Description
Cisco Security Intelligence Operations has detected significant activity related to spam e-mail messages that claim to contain an attachment of documents for the recipient. The text in the e-mail message attempts to persuade the recipient to open the attachment for details. However, the .zip attachment contains a malicious .exe file that, when executed, attempts to infect the system with malicious code.
E-mail messages that are related to this threat (RuleID5485) may contain the following files:
Bill of Lading.zip
Bill of Lading.exe
The Bill of Lading.exe file in the Bill of Lading.zip attachment has a file size of 206,484 bytes. The MD5 checksum, which is a unique identifier of the executable, is the following string: 0x09AD49EFE92DD6BCA169B5021450A583
The following text is a sample of the e-mail message that is associated with this threat outbreak:
Subject: Re: Shipping Documents, Bill of Lading Attached
Message Body:
Dear Sir,
Please find attached Bill of Lading, Shipping Document and Packing List
of the already shipped Order.
Kindly cross check the attached Documents and Confirm receive of the
shipping Documents.
For any further question dont hesitate to ask in your next reply.
--
Regards
Ms. Shau.
Green Thai Foods
62 The Stock Exchange of Thailand Building, 4, 6-7th Floor,
Rachadapisek Road, Klongtoey, Bangkok 10110, Thailand
Telephone : (662) 229-2800, (662) 654-5599
Fax : (662) 359-1259
Source: Cisco