Trojan downloader Chepvil on the UPSwing – Microsoft Malware protection center

A new spam campaign using UPS (United Parcel Service) as a social-engineering draw was initiated this week.

The spammed message contains an attachment, detected as TrojanDownloader:Win32/Chepvil.I.

The spam campaign actually started around March 16th 2011. The threat was originally detected as Backdoor:Win32/Hostil.gen!A (was Backdoor:Win32/Hostil.F).

More specific signatures (TrojanDownloader:Win32/Chepvil.I and TrojanDownloader:Win32/Chepvil.J) were added on March 22nd 2011.

Encyclopedia entry – Microsoft Security Portal Updated:        Mar 26, 2011        |  Published:        Mar 25, 2011..Click here for more info