Products & Services
Support How to Buy

For Home

Cisco Home Products Store
Products for everyone

Flip Video Store
Meet the Flip Family:
Life now has a play button

All Ordering Options

Training & Events Partners

Find a Partner

Cisco Partners help you find the right solution for your Business

Become a Partner

Enhance your company's value-add, expertise and opportunities

Small Business Partners

Log in to get sales resources.

Already a Partner?

Log in for resources.

Register as a New User

Visit Partner Central or My Cisco Workspace

Guest

Threat Outbreak Alert

Threat Outbreak Alert: Fake MasterCard Purchase Order Notification E-mail Messages on July 15, 2012

 
Threat Type:IntelliShield: Threat Outbreak Alert
IntelliShield ID:25955
Version:8
First Published:2012 May 17 16:49 GMT
Last Published:2012 July 16 16:56 GMT
Port: Not Available
Urgency: Possible Use
Credibility: Confirmed
Severity: Harrassment
 
Version Summary:Cisco Security Intelligence Operations has detected significant activity on July 15, 2012.
 

Description
 

Cisco Security Intelligence Operations has detected significant activity related to a German-language spam e-mail message that claims to contain the details of a purchase order for the recipient.  The e-mail message attempts to convince the recipient to open a .zip attachment to view the purchase order.  However, the attachment contains a malicious .pif file that, when executed, attempts to infect the system with malicious code.

The e-mail message that is related to this threat (RuleID4162, RuleID4165, and RuleID4162KVR) may contain the following files:

Vertrag.zip
Vertrag 17.05.2012.pif
Buchung.zip
Buchung 18.05.pif

Vertrag 17.05.2012.com
Mitgliedschaft.zip
Mitgliedschaft.pif

Buchung.pif
Unterlagen.zip
Unterlagen.pif

Abzug.zip
Ebay-Rechnung.pif

Anlagen.zip
Anlagen 12.06.2012 .pif

12.06.2012.zip
FOTO THUN GmbH.pif
Rechnung.zip
Rechnung nach Vertrag vom 15.07.2012 .com

Auftrag.zip
Auftrag 13.07.com

The Vertrag 17.05.2012.pif file in the Vertrag.zip attachment has a file size of 34,477 bytes.  The MD5 checksum, which is a unique identifier of the executable, is the following string: 0x78EE9C318793ADB145A5ABDC07DB8F1B

The Buchung 18.05.pif file in the Buchung.zip attachment has a file size of 73,216 bytes.  The MD5 checksum is the following string: 0x2BE22D6A7CEBD1078642CCB612DA265D

The Vertrag 17.05.2012.com file in the Vertrag.zip attachment has a file size of 71,680 bytes.  The MD5 checksum is the following string: 0xB956277FF83B800E01A5E45006EB6B45

The Mitgliedschaft.pif file in the Mitgliedschaft.zip attachment has a file size of 53,248 bytes.  The MD5 checksum is the following string: 0xA878329F092026265FF2029B7F1F1E78

The Buchung.pif file in the Buchung.zip attachment has a file size of 52,224 bytes.  The MD5 checksum is the following string: 0x12656E048DEC42B589C1902D16948BF3

The Unterlagen.pif file in the Unterlagen.zip attachment has a file size of 48,128 bytes.  The MD5 checksum is the following string: 0xE7C55AC32BD694EC72200C31D6F4793E

The Ebay-Rechnung.pif file in the Abzug.zip attachment has a file size approximately of 48,005 bytes.  The MD5 checksum is not available.

The Anlagen 12.06.2012 .pif file in the Anlagen.zip attachment has a file size of 77,824 bytes.  The MD5 checksum is the following string: 0xF006E2C76A4DFE750C08130826D0EB34

The FOTO THUN GmbH.pif file in the 12.06.2012.zip attachment has a file size of 76,288 bytes.  The MD5 checksum is the following string: 0xEC6CE550AE2BF5E07562303C0F2CC438

The Rechnung nach Vertrag vom 15.07.2012 .com file in the Rechnung.zip attachment has a file size of 98,816 bytes.  The MD5 checksum is the following string: 0xFE99DAFE4A211DC29ABFD21978361E88

The Auftrag 13.07.com file in the Auftrag.zip attachment has a file size of 55,808 bytes.  The MD5 checksum is the following string: 0xB3B2B77130EB221B015EFA7488670333

The following text is a sample of the e-mail message that is associated with this threat outbreak:

Subject: Artikelbestellung 5502425326

Message Body:

Sehr geehrte Damen und Herren,
Vielen Dank fr Ihren Einkauf bei PersonalNOVEL, nachfolgend finden Sie Ihre Kaufbest?gung.
Ihre Bestellnummer: 483534164216
Artikel: Samsung 9600558888   6992,04 Euro
Rechnungsname: Wie in Bestelldetails gekennzeichnet
Zahlungsmethode: Mastercard
Versandadresse und detaillierte Bestelldetails finden Sie zwecks Vorsichtsmassnahmen im Anhang.
Die Zahlung wurde autorisiert und wird innerhalb 3 Tage abgetragen.
Kaufeinzelheiten und Storno Mitteilung finden Sie in beigefgter Datei.
Ihr Kundensupport
Wolf GmbH
Bergstieg 67
39072 Hannover

Or

Subject: WG: Claudia Ihre Datingwebseite-Premiumanmeldung

Message Body:

Besten Dank für Ihr Vertrauen Claudia,
Sie haben soeben bei der Dating-Agentur www.Parship.com die Starmitgliedschaft beantragt. Der Betrag in Höhe von 366,69 EUR wird in den nächsten Tagen von Ihrem Konto abgebucht. Die Kontobuchung erfolgt durch Rayment GmbH.
Sie sind jetzt für die kommenden 12 Monate Premiummitglied und können in voller Grösse die Elitedienstleistungen nutzen.
Entziehen Sie die Vertragsdetails bitte der Beilage, dort finden Sie auch die Vertragseinzeilheiten und Elitedienstvorteile. Falls Sie die Premium-Mitgliedschaft nicht mehr wünschen, mailen Sie die Kündigung, mit der in dem Anhang, beigelegten Widerrufserklärung.
Claudia das Team wünscht dir viel Glück.
Mit freundlichen Grüßen Klaus Bauer
Support-Team
Hamburg 01429, Deutschland
Telefon: +49-553-65257715
Geschäftsführer: Sabine Winkler
Inhaltlich Verantwortlicher gemäss § 6 MDStV: Ursula Binder
Datenschutzbeauftragter: Karin Leitner
Ust-ID-Nr.: DE2898326711
Amtsgericht Essen
Handelsregister: HRB 46050

Or

Subject: CP Reported as Junk

Message Body:

Hallo Francesco Ciardullo,
Ihr Konto ist überfällig. Bitte begleichen Sie Ihre ausstehende Rechnung vollständig, da wir sonst Ihre Möglichkeiten bei
eBay einkaufen und verkaufen zu können, einschränken müssen.
Ihre eBay-Rechnung für den Zeitraum vom 2'k. April 2012 bis zum 12. Mai 2012 ist jetzt in beigefügtem Anhang zu sehen. Fäl l iger Betrag: 085, 9'k
Zahlung ist jetzt fällig. Bitte beachten Sie, dass bei einer Zahlungsverspätung, Ihnen Mahngebühren angerechnet werden können. Ihre Artikeldetails und Stornierung Erklärung finden Sie auch im zugefügtem Zip Ordner. Hinweis: eBay fragt niemals per E-Mail nach vertraulichen oder persönlichen Daten (z. B. Passwort, Kreditkarte, Kontonummer) . Vielen Dank, dass Sie eBay nutzen.
Mit freundlichen Grüßen, eBay
eBay hat diese Nachricht an Francesco Ciardullo geschickt.
Ihr Name in dieser Nachricht ist ein Hinweis darauf, dass die Nachricht tatsächlich von eBay stammt.
Mehr zum Thema: http://pages.ebay.de/help/confidence/name-userid-emails.html
Dies ist eine automatisch generierte E-Mail. Bitte antworten Sie nicht darauf.

Cisco Security Intelligence Operations analysts examine real-world e-mail traffic data that is collected from over 100,000 contributing organizations worldwide.  This data helps provide a range of information about and analysis of global e-mail security threats and trends.  Cisco will continue to monitor this threat and automatically adapt IronPort systems to protect customers.  This report will be updated if there are significant changes or if the risk to end users increases.

Cisco IronPort Virus Outbreak Filters protect customers during the critical period between the first exploit of a virus outbreak and the release of vendor antivirus signatures.  E-mail that is managed by Cisco and end users who are protected by Cisco IronPort web security appliances will not be impacted by these attacks.  Cisco IronPort appliances are automatically updated to prevent both spam e-mail and hostile web URLs from being passed to the end user.

Related Links
Cisco Security Intelligence Operations 
Cisco Threat Operations Center
Cisco SenderBase Security Network

 
Alert History
 

Version 7, June 13, 2012, 12:14 PM: Cisco Security Intelligence Operations has detected significant activity on June 12, 2012.

Version 6, June 12, 2012, 8:28 AM: Cisco Security Intelligence Operations has detected significant activity on June 12, 2012.

Version 5, May 25, 2012, 10:02 AM: Cisco Security Intelligence Operations has detected significant activity on May 25, 2012.

Version 4, May 25, 2012, 12:35 AM: Cisco Security Intelligence Operations has detected significant activity on May 24, 2012.

Version 3, May 23, 2012, 10:12 AM: Cisco Security Intelligence Operations has detected significant activity on May 23, 2012.

Version 2, May 18, 2012, 1:48 PM: Cisco Security Intelligence Operations has detected significant activity on May 18, 2012.

Version 1, May 17, 2012, 11:49 AM: Cisco Security Intelligence Operations has detected significant activity on May 17, 2012.



Product Sets
 
The security vulnerability applies to the following combinations of products.

Primary Products:
IntelliShieldThreat Outbreak AlertOriginal Release Base

Associated Products:
N/A




Alerts and bulletins on the Cisco Security Intelligence Operations Portal are highlighted by analysts in the Cisco Threat Operations Center and represent a subset of the comprehensive content that is available through Cisco Security IntelliShield Alert Manager Service. This customizable threat and vulnerability alert service provides security staff with access to timely, accurate, and credible information about threats and vulnerabilities that may affect their environment. Cisco is pleased to offer a free trial of the service. To register for full access, please visit the IntelliShield trial registration page.


LEGAL DISCLAIMER
The urgency and severity ratings of this alert are not tailored to individual users; users may value alerts differently based upon their network configurations and circumstances. THE ALERT, AND INFORMATION CONTAINED THEREIN, ARE PROVIDED ON AN "AS IS" BASIS AND DO NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE ALERT, AND INFORMATION CONTAINED THEREIN, OR MATERIALS LINKED FROM THE ALERT, IS AT YOUR OWN RISK. INFORMATION IN THIS ALERT AND ANY RELATED COMMUNICATIONS IS BASED ON OUR KNOWLEDGE AT THE TIME OF PUBLICATION AND IS SUBJECT TO CHANGE WITHOUT NOTICE. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE ALERTS AT ANY TIME.
Powered by  IntelliShield

Feedback

Which alert section is most useful?

  • Affected Products/Versions
  • Patches/Software Updates
  • Description
  • Safeguards
  • Technical Information/Analysis

Do you use the CVSS scoring provided in alerts? Why?

What additional information should IntelliShield alerts include?