Subject: Western Union Transfer MTCN: 2474153681In this case there was an attachment called Invoice_8773.zip containing a file named Invoice_8773.exe. Because of the really stupid way that Windows (by default) hides the file extensions and the fact that the bad guys have given this executable a convincing icon, it will look something like this when unzipped:
From: "Western Union Support Team" firstname.lastname@example.org
Date: Tue, May 12, 2009 11:00 pm
The money transfer you have sent on the 22nd of April was not collected by the
According to the Western Union contract the transfers which are not received in 15
days are to be returned to sender.
To collect cash you need to print the invoice attached to this email and visit the
nearest Western Union agency.
VirusTotal identifies is as a variant of Zbot, the ThreatExpert prognosis has more details in case you are trying to clean it up.
If you can block EXE-in-ZIP files at your mail perimeter, then that is always the best defence against this kind of attack.