On July 15, we sent out a Security Advisory including Generic Downloader.ab (MTIS08-131-A).  This covered a Trojan variant that was mass spammed, purporting to be a UPS invoice.  Since then we’ve seen a number of subsequent mass spammings carrying new variants of Spy-Agent.bw, The email message content is similar to the original spam:

———————————-
From: “United Parcel Service”
Subject: [RE] UPS Tracking Number [number]
Body:

Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at our office

Your UPS

Attachment: UPS_INVOICE_[number].zip or invoice_[number].zip
———————————-

Over the past 24 hours we’ve seen other spam runs from “Customs Service” with the attachment “Tax_invoice.zip” as well as “Bill_Tax.zip” attachments from “US Customs Service” and “Rechnung.zip” from “WG: Lastschrift [number]”.  The zip attachments contain .EXE files.  In order for infection to occur users must open the attached ZIP and then choose to run the executables manually.

Product coverage is being updated for new malware variants as necessary and a follow-up security advisory will be sent soon.

These spam runs may continue over the next few days.  Avert Labs reminds readers to practice safe computing, and never to open unexpected email attachments, or follow unexpected URLs; especially from unfamiliar senders.