Threat Outbreak Alert
Threat Outbreak Alert: Fake Payment Information Email Messages on September 24, 2013
|
Threat Type: | IntelliShield: Threat Outbreak Alert |
|
IntelliShield ID: | 30969 |
Version: | 1 |
First Published: | 2013 September 24 19:04 GMT |
Last Published: | 2013 September 24 19:04 GMT |
Port:
| Not available |
|
| Urgency: | Possible use | |
| Credibility: | Confirmed | |
| Severity: | Mild Damage | |
|
|
|
|
Version Summary: | Cisco Security Intelligence Operations has detected significant activity on September 24, 2013. |
|
Description |
|
Cisco Security Intelligence
Operations has detected significant activity related to spam email
messages that claims to contain payment information from HSBC for the
recipient. The message attempts to convince the recipient to open the
attachment to view the details. However, the .zip attachment contains a malicious .scr file that, when executed, attempts to infect the system with malicious code.
Email messages that are related to this threat (RuleID7195) may contain the following files:
Swift Copy.zip
SwiftCopy.scr
The SwiftCopy.scr file in the Swift Copy.zip
attachment has a file size of 761,856 bytes. The MD5 checksum, which is a
unique identifier of the executable, is the following string:
0xB12F08506DA417B752766AFE443AFF18
The following text is a sample of the email message that is associated with this threat outbreak:
Subject: SWIFT PAYMENT
Message Body:
Dear Sir/Madam,
The attached payment advice is issued at the request of our customer.
The advice is for your reference only.
Please contact your bank for confirmation.
Yours faithfully,
Global Payments and Cash Management
HSBC
***************************************************************************
This is an auto-generated email, please DO NOT REPLY. Any replies to this
email will be disregarded.
*******************************************************************
"SAVE PAPER - THINK BEFORE YOU PRINT!"...
Payment Advice - Advice Ref:[G41978847383] / ACH credits / CustomerRef:[PO925110] / Second Party Ref:[INVSUMMARY]
======================
"HSBC Advising Service" (advising.service@mail.hsbcnet.hsbc.com)
Cisco Security Intelligence Operations analysts examine real-world email
traffic data that is collected from over 100,000 contributing
organizations worldwide. This data helps provide a range of information
about and analysis of global email security threats and trends. Cisco
will continue to monitor this threat and automatically adapt systems to
protect customers. This report will be updated if there are significant
changes or if the risk to end users increases.
Cisco security appliances protect customers during the critical period
between the first exploit of a virus outbreak and the release of vendor
antivirus signatures. Email that is managed by Cisco and end users who
are protected by Cisco Web Security Appliances will not be impacted by
these attacks. Cisco security appliances are automatically updated to
prevent both spam email and hostile web URLs from being passed to the
end user.
Related Links
Cisco Security Intelligence Operations
Cisco SenderBase Security Network |
|
Alert History |
|
Initial Release |
|
Product Sets |
|
The security vulnerability applies to the following combinations of products.
|
|
Alerts and bulletins on the Cisco Security Intelligence Operations Portal are highlighted by analysts in the
Cisco Threat Operations Center and represent a subset of the comprehensive content that is available through Cisco Security IntelliShield Alert Manager Service.
This customizable threat and vulnerability alert service
provides security staff with access to timely, accurate, and credible
information about threats and vulnerabilities that may affect their
environment.
|
|
LEGAL DISCLAIMER
The urgency and severity ratings of this alert are
not tailored to individual users; users may value alerts differently
based upon their network configurations and circumstances. THE ALERT,
AND INFORMATION CONTAINED THEREIN, ARE PROVIDED ON AN "AS IS" BASIS AND
DO NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES
OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE
ALERT, AND INFORMATION CONTAINED THEREIN, OR MATERIALS LINKED FROM THE
ALERT, IS AT YOUR OWN RISK. INFORMATION IN THIS ALERT AND ANY RELATED
COMMUNICATIONS IS BASED ON OUR KNOWLEDGE AT THE TIME OF PUBLICATION AND
IS SUBJECT TO CHANGE WITHOUT NOTICE. CISCO RESERVES THE RIGHT TO CHANGE
OR UPDATE ALERTS AT ANY TIME. |
|
|
No comments:
Post a Comment