
Dell SonicWALL Threats Research team discovered a new German Ransomware Trojan being spammed in the wild. The spammed e-mail contains a fake premium membership order confirmation at a partner agency and informs the user to open the attachment for elite account cancellation policy details. The attachment contains the new Ransomware Trojan. A sample e-mail message looks like below:

Translated e-mail: (Credit: Google Translate)
Attachment: Registration.zip
Subject: Your partner agency order (UserName) No. 809119652
Body:
Thank you for your trust (UserName)
You have just ordered www.Meinestadt.ch at the partner agency, the premium membership. The amount of 557.19 EUR is amortized over the next days of your account. The move made ??by Lugyment AG.
You are now ready for the next 6 months premium member and can use the full size premium options.Please refrain from using the contract information of the supplement, it also contains the invoice data and elite service benefits. If you no longer want the Elite membership, please email the withdrawal, with the attached in the Appendix, attached cancellation policy.
(UserName), we wish you good luck!
Sincerely, Mary Moeller
Support Team
The attached zip file contains the new Ransomware Trojan with an icon disguised as a MS-DOS shortcut file:

If the user opens the file, it will perform following activity on the victim's machine:



Translated Message (Credit: Google Translate)
Ladies and Gentlemen,
apparently the update program has been completely disrupted. Now the virus can only be removed manually. This you need to use your files to. So if you need the locked data, please send us 200 euros Ukash code to the email: security-center@inbox.lt so soon, this code has been tested, you will receive an update program. If you need your data, we strongly advise you to reformat your computer to completely remove the virus. Ukash can be purchased at any gas station and in several Internet cafes in your area.
mfG Your Security Team

Dell SonicWALL Gateway AntiVirus provides protection against this threat via the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News