Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Threat Outbreak Alert: Fake eFax Message Notification E-mail Messages

$
0
0

Description

Cisco Security Intelligence Operations has detected significant activity related to spam e-mail messages that claim to contain a fax message notification for the recipient. The text in the e-mail message attempts to persuade the recipient to open the attachment and view the details. However, the .zip attachment contains a malicious .exe file that, when executed, attempts to infect the system with malicious code.

E-mail messages that are related to this threat (RuleID5329) may contain the following files:

fax_message_9586670910-9854245494-29_19022013.zip
fax_message_{DIGIT[10]}-{DIGIT[10]}-{DIGIT[2]}_19022013.exe

The fax_message_{DIGIT[10]}-{DIGIT[10]}-{DIGIT[2]}_19022013.exe file in the fax_message_9586670910-9854245494-29_19022013.zip attachment has a file size of 132,608 bytes. The MD5 checksum, which is a unique identifier of the executable, is the following string: 0xC0A98D3BD1BD9C2B95CE402B1BCFD8BC

The following text is a sample of the e-mail message that is associated with this threat outbreak:

Subject: Corporate eFax message - 3 pages

Message Body:

Fax Message [Caller-ID: 628-634-6607]
You have received a 3 pages fax at 19-02-2013 10:27:17 .
View this fax using your PDF reader.
Please visit www.eFax.com/en/efax/twa/page/help if you have any questions regarding this message or your service.
Thank you for using the eFax service!
Home Contact Login
Powered by j2
2013 j2 Global Communications, Inc. All rights reserved.
eFax is a registered trademark of j2 Global Communications, Inc.
This account is subject to the terms listed in the eFax Customer Agreement.


Source: Cisco

Viewing all articles
Browse latest Browse all 8064

Trending Articles