Cisco Security Intelligence Operations has detected significant activity related to German-language spam e-mail messages that claim to contain order request details for the recipient. The text in the e-mail message attempts to convince the recipient to open the attachment and view the order details. However, .zip attachment contains a malicious .pif file that, when executed, attempts to infect the system with malicious code.
E-mail messages that are related to this threat (RuleID4159) may contain any of the following files:
Lieferschein.zip
Lieferschein.pif
The Lieferschein.pif file in the Lieferschein.zip attachment has a file size of 65,536 bytes. The MD5 checksum, which is a unique identifier of the executable, is the following string: 0xBE4DD0C9FE78B6A3C3BF4F2750D52D6E
The following text is a sample of the e-mail message that is associated with this threat outbreak:
Subject: Fwd:Vertragsdaten f?r Gabriele Rohringer 41325284094
Message Body:
Dear Sir, dear Madam,
Please find the following e-mail concerning an order I never did.
Best regards,
G. Rohringer
----- Urspr?ngliche Nachricht -----
Von: ""
Erhalten: 16.05.2012 07:09
An: "Gabriele Rohringer"
Verehrte(r) Gabriele Rohringer,
Besten Dank f?r Ihre Bestellung bei K+PHolzShop, nachfolgend finden Sie Ihre Bezahbest?tigung.
Deine Auftragsnummer: 498992192361
Artikel: DWL-ANTK240500 1065869611 5834,37 Euro
Rechnungsname: Gabriele Rohringer
Zahlungsmethode: Per Nachname
Versandadresse und detaillierte Bestelldetails finden Sie zwecks Vorsichtsmassnahmen im Anhang.
Die Buchung wurde autorisiert und wird innerhalb 4 Tage abgeschrieben.
Bezahlauflistung und Widerruf Mitteilung finden Sie im zugef?gtem Zip Ordner.
Ihr Verkaufs-Team
Neumann GmbH
Horner Stieg 61
34579 Keiserslauter
(Mo-Fr 8.00 bis 19.00 Uhr, Sa 9.00 bis 19.00 Uhr)
Gesellschaftssitz ist Altenau
Umsatzsteuer-ID: DE753960577
Gesch?ftsfuehrer: Henri Schneider
Cisco Security Intelligence Operations analysts examine real-world e-mail traffic data that is collected from over 100,000 contributing organizations worldwide. This data helps provide a range of information about and analysis of global e-mail security threats and trends. Cisco will continue to monitor this threat and automatically adapt IronPort systems to protect customers. This report will be updated if there are significant changes or if the risk to end users increases.
Cisco IronPort Virus Outbreak Filters protect customers during the critical period between the first exploit of a virus outbreak and the release of vendor antivirus signatures. E-mail that is managed by Cisco and end users who are protected by Cisco IronPort web security appliances will not be impacted by these attacks. Cisco IronPort appliances are automatically updated to prevent both spam e-mail and hostile web URLs from being passed to the end user.
Related Links
Cisco Security Intelligence Operations
Cisco Threat Operations Center
Cisco SenderBase Security Network