Products & Services
Support How to Buy

For Home

Cisco Home Products Store
Products for everyone

Flip Video Store
Meet the Flip Family:
Life now has a play button

All Ordering Options

Training & Events Partners

Find a Partner

Cisco Partners help you find the right solution for your Business

Become a Partner

Enhance your company's value-add, expertise and opportunities

Small Business Partners

Log in to get sales resources.

Already a Partner?

Log in for resources.

Register as a New User

Visit Partner Central or My Cisco Workspace

Guest

Threat Outbreak Alert

Threat Outbreak Alert: Fake Product Order E-mail Messages on May 20, 2013

 
Threat Type:IntelliShield: Threat Outbreak Alert
IntelliShield ID:27710
Version:24
First Published:2012 December 21 18:20 GMT
Last Published:2013 May 20 14:28 GMT
Port: Not Available
Urgency: Possible Use
Credibility: Confirmed
Severity: Mild Damage
 
Version Summary:Cisco Security Intelligence Operations has detected significant activity on May 20, 2013.
 

Description
 
Cisco Security Intelligence Operations has detected significant activity related to spam e-mail messages that claim to contain a product order quote for the recipient. The text in the e-mail message attempts to convince the recipient to open the attachment and view the details. However, the .zip attachment contains a malicious .exe file that, when executed, attempts to infect the system with malicious code.

E-mail messages that are related to this threat (RuleID4961 and RuleID4961KVR) may contain the following files:

Newt_Order_Product_Quotation-doc.zip
Newt_Order_Product_Quotation-doc.exe
New_Order_Product_Quote-doc.zip
New_Order_Product_Quote-doc.exe
scan01_pdf.zip
scan01_pdf.exe
sample_pdf.zip
sample_pdf.exe
tt copy_pdf.zip
products.zip
PRODUC~1.EXE
New_Order_Quotation-doc.zip
New_Order_Quotation-doc.exe
PAYMENTSLIP.zip

Samplepicture_pdf.zip
Samplepicture_pdf.exe
New_Order_Quotation-pdf.zip
New_Order_Quotation-pdf.exe
New_Order_Quotations-doc.zip
New_Order_Quotations-doc.exe
Wester Union Payment Slip_pdf.zip
Wester Union Payment Slip_pdf.exe
scan000_pdf.exe
Quotation_pdf.zip
Quotation_pdf.exe
Obfuscated. Order_pdf.exe
tt_copy_pdf.zip
tt_copy_pdf.scr
Purchase order.pdf.zip
Product Order_pdf.exe
scan002_pdf.zip
scan002_pdf.exe

image001_pdf.zip
image001_pdf.exe
image15052013_pdf.zip
image15052013_pdf.exe
report_0946547_PDF.exe
image200313_pdf.zip
image200313_pdf.exe

The Newt_Order_Product_Quotation-doc.exe file in the Newt_Order_Product_Quotation-doc.zip attachment has a file size of 246,272 bytes. The MD5 checksum, which is a unique identifier of the executable, is the following string: 0x374DB3316720F085660D248FF80F7236

The New_Order_Product_Quote-doc.exe file in the New_Order_Product_Quote-doc.zip attachment has a file size of 208,896 bytes. The MD5 checksum is the following string: 0xE35A51B00D65A62D923ECF38F0958332

The scan01_pdf.exe file in the scan01_pdf.zip attachment has a file size of 551,986 bytes. The MD5 checksum is the following string: 0x1FF7800661B8DABE3D07BEB4CAE9BBED

The sample_pdf.exe file in the sample_pdf.zip attachment has a file size of 552,585 bytes. The MD5 checksum is the following string: 0xB486F08C3A3FA4FC4196BC4AC198558D

The PRODUC~1.EXE file in the products.zip attachment has a file size of 622,080 bytes. The MD5 checksum is the following string: 0x77D61900D8D38567FBF3C1A0F83B7B88

The New_Order_Quotation-doc.exe file in the New_Order_Quotation-doc.zip attachment has a file size of 242,176 bytes. The MD5 checksum is the following string: 0x10B1B22D78452DDBB2DB45A281840EA8

The Samplepicture_pdf.exe file in the Samplepicture_pdf.zip attachment has a file size of 1,404,968 bytes. The MD5 checksum is the following string: 0x000ED64D563392ABB8FE971148E54B62

A variant of sample_pdf.exe file in the sample_pdf.zip attachment has a file size of 563,204 bytes. The MD5 checksum is the following string: 0xEBD9C2F7EA857F895D954D778D34802D

The New_Order_Quotation-pdf.exe file in the New_Order_Quotation-pdf.zip attachment has a file size of 479,744 bytes. The MD5 checksum is the following string: 0x447C433BBAC67632EC309F8248A32221

The New_Order_Quotations-doc.exe file in the New_Order_Quotations-doc.zip attachment has a file size of 238,080 bytes. The MD5 checksum is the following string: 0xE88E598C69D226473554EF92B544D61B

The Wester Union Payment Slip_pdf.exe file in the Wester Union Payment Slip_pdf.zip attachment has a file size of 561,546 bytes. The MD5 checksum is the following string: 0xAC17928943887F879D0F7410B3FB85C5

The scan000_pdf.exe file has a file size of 561,481 bytes. The MD5 checksum is the following string: 0xE3C11111B0237A07E52991352FF30455

The Quotation_pdf.exe file in the Quotation_pdf.zip attachment has a file size of 324,096 bytes. The MD5 checksum is the following string: 0x0FDD80F5725D8086B76DDE6C3A3C8476

A third variant of sample_pdf.exe file in the tt copy_pdf.zip attachment has a file size of 567,637 bytes. The MD5 checksum is the following string: 0xD0145A94B7B7A76560A74FEC4FF954EA

The Obfuscated. Order_pdf.exe has a file size of 616,960 bytes. The MD5 checksum is the following string: 0x99E0857035EE258BD49D65DE21C23D38

The tt_copy_pdf.scr file in the tt_copy_pdf.zip attachment has a file size of 567,427 bytes. The MD5 checksum is the following string: 0x997E1C3EE1BE1B01A9750C736375E267

A fourth variant of the sample_pdf.exe file in the sample_pdf.zip attachment has a file size of 568,226 bytes. The MD5 checksum is the following string: 0x3AFFE31D2F69CFE8F477381ECC2A9485

The Product Order_pdf.exe file in the Purchase order.pdf.zip attachment has a file size of 200,704 bytes. The MD5 checksum is the following string: 0x7E4DCE631728B13CEDC6E800378DF9A1

The scan002_pdf.exe file in the scan002_pdf.zip attachment has a file size of 193,814 bytes. The MD5 checksum is the following string: 0x0D9CA29E21821BC123BCC8FEEFCB7206

The image001_pdf.exe file in the image001_pdf.zip attachment has a file size of 567,704 bytes. The MD5 checksum is the following string: 0xD020B6B79EB642A4A543AA36D58D5370

A variant of New_Order_Quotation-doc.exe file in the PAYMENTSLIP.zip attachment has a file size of 295,424 bytes. The MD5 checksum is the following string: 0xB8D9B77C93D7E924FF4B701F73253F19

A third variant of the New_Order_Quotation-doc.exe file in the New_Order_Quotation-doc.zip attachment has a file size of 291,328 bytes. The MD5 checksum is the following string: 0x6299A6F9BFD9E2A1F8217F321D211563

The fifth variant of the sample_pdf.exe file in the sample_pdf.zip attachment has a file size of 219,975 bytes. The MD5 checksum is the following string: 0x200189938C0D0A1C2FA048DAC326C0BF

The image15052013_pdf.exe file in the image15052013_pdf.zip attachment has a file size of 222,023 bytes. The MD5 checksum is the following string: 0x03887FD4DA77216D554C9C17E3F37B44

The report_0946547_PDF.exe file has a file size of 127,488 bytes. The MD5 checksum is the following string: 0xF51B8A6450A27810C6F11D0A30CCA2F0

The image200313_pdf.exe file in the image200313_pdf.zip attachment has a file size of 221,105 bytes. The MD5 checksum is the following string: 0x6B9E3F487FFA3E7D4C17B18F22C05C57

The following text is a sample of the e-mail message that is associated with this threat outbreak:

Message Body:

This is Boris Kris from ICA PTY Ltd. Please view attached files for the Quantity and products we
want to Order and see if your firm will be able to fulfill our demand. Also provide us with the available
Discounts on the products we are requesting.
Please, kindly provide:
FOB price per piece
Minimum order quantity
I would appreciate your early reply in advance.
Sincerely
Boris Kris
Admin Marketing
ICA PTY ltd.
1742 Kings Dr. NWE Austrialia

Or

Subject: URGENT SUPPLY NEEDED!

Message Body:

Compliments of the day,
We saw similar Product of your company and some of our clients
are interested in them, so please confirm to us if your company
can make provision of the exact product with good quality. Please
finda attached’ specification and relative orders before giving
your quotation and subsequently making your proforma invoice
(PI). Please download attachment of the sample.
Please .This will enable us add it to our safe list and avoid
your email been sent to spam folder.
Looking forward to your response with details, prize and quantity
that can be made available.
Regards
MR DAVE JOHN
Sales Manager
Emirates.Technotrade. L.L.C
Jaierjah, UAE

Or

Message Body:

ATO_header.gif (181×54)
E-tax Notification!
Dear e-tax user,
You are advised to download your Online e-tax Payment Receipt for your Tax refunds for the year 2012.
Attached to this e-mail is your Receipt and you are advise to download it to view your payment report and history.
ATO e-tax Service

Or

Message Body:

Manager Desk Office Angel Star General Merchandise
Paris, France.
My name is Jerry Pounds the head manager of Angel Star Paris Head office.
I am interested in your product and want a long term relation in business once I confirm you can render the required service needed by me.
I will like to know the FOB prices per each items plus the shipping cost I also want to know the kind of method you accept for payment.
Attached to this email is our sample order.Please view and get back to me as soon as possible.
Get back to me and let me know if you have the design so we can do business together.
Await your reply and update.
Jerry Pounds
Manager Desk Office Angel Star General Merchandise
Paris, France.

Or

Subject: New Order Enquiry

Message Body:

How are you?
This is Lee Wuteng from Mwsocds Imports Ltd. Please provide the FOB price and the allowed MQO for the products in the attached document.
I would appreciate your early reply in advance.
Sincerely
Lee Wuteng
Admin Marketing
Mwsocds Imports Ltd.
1894 Sandy Spring Road
Laurel 20707 MD. USA

Or

Subject: I Just make the payment.

Message Body:

Hi,
Please view the western union payment receipt for confirmation, and do get back to me immediately. Don't forget that you gave me your words of assurance never to let me down before i could raise this $4,750usd. I will be waiting for your email
asap.
Best Regards,
Williams Smith

Or

Subject: MAKING MONEY MADE EASY !!!

Message Body:

Hello,
You can work online and make a minimum of $250 USD per day.
Read document for further details.
NOTE: NO REGISTRATION FEE REQUIRED.

Or

Subject: Re: TT Copy.

Message Body:

Greeting's
Find the attached 30% down payment for your PI and will send balance after receiving BL.
Please,update me about production timing and all as its a re-order.
Best regards,
Laura Castilo Gomez
Sherlock Interbiz Co.,Ltd.
Silver Spring,Sanders Ville NY,USA

Or
Subject: P.O 234710

Message Body:

Dear Sir/Madam
We  are Yuyao Jiachi Pipe Co., Ltd,we are  professionals in dealing with Metal connector , Plastic coated pipe , Metal joint.We are really interested with your products as seen from your gallery on your website
Attached is Our signed Purchase Order ,but most importantly we will we will need your guarantee of speedy delivery of this order and as we have listed on our Purchase Order
Note:You will have to sign the Purchase Order and send back along with your Contract Letter
Contact:Mr.Zhou
E-mail:sales@nbjiachi.com
Website:www.nbjieachi.com

Or
Subject: Bank Of America

Message Body:

Attention,
Receive Your Funds Now With No Fee Required
Incoming Wire Notification.
An incoming wire transfer has been received by your financial institution and the funds deposited to your account on 08-03-2013.
Please download the attached document and view the transfer confirmation slip to be sure there's no error on your account that the funds was wired to.
Thanks For your cooperation
Regards
Customer Service
Bank Of America
Benedict Raul
Or
Subject: NEW ORDER QUOTATION

Message Body:

Dear,
Please see the attached product list and send us your quote.
Note: include the FOB, MQO, CIF, and the earliest shipping date
thanks
yours faithfuly
HENRY TB KL
Goe company ltd
Or
Subject: International Wire Transfer File Not Processed

Message Body:

We are unable to process your International Wire Transfer request due to
insufficient funds in the identified account.
Review the information below and contact your Relationship Manager if you
have questions, or make immediate arrangements to fund the account. If funds
are not received by 04/12/2013 03:00 pm PT, the file may not be processed.
Please view the attached file for more details on this transaction.
Any email address changes specific to the Wire Transfer Service should be
directed to Treasury Management Client Services at 1-800-AT-WELLS
(1-800-289-3557).
Event Message ID: S941-6828257
Date/Time Stamp: Fri, 17 May 2013 09:16:42 +0330
---------------------------------------------------------------------------
-------------------------------------------------------------------------
Please do not reply to this email; this mailbox is only for delivery of
Event Messaging notices. To ensure you receive these notices, add
ofsrep.ceoemigw@wellsfargo.com to your address book.
For issues related to the receipt of this message, call toll free
1-800-AT-WELLS (1-800-289-3557) Monday through Friday between 4:00 am and
7: 00 pm and Saturday between 6:00 am and 4:00 pm Pacific Time.
Customers outside the U.S. and Canada may contact their local
representative's office, or place a collect call to Treasury Management
Client Services at 1-704-547-0145.
Please have the Event Message ID available when you call.

Cisco Security Intelligence Operations analysts examine real-world e-mail traffic data that is collected from over 100,000 contributing organizations worldwide. This data helps provide a range of information about and analysis of global e-mail security threats and trends. Cisco will continue to monitor this threat and automatically adapt systems to protect customers. This report will be updated if there are significant changes or if the risk to end users increases.

Cisco security appliances protect customers during the critical period between the first exploit of a virus outbreak and the release of vendor antivirus signatures. E-mail that is managed by Cisco and end users who are protected by Cisco Web Security Appliances will not be impacted by these attacks. Cisco security appliances are automatically updated to prevent both spam e-mail and hostile web URLs from being passed to the end user.

Related Links
Cisco Security Intelligence Operations
Cisco Threat Operations Center
Cisco SenderBase Security Network
 
Alert History
 
Version 23, May 17, 2013, 6:36 PM: Cisco Security Intelligence Operations has detected significant activity on May 17, 2013.

Version 22, May 16, 2013, 2:50 PM: Cisco Security Intelligence Operations has detected significant activity on May 16, 2013.

Version 21, May 15, 2013, 7:12 PM: Cisco Security Intelligence Operations has detected significant activity on May 15, 2013.

Version 20, May 6, 2013, 7:22 PM: Cisco Security Intelligence Operations has detected significant activity on May 3, 2013.

Version 19, March 18, 2013, 1:16 PM: Cisco Security Intelligence Operations has detected significant activity on March 15, 2013.

Version 18, March 12, 2013, 12:48 AM: Cisco Security Intelligence Operations has detected significant activity on March 12, 2013.

Version 17, March 5, 2013, 5:46 AM: Cisco Security Intelligence Operations has detected significant activity on March 4, 2013.

Version 16, February 27, 2013, 7:33 AM: Cisco Security Intelligence Operations has detected significant activity on February 26, 2013.

Version 15, February 25, 2013, 7:14 AM: Cisco Security Intelligence Operations has detected significant activity on February 24, 2013.

Version 14, February 20, 2013, 4:11 AM: Cisco Security Intelligence Operations has detected significant activity on February 19, 2013.

Version 13, February 19, 2013, 4:15 AM: Cisco Security Intelligence Operations has detected significant activity on February 18, 2013.

Version 12, February 18, 2013, 8:11 AM: Cisco Security Intelligence Operations has detected significant activity on February 18, 2013.

Version 11, February 15, 2013, 11:49 AM: Cisco Security Intelligence Operations has detected significant activity on February 15, 2013.

Version 10, February 15, 2013, 5:41 AM: Cisco Security Intelligence Operations has detected significant activity on February 14, 2013.

Version 9, February 11, 2013, 9:29 AM: Cisco Security Intelligence Operations has detected significant activity on February 11, 2013.

Version 8, February 4, 2013, 7:42 AM: Cisco Security Intelligence Operations has detected significant activity on February 3, 2013.

Version 7, January 28, 2013, 10:17 AM: Cisco Security Intelligence Operations has detected significant activity on January 28, 2013.

Version 6, January 25, 2013, 8:21 AM: Cisco Security Intelligence Operations has detected significant activity on January 24, 2013.

Version 5, January 22, 2013, 8:07 AM: Cisco Security Intelligence Operations has detected significant activity on January 21, 2013.

Version 4, January 16, 2013, 8:10 AM: Cisco Security Intelligence Operations has detected significant activity on January 15, 2013.

Version 3, January 16, 2013, 6:46 AM: Cisco Security Intelligence Operations has detected significant activity on January 15, 2013.

Version 2, January 2, 2013, 5:26 AM: Cisco Security Intelligence Operations has detected significant activity on December 25, 2012.

Version 1, December 21, 2012, 9:20 AM: Cisco Security Intelligence Operations has detected significant activity on December 20, 2012.


Product Sets
 
The security vulnerability applies to the following combinations of products.

Primary Products:
IntelliShieldThreat Outbreak AlertOriginal Release Base

Associated Products:
N/A




Alerts and bulletins on the Cisco Security Intelligence Operations Portal are highlighted by analysts in the Cisco Threat Operations Center and represent a subset of the comprehensive content that is available through Cisco Security IntelliShield Alert Manager Service. This customizable threat and vulnerability alert service provides security staff with access to timely, accurate, and credible information about threats and vulnerabilities that may affect their environment. Cisco is pleased to offer a free trial of the service. To register for full access, please visit the IntelliShield trial registration page.


LEGAL DISCLAIMER
The urgency and severity ratings of this alert are not tailored to individual users; users may value alerts differently based upon their network configurations and circumstances. THE ALERT, AND INFORMATION CONTAINED THEREIN, ARE PROVIDED ON AN "AS IS" BASIS AND DO NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE ALERT, AND INFORMATION CONTAINED THEREIN, OR MATERIALS LINKED FROM THE ALERT, IS AT YOUR OWN RISK. INFORMATION IN THIS ALERT AND ANY RELATED COMMUNICATIONS IS BASED ON OUR KNOWLEDGE AT THE TIME OF PUBLICATION AND IS SUBJECT TO CHANGE WITHOUT NOTICE. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE ALERTS AT ANY TIME.
Powered by  IntelliShield