Threat Outbreak Alert: Fake Product Order E-mail Messages on May 20, 2013
Threat Type:
IntelliShield: Threat Outbreak Alert
IntelliShield ID:
27710
Version:
24
First Published:
2012 December 21 18:20 GMT
Last Published:
2013 May 20 14:28 GMT
Port:
Not Available
Urgency:
Possible Use
Credibility:
Confirmed
Severity:
Mild Damage
Version Summary:
Cisco Security Intelligence Operations has detected significant activity on May 20, 2013.
Description
Cisco Security Intelligence Operations has detected significant activity related to spam e-mail messages that claim to contain a product order quote for the recipient. The text in the e-mail message attempts to convince the recipient to open the attachment and view the details. However, the .zip attachment contains a malicious .exe file that, when executed, attempts to infect the system with malicious code.
E-mail messages that are related to this threat (RuleID4961 and RuleID4961KVR) may contain the following files:
The Newt_Order_Product_Quotation-doc.exe file in the Newt_Order_Product_Quotation-doc.zip attachment has a file size of 246,272 bytes. The MD5 checksum, which is a unique identifier of the executable, is the following string: 0x374DB3316720F085660D248FF80F7236
The New_Order_Product_Quote-doc.exe file in the New_Order_Product_Quote-doc.zip attachment has a file size of 208,896 bytes. The MD5 checksum is the following string: 0xE35A51B00D65A62D923ECF38F0958332
The scan01_pdf.exe file in the scan01_pdf.zip attachment has a file size of 551,986 bytes. The MD5 checksum is the following string: 0x1FF7800661B8DABE3D07BEB4CAE9BBED
The sample_pdf.exe file in the sample_pdf.zip attachment has a file size of 552,585 bytes. The MD5 checksum is the following string: 0xB486F08C3A3FA4FC4196BC4AC198558D
The PRODUC~1.EXE file in the products.zip attachment has a file size of 622,080 bytes. The MD5 checksum is the following string: 0x77D61900D8D38567FBF3C1A0F83B7B88
The New_Order_Quotation-doc.exe file in the New_Order_Quotation-doc.zip attachment has a file size of 242,176 bytes. The MD5 checksum is the following string: 0x10B1B22D78452DDBB2DB45A281840EA8
The Samplepicture_pdf.exe file in the Samplepicture_pdf.zip attachment has a file size of 1,404,968 bytes. The MD5 checksum is the following string: 0x000ED64D563392ABB8FE971148E54B62
A variant of sample_pdf.exe file in the sample_pdf.zip attachment has a file size of 563,204 bytes. The MD5 checksum is the following string: 0xEBD9C2F7EA857F895D954D778D34802D
The New_Order_Quotation-pdf.exe file in the New_Order_Quotation-pdf.zip attachment has a file size of 479,744 bytes. The MD5 checksum is the following string: 0x447C433BBAC67632EC309F8248A32221
The New_Order_Quotations-doc.exe file in the New_Order_Quotations-doc.zip attachment has a file size of 238,080 bytes. The MD5 checksum is the following string: 0xE88E598C69D226473554EF92B544D61B
The Wester Union Payment Slip_pdf.exe file in the Wester Union Payment Slip_pdf.zip attachment has a file size of 561,546 bytes. The MD5 checksum is the following string: 0xAC17928943887F879D0F7410B3FB85C5
The scan000_pdf.exe file has a file size of 561,481 bytes. The MD5 checksum is the following string: 0xE3C11111B0237A07E52991352FF30455
The Quotation_pdf.exe file in the Quotation_pdf.zip attachment has a file size of 324,096 bytes. The MD5 checksum is the following string: 0x0FDD80F5725D8086B76DDE6C3A3C8476
A third variant of sample_pdf.exe file in the tt copy_pdf.zip attachment has a file size of 567,637 bytes. The MD5 checksum is the following string: 0xD0145A94B7B7A76560A74FEC4FF954EA
The Obfuscated. Order_pdf.exe has a file size of 616,960 bytes. The MD5 checksum is the following string: 0x99E0857035EE258BD49D65DE21C23D38
The tt_copy_pdf.scr file in the tt_copy_pdf.zip attachment has a file size of 567,427 bytes. The MD5 checksum is the following string: 0x997E1C3EE1BE1B01A9750C736375E267
A fourth variant of the sample_pdf.exe file in the sample_pdf.zip attachment has a file size of 568,226 bytes. The MD5 checksum is the following string: 0x3AFFE31D2F69CFE8F477381ECC2A9485
The Product Order_pdf.exe file in the Purchase order.pdf.zip attachment has a file size of 200,704 bytes. The MD5 checksum is the following string: 0x7E4DCE631728B13CEDC6E800378DF9A1
The scan002_pdf.exe file in the scan002_pdf.zip attachment has a file size of 193,814 bytes. The MD5 checksum is the following string: 0x0D9CA29E21821BC123BCC8FEEFCB7206
The image001_pdf.exe file in the image001_pdf.zip attachment has a file size of 567,704 bytes. The MD5 checksum is the following string: 0xD020B6B79EB642A4A543AA36D58D5370
A variant of New_Order_Quotation-doc.exe file in the PAYMENTSLIP.zip attachment has a file size of 295,424 bytes. The MD5 checksum is the following string: 0xB8D9B77C93D7E924FF4B701F73253F19
A third variant of the New_Order_Quotation-doc.exe file in the New_Order_Quotation-doc.zip attachment has a file size of 291,328 bytes. The MD5 checksum is the following string: 0x6299A6F9BFD9E2A1F8217F321D211563
The fifth variant of the sample_pdf.exe file in the sample_pdf.zip attachment has a file size of 219,975 bytes. The MD5 checksum is the following string: 0x200189938C0D0A1C2FA048DAC326C0BF
The image15052013_pdf.exe file in the image15052013_pdf.zip attachment has a file size of 222,023 bytes. The MD5 checksum is the following string: 0x03887FD4DA77216D554C9C17E3F37B44
The report_0946547_PDF.exe file has a file size of 127,488 bytes. The MD5 checksum is the following string: 0xF51B8A6450A27810C6F11D0A30CCA2F0
The image200313_pdf.exe file in the image200313_pdf.zip attachment has a file size of 221,105 bytes. The MD5 checksum is the following string: 0x6B9E3F487FFA3E7D4C17B18F22C05C57
The following text is a sample of the e-mail message that is associated with this threat outbreak:
Message Body:
This is Boris Kris from ICA PTY Ltd. Please view attached files for the Quantity and products we
want to Order and see if your firm will be able to fulfill our demand. Also provide us with the available
Discounts on the products we are requesting.
Please, kindly provide:
FOB price per piece
Minimum order quantity
I would appreciate your early reply in advance.
Sincerely
Boris Kris
Admin Marketing
ICA PTY ltd.
1742 Kings Dr. NWE Austrialia
Or
Subject: URGENT SUPPLY NEEDED!
Message Body:
Compliments of the day,
We saw similar Product of your company and some of our clients
are interested in them, so please confirm to us if your company
can make provision of the exact product with good quality. Please
finda attached’ specification and relative orders before giving
your quotation and subsequently making your proforma invoice
(PI). Please download attachment of the sample.
Please .This will enable us add it to our safe list and avoid
your email been sent to spam folder.
Looking forward to your response with details, prize and quantity
that can be made available.
Regards
MR DAVE JOHN
Sales Manager
Emirates.Technotrade. L.L.C
Jaierjah, UAE
Or
Message Body:
ATO_header.gif (181×54)
E-tax Notification!
Dear e-tax user,
You are advised to download your Online e-tax Payment Receipt for your Tax refunds for the year 2012.
Attached to this e-mail is your Receipt and you are advise to download it to view your payment report and history.
ATO e-tax Service
Or
Message Body:
Manager Desk Office Angel Star General Merchandise
Paris, France.
My name is Jerry Pounds the head manager of Angel Star Paris Head office.
I am interested in your product and want a long term relation in business once I confirm you can render the required service needed by me.
I will like to know the FOB prices per each items plus the shipping cost I also want to know the kind of method you accept for payment.
Attached to this email is our sample order.Please view and get back to me as soon as possible.
Get back to me and let me know if you have the design so we can do business together.
Await your reply and update.
Jerry Pounds
Manager Desk Office Angel Star General Merchandise
Paris, France.
Or
Subject: New Order Enquiry
Message Body:
How are you?
This is Lee Wuteng from Mwsocds Imports Ltd. Please provide the FOB price and the allowed MQO for the products in the attached document.
I would appreciate your early reply in advance.
Sincerely
Lee Wuteng
Admin Marketing
Mwsocds Imports Ltd.
1894 Sandy Spring Road
Laurel 20707 MD. USA
Or
Subject: I Just make the payment.
Message Body:
Hi,
Please view the western union payment receipt for confirmation, and do get back to me immediately. Don't forget that you gave me your words of assurance never to let me down before i could raise this $4,750usd. I will be waiting for your email
asap.
Best Regards,
Williams Smith
Or
Subject: MAKING MONEY MADE EASY !!!
Message Body:
Hello,
You can work online and make a minimum of $250 USD per day.
Read document for further details.
NOTE: NO REGISTRATION FEE REQUIRED.
Or
Subject: Re: TT Copy.
Message Body:
Greeting's
Find the attached 30% down payment for your PI and will send balance after receiving BL.
Please,update me about production timing and all as its a re-order.
Best regards,
Laura Castilo Gomez
Sherlock Interbiz Co.,Ltd.
Silver Spring,Sanders Ville NY,USA
Or
Subject: P.O 234710
Message Body: Dear Sir/Madam
We are Yuyao Jiachi Pipe Co., Ltd,we are professionals in dealing with Metal connector , Plastic coated pipe , Metal joint.We are really interested with your products as seen from your gallery on your website
Attached is Our signed Purchase Order ,but most importantly we will we will need your guarantee of speedy delivery of this order and as we have listed on our Purchase Order
Note:You will have to sign the Purchase Order and send back along with your Contract Letter
Contact:Mr.Zhou
E-mail:sales@nbjiachi.com
Website:www.nbjieachi.com
Or
Subject: Bank Of America
Message Body:
Attention,
Receive Your Funds Now With No Fee Required
Incoming Wire Notification.
An incoming wire transfer has been received by your financial institution and the funds deposited to your account on 08-03-2013.
Please download the attached document and view the transfer confirmation slip to be sure there's no error on your account that the funds was wired to.
Thanks For your cooperation
Regards
Customer Service
Bank Of America
Benedict Raul
Or
Subject: NEW ORDER QUOTATION
Message Body:
Dear,
Please see the attached product list and send us your quote.
Note: include the FOB, MQO, CIF, and the earliest shipping date
thanks
yours faithfuly
HENRY TB KL
Goe company ltd
Or
Subject: International Wire Transfer File Not Processed
Message Body:
We are unable to process your International Wire Transfer request due to
insufficient funds in the identified account.
Review the information below and contact your Relationship Manager if you
have questions, or make immediate arrangements to fund the account. If funds
are not received by 04/12/2013 03:00 pm PT, the file may not be processed.
Please view the attached file for more details on this transaction.
Any email address changes specific to the Wire Transfer Service should be
directed to Treasury Management Client Services at 1-800-AT-WELLS
(1-800-289-3557).
Event Message ID: S941-6828257
Date/Time Stamp: Fri, 17 May 2013 09:16:42 +0330
---------------------------------------------------------------------------
-------------------------------------------------------------------------
Please do not reply to this email; this mailbox is only for delivery of
Event Messaging notices. To ensure you receive these notices, add
ofsrep.ceoemigw@wellsfargo.com to your address book.
For issues related to the receipt of this message, call toll free
1-800-AT-WELLS (1-800-289-3557) Monday through Friday between 4:00 am and
7: 00 pm and Saturday between 6:00 am and 4:00 pm Pacific Time.
Customers outside the U.S. and Canada may contact their local
representative's office, or place a collect call to Treasury Management
Client Services at 1-704-547-0145.
Please have the Event Message ID available when you call.
Cisco Security Intelligence Operations analysts examine real-world e-mail traffic data that is collected from over 100,000 contributing organizations worldwide. This data helps provide a range of information about and analysis of global e-mail security threats and trends. Cisco will continue to monitor this threat and automatically adapt systems to protect customers. This report will be updated if there are significant changes or if the risk to end users increases.
Cisco security appliances protect customers during the critical period between the first exploit of a virus outbreak and the release of vendor antivirus signatures. E-mail that is managed by Cisco and end users who are protected by Cisco Web Security Appliances will not be impacted by these attacks. Cisco security appliances are automatically updated to prevent both spam e-mail and hostile web URLs from being passed to the end user.
The security vulnerability applies to the following combinations of products.
Primary Products:
IntelliShield
Threat Outbreak Alert
Original Release Base
Associated Products:
N/A
Alerts and bulletins on the Cisco Security Intelligence Operations Portal are highlighted by analysts in the
Cisco Threat Operations Center and represent a subset of the comprehensive content that is available through Cisco Security IntelliShield Alert Manager Service.
This customizable threat and vulnerability alert service provides security staff with access to timely, accurate, and credible information about threats and vulnerabilities that may affect their environment. Cisco is pleased to offer a free trial of the service.
To register for full access, please visit the IntelliShield trial registration page.
LEGAL DISCLAIMER The urgency and severity ratings of this alert are not tailored to individual users; users may value alerts differently based upon their network configurations and circumstances. THE ALERT, AND INFORMATION CONTAINED THEREIN, ARE PROVIDED ON AN "AS IS" BASIS AND DO NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE ALERT, AND INFORMATION CONTAINED THEREIN, OR MATERIALS LINKED FROM THE ALERT, IS AT YOUR OWN RISK. INFORMATION IN THIS ALERT AND ANY RELATED COMMUNICATIONS IS BASED ON OUR KNOWLEDGE AT THE TIME OF PUBLICATION AND IS SUBJECT TO CHANGE WITHOUT NOTICE. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE ALERTS AT ANY TIME.