<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>#FedEx &#8211; Startupware: Managing Startups</title>
	<atom:link href="https://www.startupware.com/tag/fedex/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.startupware.com</link>
	<description>Autorunning Software &#38; Running a Software Business</description>
	<lastBuildDate>Thu, 12 Mar 2020 20:30:48 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
	<item>
		<title>Careful again: FedEx Doesn&#8217;t Leave Your Package at the Post Office</title>
		<link>https://www.startupware.com/field-reports/careful-again-fedex-doesnt-leave-your-package-at-the-uspse/</link>
		
		<dc:creator><![CDATA[Jerry Stern]]></dc:creator>
		<pubDate>Tue, 03 Sep 2013 13:26:54 +0000</pubDate>
				<category><![CDATA[Field Reports]]></category>
		<category><![CDATA[#FedEx]]></category>
		<category><![CDATA[#malware]]></category>
		<guid isPermaLink="false">https://www.startupware.com/?p=1137</guid>

					<description><![CDATA[<p>Here&#8217;s another sample of what&#8217;s not safe to open. Again, the clues are clear, if you&#8217;re careful before you click: There are punctuation and grammar errors in the message. The link that you&#8217;ll see when floating the mouse over that &#8216;Print Label&#8217; link doesn&#8217;t match the &#8216;from&#8217; domain, and isn&#8217;t Fedex.com. European date format used &#8230; <a href="https://www.startupware.com/field-reports/careful-again-fedex-doesnt-leave-your-package-at-the-uspse/" class="more-link">Continue reading <span class="screen-reader-text">Careful again: FedEx Doesn&#8217;t Leave Your Package at the Post Office</span> <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a rel="nofollow" href="https://www.startupware.com/field-reports/careful-again-fedex-doesnt-leave-your-package-at-the-uspse/">Careful again: FedEx Doesn&#8217;t Leave Your Package at the Post Office</a> appeared first on Startupware.com. Visit to read more about software design, malware, and computer security.</p>
]]></description>
										<content:encoded><![CDATA[<p>Here&#8217;s another sample of what&#8217;s not safe to open.<br />
Again, the clues are clear, if you&#8217;re careful before you click:<br />
<img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-1139" src="//www.startupware.com/wp-content/uploads/2013/09/Fake-Fedex.png" alt="Fake FedEx notice" width="524" height="382" srcset="https://www.startupware.com/wp-content/uploads/2013/09/Fake-Fedex.png 524w, https://www.startupware.com/wp-content/uploads/2013/09/Fake-Fedex-300x218.png 300w" sizes="(max-width: 524px) 100vw, 524px" /></p>
<ul>
<li>There are punctuation and grammar errors in the message.</li>
<li>The link that you&#8217;ll see when floating the mouse over that &#8216;Print Label&#8217; link doesn&#8217;t match the &#8216;from&#8217; domain, and isn&#8217;t Fedex.com.</li>
<li>European date format used by a US-based company.</li>
<li>The logo is a bad jagged paste, and is missing the circle-R symbol for &#8216;registered trademark&#8217;.</li>
<li>FedEx has no pickup service at their competitor, the &#8220;nearest&#8221; US Post Office.</li>
</ul>
<p><span id="more-1137"></span></p>
<p>Now, that&#8217;s already enough information to make me delete the email, but I&#8217;ll look a little deeper:</p>
<p>I downloaded the &#8220;label&#8221; to look&#8211;it was &#8220;Shipping_Label_US_Westminster.zip&#8221; and it held one file, &#8220;Shipping_Label_US_Westminster.exe&#8221;.</p>
<p>The antivirus I&#8217;m running didn&#8217;t object to either file; it probably can&#8217;t detect today&#8217;s variation yet.</p>
<p>I looked inside that file with an extraction program, and found a .rsrc folder, and files .text, .rdata, .data. Inside the folder there were two .ico files, basically desktop icons.</p>
<p>That&#8217;s enough to tell me that it appears to be a script to install software. It&#8217;s clearly not a label&#8211;that would be a PDF or a JPG image.</p>
<p>IMO, the most-likely payload would be a rogue/fake security program, either scare-ware or blackmail-ware. The message itself isn&#8217;t infectious, just don&#8217;t click that link.</p>
<p><a href="https://sciencetranslations.com" target="_blank" rel="author noopener noreferrer">Jerry Stern</a> is webmaster at <a title="PC410.com" href="http://www.pc410.com" target="_blank" rel="noopener">PC410.com</a> and <a title="Startupware.com" href="//www.Startupware.com">Startupware.com</a>.</p>
<p>The post <a rel="nofollow" href="https://www.startupware.com/field-reports/careful-again-fedex-doesnt-leave-your-package-at-the-uspse/">Careful again: FedEx Doesn&#8217;t Leave Your Package at the Post Office</a> appeared first on Startupware.com. Visit to read more about software design, malware, and computer security.</p>
<p>Original article: <a href="https://www.startupware.com/field-reports/careful-again-fedex-doesnt-leave-your-package-at-the-uspse/">Careful again: FedEx Doesn&#8217;t Leave Your Package at the Post Office</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
