Products & Services
Support How to Buy

For Home

Cisco Home Products Store
Products for everyone

Flip Video Store
Meet the Flip Family:
Life now has a play button

All Ordering Options

Training & Events Partners

Find a Partner

Cisco Partners help you find the right solution for your Business

Become a Partner

Enhance your company's value-add, expertise and opportunities

Small Business Partners

Log in to get sales resources.

Already a Partner?

Log in for resources.

Register as a New User

Visit Partner Central or My Cisco Workspace

Guest

Threat Outbreak Alert

Threat Outbreak Alert: Fake Personal Photos E-mail Messages on July 21, 2012

 
Threat Type:IntelliShield: Threat Outbreak Alert
IntelliShield ID:25258
Version:28
First Published:2012 February 24 21:11 GMT
Last Published:2012 July 23 17:15 GMT
Port: Not Available
Urgency: Possible Use
Credibility: Confirmed
Severity: Mild Damage
 
Version Summary:Cisco Security Intelligence Operations has detected significant activity on July 21, 2012.
 

Description
 

Cisco Security Intelligence Operations has detected significant activity related to spam e-mail messages that claim to contain personal photos. The text in the e-mail message attempts to convince the recipient to open an attachment to view the photos. However, the .zip attachment contains a malicious .exe file that, when executed, attempts to infect the system with malicious code.

E-mail messages that are related to this threat (RuleID3961 and RuleID3961KVR) may contain any of the following files:

Photos.zip
IMG958.exe
IMG8493.exe

IMG839.exe
IMG04958.exe
Photo.zip
IMG02745.exe
IMG00687.exe
IMG94857.exe

IMG04762.exe
IMG9385.exe
IMG0457.exe
IMG0496.zip
IMG0496.exe

IMG0591.exe
EPS0948.exe
Photo.exe
IMG8495.exe
IMG0893.zip
IMG0893.exe

IMG9807.zip
IMG9807.exe

IMG9821.zip
IMG9821.exe

IMG7652.zip
IMG7652.exe

EPS00872.zip
EPS00872.exe

IMG9403.zip
IMG9403.exe

IMG9847.zip
IMG9847.exe

IMG0962.zip
IMG8927.exe

IMG0395.zip
IMG0395.exe

Photos.exe
IMG4898.exe
KVREPS0049.zip
EPS0049.exe

IMG93857.exe

EPS09678.zip
EPS09678.exe

IMG3619.exe
IMG93038.zip
IMG93038.exe

CAN03489.exe
EPS00364585.exe
sample.zip
ok1.exe

The IMG958.exe file in the Photos.zip attachment has a file size of 36,352 bytes.  The MD5 checksum, which is a unique identifier of the executable, is the following string: 0xE64EE2AD5901EC4E49C44099BA5C9A54

The IMG8493.exe file in the Photos.zip attachment has a file size of 41,472 bytes. The MD5 checksum is the following string: 0x21521C77EEEF1197BA86E65204EFCA63

The IMG839.exe file in the Photos.zip attachment has a file size of 41,984 bytes.  The MD5 checksum is the following string: 0x8A5DC48813D5B490785A6CC7A8C5FCF8

The IMG04958.exe file in the Photo.zip attachment has a file size of 36,352 bytes.  The MD5 checksum is the following string: 0x21521C77EEEF1197BA86E65204EFCA63

The IMG02745.exe file in the Photo.zip attachment has a file size of 47,616 bytes.  The MD5 checksum is the following string: 0x1F4A0E18C7B18A3C2799540F10E503AF

The IMG00687.exe file in the Photo.zip attachment has a file size of 32,256 bytes.  The MD5 checksum is the following string: 0x0DF04BB66914BA6762F47E65B03D824C

The IMG94857.exe file in the Photo.zip attachment has a file size of 33,792 bytes.  The MD5 checksum is the following string: 0x64944A12B74DC86CF0BD968BC33B56F0

The IMG04762.exe file in the Photo.zip attachment has a file size of 33,792 bytes.  The MD5 checksum is the following string: 0xCB407F8A82E75AA9FB54A5685EC43FFD

The IMG9385.exe file in the Photo.zip attachment has a file size of 33,280 bytes.  The MD5 checksum is the following string: 0x1D134D3108DD0B6DD7BC2BA47ABD678B

The IMG0457.exe file in the Photo.zip attachment has a file size of 31,232 bytes.  The MD5 checksum is the following string: 0xFC66726B33E42A17EE8B9FF8EED88C69

The IMG0496.exe file in the IMG0496.zip attachment has a file size of 32,256 bytes.  The MD5 checksum is the following string: 0x9C5D54D2998E60247DA04AD704DFB2F6

The IMG0591.exe file in the Photo.zip attachment has a file size of 32,256 bytes.  The MD5 checksum is the following string: 0x0675FB4107BB1AE2696A882CB91AAA2E

The EPS0948.exe file in the Photo.zip attachment has a file size of 31,232 bytes.  The MD5 checksum is the following string: 0x93735AEBB3E5960D7C8ACA3998C8C813

The Photo.exe file in the Photo.zip attachment has a file size of 34,304 bytes.  The MD5 checksum is the following string: 0x3688B8E76FBFE9FD381BF3A65DDADA71

The IMG8495.exe file in the Photo.zip attachment has a file size of 33,792 bytes.  The MD5 checksum is the following string: 0xCA8A110EF6967BEEBE521EE61FBDD43E

A variant of the Photo.exe file in the Photo.zip attachment has a file size of 34,304 bytes.  The MD5 checksum is the following string: 0x1389C1983EA4EAA72A0BF87F506C9B45

The IMG0893.exe file in the IMG0893.zip attachment has a file size of 33,792 bytes.  The MD5 checksum is the following string: 0x5B1E1534C828D398B0AE91820913911F

The IMG9807.exe file in the IMG9807.zip attachment has a file size of 31,232 bytes.  The MD5 checksum is the following string: 0xE3A9EC00EDB2D8557F535D42FA7C8441

The IMG9821.exe file in the IMG9821.zip attachment has a file size of 46,592 bytes.  The MD5 checksum is the following string: 0xC059816A9E77113092F7C6ADB2DEECEB

The IMG7652.exe file in the IMG7652.zip attachment has a file size of 48,128 bytes.  The MD5 checksum is the following string: 0x45BC9AD077DEC8A5B682F02900F844AE

The EPS00872.exe file in the EPS00872.zip attachment has a file size of 51,200 bytes.  The MD5 checksum is the following string: 0x5FE3EC48C6C232AC74D4C273F9306085

The IMG9403.exe file in the IMG9403.zip attachment has a file size of 50,688 bytes.  The MD5 checksum is the following string: 0xAD1696DFDEDBEBA3437543718A3DDB3A

The IMG9847.exe file in the IMG9847.zip attachment has a file size of 58,880 bytes.  The MD5 checksum is the following string: 0x347706FABA95F6D7FE64DF2F27BEF024

The IMG8927.exe file in the IMG0962.zip attachment has a file size of 51,200 bytes.  The MD5 checksum is the following string: 0x75BCFADB754DE06C2207CAD5DAD0C003

The IMG0395.exe file in the IMG0395.zip attachment has a file size of 49,664 bytes.  The MD5 checksum is the following string: 0xC2618A002853E9266A4A3A1F9E7CD957

A variant of the Photos.exe file in the Photos.zip attachment has a file size of 57,344 bytes.  The MD5 checksum is the following string: 0x7484453DF392E9E577C17B504A415ACD

A variant of the Photo.exe file in the Photo.zip attachment has a file size of 65,024 bytes.  The MD5 checksum is the following string: 0x8A115563822E7ECA1B83ABEC0D31416B

A third variant of the Photo.exe file in the Photo.zip attachment has a file size of 61,952 bytes.  The MD5 checksum is the following string: 0x1988B57F1448DE5413EF3A75F7836231

A fourth variant of the Photo.exe file in the Photo.zip attachment has a file size of 63,488 bytes.  The MD5 checksum is the following string: 0x971BE4892A3F3A4B4EB9818434749DB0

A fifth variant of the Photo.exe file in the Photo.zip attachment has a file size of 61,440 bytes.  The MD5 checksum is the following string: 0x46E7B5C14BB15FA134F1DFD457F65C0E

The IMG4898.exe file in the Photo.zip attachment has a file size of 64,000 bytes.  The MD5 checksum is the following string: 0xB4E77546C5A762987FAFE289E401AA57

The EPS0049.exe file in the KVREPS0049.zip attachment has a file size of  59,904 bytes.  The MD5 checksum is the following string: 0x6A22F40B23012DD26274A8767CF61145

A variant of the IMG93857.exe file in the Photo.zip attachment has a file size of 58,368 bytes.  The MD5 checksum is 0x84E886503FBFAA2E4A6F043CD672ECD9

The EPS09678.exe file in the EPS09678.zip attachment has a file size of 63,488 bytes.  The MD5 checksum is the following string: 0xA6937CE5EE9A18CC4988E036F46811F9

The IMG3619.exe file in the Photo.zip attachment has a file size of 38,400 bytes.  The MD5 checksum is the following string: 0x940024C714B1DC8F21FC2FA81F88FD2C

The IMG93038.exe file in the IMG93038.zip attachment has a file size of 47,104 bytes.  The MD5 checksum is the following string: 0xE5B396C22BE1FA9AF176A61046757947

A third variant of the CAN03489.exe file in the Photo.zip attachment has a file size of 47,104 bytes.  The MD5 checksum is the following string:  0xE2A8EFE717547076A019321AA16BC429

A fourth variant of the EPS00364585.exe file in the Photo.zip attachment has a file size of 49,152 bytes.  The MD5 checksum is the following string:  0x79AEACE252D7CCADC47364573FE29769

The ok1.exe file in the sample.zip attachment has a file size of 750,592 bytes. The MD5 checksum is the following string: 0x9C3817BEEAB7852C83668264F5C5861E

The following text is a sample of the e-mail message that is associated with this threat outbreak:

Subject: O boy you look so stupid here.

Message Body:

Hi de3cup@yahoo.com,
I got this photo from your ex-girlfriend. You're really ridiculous man!

Or

Subject: Got you by the balls man.

Message Body:

Cheers bradleyjreece@yahoo.com,
I'm sorry man you seem to be in trouble. My girfriend got this picture of you yesterday and sent to your wife. Hope you can handle it

Or

Subject: I got you busted man. Proof is attached.

Message Body:

Hey branniont@yahoo.com,
How would you explain that picture of yours, it attachment? I don't really know what to think of you now.

Or

Subject: This chick in this video looks like you. It's you?

Message Body:

Hey andy_roc_1230@yahoo.com,
This chick in this pornvideo in attachment looks a lot like your girfriend. Do you know that she did porn? Are you OK with it?.

Or

Subject: Looks like we didn't really know anything about her:)

Message Body:

Hi there sanjohnson@geico.com,
Check the attached video, someone on Facebook sent it to me. Is it really Rihanna?? Mind-blowing:)) She's really weird!.

Or

Subject: Hey what's with your Facebook profile?

Message Body:

Hey bobo_bossu_11@yahoo.com,
What's with your facebook??? Very strange stuff on your profile page, I made a screenshot, see attachment. Is is you or someone stole your account??.

Or

Subject: You HAVE to check this photo in attachment man.

Message Body:

Excuse me al@cesmail.net,
I got to show you this picture in attachment, I can't tell who gave it to me, sorry, but this chick looks a lot like your ex-gf. But who's that dude?? I have a question, have you seen this picture of yours, in attachment?? Three facebook friends sent it to me today... why did you put it online? wouldn't it harm your job? what if parents see it? you must be way cooler than I thought about you man :)))).

Cisco Security Intelligence Operations analysts examine real-world e-mail traffic data that is collected from over 100,000 contributing organizations worldwide. This data helps provide a range of information about and analysis of global e-mail security threats and trends. Cisco will continue to monitor this threat and automatically adapt IronPort systems to protect customers. This report will be updated if there are significant changes or if the risk to end users increases.

Cisco IronPort Virus Outbreak Filters protect customers during the critical period between the first exploit of a virus outbreak and the release of vendor antivirus signatures. E-mail that is managed by Cisco and end users who are protected by Cisco IronPort web security appliances will not be impacted by these attacks. Cisco IronPort appliances are automatically updated to prevent both spam e-mail and hostile web URLs from being passed to the end user.

Related Links
Cisco Security Intelligence Operations
Cisco Threat Operations Center
Cisco SenderBase Security Network

 
Alert History
 
Version 27, July 11, 2012, 12:03 PM: Cisco Security Intelligence Operations has detected significant activity on July 10, 2012.

Version 26, July 3, 2012, 10:07 AM: Cisco Security Intelligence Operations has detected significant activity on July 8, 2012.

Version 25, July 3, 2012, 10:11 AM: Cisco Security Intelligence Operations has detected significant activity on July 3, 2012.

Version 24, June 26, 2012, 5:01 PM: Cisco Security Intelligence Operations has detected significant activity on June 26, 2012.

Version 23, June 25, 2012, 2:36 PM: Cisco Security Intelligence Operations has detected significant activity on June 22, 2012.

Version 22, June 22, 2012, 10:03 AM: Cisco Security Intelligence Operations has detected significant activity on June 21, 2012.

Version 21, May 29, 2012, 10:47 AM: Cisco Security Intelligence Operations has detected significant activity on May 29, 2012.

Version 20, May 25, 2012, 12:41 PM: Cisco Security Intelligence Operations has detected significant activity on May 12, 2012.

Version 19, May 12, 2012, 7:16 PM: Cisco Security Intelligence Operations has detected significant activity on May 8, 2012.

Version 18, May 7, 2012, 10:28 AM: Cisco Security Intelligence Operations has detected significant activity on May 7, 2012.

Version 17, May 4, 2012, 1:59 PM: Cisco Security Intelligence Operations has detected significant activity on May 3, 2012.

Version 16, April 30, 2012, 9:50 AM: Cisco Security Intelligence Operations has detected significant activity on April 29, 2012.

Version 15, April 20, 2012, 10:05 AM: Cisco Security Intelligence Operations has detected significant activity on April 20, 2012.

Version 14, April 6, 2012, 3:38 PM: Cisco Security Intelligence Operations has detected significant activity on April 5, 2012.

Version 13, April 5, 2012, 12:56 PM: Cisco Security Intelligence Operations has detected significant activity on April 4, 2012.

Version 12, April 4, 2012, 11:06 AM: Cisco Security Intelligence Operations has detected significant activity on April 4, 2012.

Version 11, March 19, 2012, 10:28 AM: Cisco Security Intelligence Operations has detected significant activity on March 16, 2012.

Version 10, March 16, 2012, 2:27 PM: Cisco Security Intelligence Operations has detected significant activity on March 15, 2012.

Version 9, March 14, 2012, 4:46 PM: Cisco Security Intelligence Operations has detected significant activity on March 13, 2012.

Version 8, March 12, 2012, 11:11 AM: Cisco Security Intelligence Operations has detected significant activity on March 9, 2012.

Version 7, March 8, 2012, 11:19 AM: Cisco Security Intelligence Operations has detected significant activity on March 7, 2012.

Version 6, March 6, 2012, 3:02 PM: Cisco Security Intelligence Operations has detected significant activity on March 6, 2012.

Version 5, March 5, 2012, 5:32 PM: Cisco Security Intelligence Operations has detected significant activity on March 5, 2012.

Version 4, February 29, 2012, 3:07 PM: Cisco Security Intelligence Operations has detected significant activity on February 29, 2012.

Version 3, February 28, 2012, 10:55 AM: Cisco Security Intelligence Operations has detected significant activity on February 28, 2012.

Version 2, February 27, 2012, 9:36 AM: Cisco Security Intelligence Operations has detected significant activity on February 26, 2012.

Version 1, February 24, 2012, 4:11 PM: Cisco Security Intelligence Operations has detected significant activity on February 24, 2012.


Product Sets
 
The security vulnerability applies to the following combinations of products.

Primary Products:
IntelliShieldThreat Outbreak AlertOriginal Release Base

Associated Products:
N/A




Alerts and bulletins on the Cisco Security Intelligence Operations Portal are highlighted by analysts in the Cisco Threat Operations Center and represent a subset of the comprehensive content that is available through Cisco Security IntelliShield Alert Manager Service. This customizable threat and vulnerability alert service provides security staff with access to timely, accurate, and credible information about threats and vulnerabilities that may affect their environment. Cisco is pleased to offer a free trial of the service. To register for full access, please visit the IntelliShield trial registration page.


LEGAL DISCLAIMER
The urgency and severity ratings of this alert are not tailored to individual users; users may value alerts differently based upon their network configurations and circumstances. THE ALERT, AND INFORMATION CONTAINED THEREIN, ARE PROVIDED ON AN "AS IS" BASIS AND DO NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE ALERT, AND INFORMATION CONTAINED THEREIN, OR MATERIALS LINKED FROM THE ALERT, IS AT YOUR OWN RISK. INFORMATION IN THIS ALERT AND ANY RELATED COMMUNICATIONS IS BASED ON OUR KNOWLEDGE AT THE TIME OF PUBLICATION AND IS SUBJECT TO CHANGE WITHOUT NOTICE. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE ALERTS AT ANY TIME.
Powered by  IntelliShield