DHL Print Label – MALWARE
I recently received the following email:
Hello! The courier company was not able to deliver your parcel by your address. Cause: Error in shipping address. You may pickup the parcel at our post office personaly! Please attention! The shipping label is attached to this e-mail. Print this label to get this package at our post office. Please do not reply to this e-mail, it is an unmonitored mailbox. Thank you, DHL Global Forwarding Services.
There is a file attached DHL_print_label_cef3e.zip, do not open or run this file as it contains malware.
ThreatExpert behavioral analysis:
http://www.threatexpert.com/report.aspx?md5=8960322225b6a842bad87a285f028f5f
Anubis behavioral analysis:
http://anubis.iseclab.org/?action=result&task_id=1eddf69e4a1adce8441a785cef6c52879
See the Web of Trust (WOT) and MalwareURL reports for mmsfoundsystem .ru, a domain to which this malware phones home, and a related domain:
http://www.mywot.com/en/scorecard/mmsfoundsystem.ru
http://www.malwareurl.com/listing.php?domain=mmsfoundsystem.ru
http://www.mywot.com/en/scorecard/mmmserver.ru
http://www.malwareurl.com/listing.php?domain=mmmserver.ru
- 3Monkeys
Popularity: 6% [?]














November 26th, 2011 at 5:37 pm
I do trust all of the ideas you’ve presented to your post. They’re really convincing and will certainly work. Still, the posts are very short for starters. Could you please lengthen them a bit from next time? Thanks for the post.
December 5th, 2011 at 2:25 am
This kind of genuinely clarified our difficulty, thanks!
January 19th, 2012 at 7:42 pm
Are you a laywer?
March 31st, 2012 at 10:09 am
I wanted to thank you for this kind of excellent read!! I definitely enjoying every small bit of it I have you bookmarked to check out new stuff you post
April 22nd, 2012 at 3:16 am
US Store: Online Shop for all products from top brands….
[...]3monkeys » DHL Print Label – MALWARE[...]…
May 9th, 2012 at 12:25 am
Hey I found your site on an unrelated Google search, long time no talk. You use Reddit now that Digg is pretty much extinct? Good to see you’re still blogging!