More online fraud. Â Here is a fake fedex email that attempts to deliver you an attachment with malware. Â If you get the email do NOT open the attachment and do NOT respond.
FedEx International Ground <clifford.barron@cio.posluh.hr>
Dear UserName,
Your parcel has arrived at March 14. Courier was unable to deliver the parcel to you.
You can review complete details of your order in the find attached.
Yours trully,
Clifford Barron,
FedEx Station Agent.
The attachment has the following malware:
| Antivirus | Result | Update |
|---|---|---|
| Microsoft | TrojanDownloader:JS/Nemucod.P | 20150405 |
| NANO-Antivirus | Trojan.Script.Heuristic-js.iacgm | 20150405 |
| Kaspersky | Trojan-Downloader.JS.Agent.hdu | 20150405 |
| Sophos | Troj/Dloadr-DXL | 20150405 |
| AVware | Malware.JS.Generic (JS) | 20150405 |
| VIPRE | Malware.JS.Generic (JS) | 20150405 |
| Emsisoft | JS:Trojan.Crypt.NI (B) | 20150405 |
| ALYac | JS:Trojan.Crypt.NI | 20150405 |
| Ad-Aware | JS:Trojan.Crypt.NI | 20150405 |
| BitDefender | JS:Trojan.Crypt.NI | 20150405 |
| F-Secure | JS:Trojan.Crypt.NI | 20150405 |
| GData | JS:Trojan.Crypt.NI | 20150405 |
| MicroWorld-eScan | JS:Trojan.Crypt.NI | 20150405 |
| nProtect | JS:Trojan.Crypt.NI | 20150404 |
| Avast | JS:Decode-CAC [Trj] | 20150405 |
| ESET-NOD32 | JS/TrojanDownloader.Nemucod.AF | 20150405 |
| Fortinet | JS/Nemucod.AF!tr | 20150405 |
| McAfee | JS/Downloader.gen.d | 20150405 |
| McAfee-GW-Edition | JS/Downloader.gen.d | 20150405 |
| CAT-QuickHeal | JS.Downloader.B | 20150404 |
| Comodo | Heur.Dual.Extensions | 20150405 |
| AVG | FakeAlert | 20150405 |