UPS Phishing Page with Malware
ID: f5d4881b-aa7f-52f2-9710-11dbc047b7e5
STIX ID: report--f5d4881b-aa7f-52f2-9710-11dbc047b7e5
Feed Name: Zscaler Security Research Blog
A fake UPS webpage (http://www.retinamac.ru/UPS/) was used to socially engineer users into downloading a malicious installer (JavaJREInstaller.exe) via popups; the payload drops multiple executables into Temp and Application Data directories and registers one binary to persist at startup. The sample initially evaded most antivirus detections but was later identified by additional vendors; the report highlights this common malware-delivery pattern (fake plugin/codec pages and exploit-kit-style distribution).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
