving the file from Outlook 2010/Windows 8 the file can be saved twice with no warning to overwrite. This raises the question as to whether other files can be overwritten without warning.

Recommendations:

- Delete any suspicious FedEx Shipment Notifications with suspicious attachments.
- If you received a legitimate zip file but it appears to be corrupt under Windows 8, forward the email to a Windows XP computer and try extracting the contents on the Windows XP computer.
- When saving a file from Outlook 2010/Windows 8 double check to see if a file with the same name already exists. As a precaution you can save the file to a new folder.

Kelvin Eldridge
www.OnlineConnections.com.au
Call 0415 910 703 if you have a computer related problem.
Servicing Templestowe, Doncaster, Eltham and the surrounding area.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • MyAnswers: How I saved a family member $500 on a Dell computer after the special had finished.
    The following MyAnswers solution 2409 is now available: Saved $500 for a family member who wanted a Dell computer but the special had finish...
  • It you're a software developer and thinking about developing an app keep these figures in mind.
    I've heard a couple of unconfirmed figures in terms of the sales of apps.   1. The top 20 apps represent 50% of app purchase...
  • Office 2013 Home & Business locked to computer it is installed on.
    Microsoft is certainly making changes to push people to their subscription pricing. Previous versions of Office when purchased retail, could...
  • Adobe Flash Player 11.6 update Chromes users
    One of the things I constantly find when assisting clients is they've installed software they don't want or need and they don't ...
  • Petrol Calculator - Calculate the cost of petrol for a given distance.
    The Petrol Cost Calculator is now available at http://www.petrolcostcalculator.com.au/ . Use the calculator to determine the cost of petro...
  • Why has Microsoft crippled the Windows Surface RT tablet?
    I kept thinking today, when something doesn’t quite make sense there is a hidden reason I’m not seeing. I was thinking about Microsoft’s Win...
  • MyAnswers: Does the PayPal Here credit card scanner work with the Apple iPhone 3GS?
    The following MyAnswers solution 2239 is now available: Does the PayPal Here credit card scanner work with the Apple iPhone 3GS? Click here ...
  • Chrome Firefox market share on Windows
    Based on my site log, Chrome has now overtaken Firefox to be the second most popular browser for Windows users in Australia. This isn't ...
  • In the site log for one of my sites today I noticed Google image robot (Googlebot-Image/1.0) trying to access images that aren't even on my site.
    I recently set up the site www.PetrolCostCalculator.com.au as a calculator for others to access and determine the cost of petrol for a give...
  • Alert: Qantas Booking reference 47648830 - Seat Select Fee Receipt
    Over the last hour I've received five fake Qantas emails for seat selection fee receipts. The booking reference number changes a...

Blog Archive

  • ►  2013 (251)
    • ►  December (6)
    • ►  November (18)
    • ►  October (6)
    • ►  September (25)
    • ►  August (22)
    • ►  July (27)
    • ►  June (18)
    • ►  May (21)
    • ►  April (23)
    • ►  March (25)
    • ►  February (41)
    • ►  January (19)
  • ▼  2012 (201)
    • ►  December (29)
    • ▼  November (29)
      • Microsoft Surface with Windows Pro release date an...
      • Internet Explorer 10 - The preferred Australian En...
      • Origin 25% (25 per cent) off Gas & Electricity offer
      • Windows 8 tip number 1 - The Start Screen
      • MyAnswers: How to remove your credit card details ...
      • Alert: Jetstar Flight Itinerary - Your Itinerary i...
      • Alert: Malware FedEx Shipment Notification from re...
      • Alert: PayPal Balance Summary - Notification of pa...
      • Alert: Vodafone PXT (picture message)
      • Apple Australia one day sale.
      • Microsoft's attempt to lock people into their serv...
      • MyAnswers: PDF icons go black on Windows 8 Desktop
      • Is it the beginning of the end for OpenOffice?
      • New site for The Preferred Australian English spel...
      • MyAnswers: Free eBooks for Android, PC and Apple i...
      • MyAnswers: How to save a PDF in Internet Exploer 1...
      • Skype free unlimited worldwide telephone calls for...
      • MyAnswers: Problem Ejecting USB Mass Storage Devic...
      • MyAnswers: How do I scan a file for malware under ...
      • Alert: Telstra - You have received a new message
      • ASUS Nexus 7 32GB tablet now available in Australia
      • Has Apple made a mistake with the iPad Mini?
      • MyAnswers: Windows 8 Mail won't work unless I have...
      • MyAnswers: WordPress blog infected and cleaned, bu...
      • MyAnswers: Add Notepad to the Send To context menu...
      • MyAnswers: Windows 8/IE10. Script Error. An error ...
      • MyAnswers: How to resend an email in Outlook 2010.
      • MyAnswers: How I removed System Progressive Protec...
      • MyAnswers: Windows Media Center not included in Wi...
    • ►  October (19)
    • ►  September (21)
    • ►  August (7)
    • ►  July (18)
    • ►  June (13)
    • ►  May (10)
    • ►  April (18)
    • ►  March (19)
    • ►  February (16)
    • ►  January (2)
  • ►  2011 (48)
    • ►  December (5)
    • ►  November (7)
    • ►  October (24)
    • ►  September (12)
Powered by Blogger.

About Me

Unknown
View my complete profile