Sponsored by..

Thursday, 13 April 2017

Malware spam: "Company Documents" / WebFilling@companieshousemail.co.uk and companieshouseemail.co.uk plus others

This spam email does not come from Companies House, but is instead a simple forgery with a malicious attachment:

From:    Companies House [WebFilling@companieshousemail.co.uk]
Date:    13 April 2017 at 11:10
Subject:    Company Documents
Signed by:    companieshousemail.co.uk



CH Logo

Company Documents

This message has been generated in response to the company complaint submitted to Companies House WebFiling service.

Please note: all forms must be answered or the form will be returned.

Service Desk tel +44 (0)303 8097 432 or email enquiries@companieshouse.gov.uk

Note: This email was sent from a notification-only email address which cannot accept incoming email. Please do not reply directly to this message.
 
Companies House 
Crown way
Maindy
Cardiff
CF14 3UZ
Crown Logo



Documents.doc
48K



---

I observed the email coming from the fake domains companieshousemail.co.uk and companieshouseemail.co.uk  but it looks like there may be more. Email is being send from servers in the 94.237.36.0/24 range (Upcloud Ltd, Finland) and I can see other servers set up to do the same thing:

companieshouseemail.co.uk  94.237.36.104
companieshouseemail.co.uk  94.237.36.145
companieshousemail.co.uk  94.237.36.146
companieshousemail.co.uk  94.237.36.147
companieshousesecure.co.uk  94.237.36.150
companieshousesecure.co.uk  94.237.36.151


Blocking email from the entire 94.237.36.0/24 range at least temporarily might be prudent.

The WHOIS details for these indicate they were registered today with presumably fake details, but that the registrar Nominet have somehow "verified".

Registrant:
Charlene hogg

Registrant type:
Unknown

Registrant's address:
37 Maberley Road
London
SE19 2JA
United Kingdom

Data validation:
Nominet was able to match the registrant's name and address against a 3rd party data source on 13-Apr-2017

Registrar:
GoDaddy.com, LLP. [Tag = GODADDY]
URL: http://uk.godaddy.com

Relevant dates:
Registered on: 13-Apr-2017
Expiry date:  13-Apr-2019
Last updated:  13-Apr-2017

Registration status:
Registered until expiry date.

Name servers:
ns29.domaincontrol.com
ns30.domaincontrol.com
All the attachments I have seen are the same with a current detection rate of 6/55. Hybrid Analysis of the document shows it downloading a component from shuswapcomputer.ca/images/banners/bannerlogo.png and a malicious executable %APPDATA%\pnwshqr.exe is dropped with a detection rate of 14/62.

Automated analysis of the binary [1] [2] show potentially malicious traffic going to:

107.181.161.221 (Total Server Solutions, US)
185.25.51.118 (Informacines sistemos ir technologijos UAB aka bacloud,com, Lithuania)


There are probably other destinations too. The payload appears to be Dyre / Dyreza.

Recommended blocklist:
94.237.36.0/24 (temporary email block only)
shuswapcomputer.ca
185.25.51.118
107.181.161.221





Tuesday, 11 April 2017

Pump and dump spam: Quest Management Inc (QSMG) stock

Following on from last month's INCT pump and dump spam the Necurs botnet is now promoting a Latvian company Quest Management Inc (QSMG) instead.

From:    Jenna Goff
Date:    11 April 2017 at 13:37
Subject:    FDA approval is about to send this stock up fifty fold

Why is Quest Management (Symbol: QSMG) guaranteed to jump 5,000% this month?

They have a cure for cancer.

This biotech is run by some of the most prolific scientists in America. Together, they have more than 400 years of experience in the field and have more diplomas than we can even imagine.

Cancer kills 1 out of 4 people in our country and we have all been affected by it either directly or indirectly.

Who doesn't know someone who's died from it?

The company's scientists are targeting cancer using stem cells. They are able to identify the bad cells and destroy them without radiating the entire body (like is common with chemo).

Apart from saving millions of lives, their treatment will surely become the No1 selling drug on earth.

The company has already made serious headway thanks to nearly two decades of research.

This cutting edge biotech company has completed animal trials successfully and just wrapped up FDA-approved human trials last week.

The next step is the public announcement of those results, which we hear through the grapevine have beat all expectations and will change the world of medicine forever.

The results will be announced this month, and once they are out the stock will jump to $25 a share overnight and will continue up to $50 or more quickly after.

"Quest"'s biotech arm could have a cancer cure that can be totally effective in killing tumors in more than 40% of patients worldwide available in hospitals throughout the globe by the end of the year.

Once that happens, we're talking about a $1000 a share stock.

We're literally coming in at the last mile, out of no where, and grabbing profits from their last 2 decades of hard work.

Consider buying QSMG right now while it's still at under 5 dollars and make sure to tell all your friends to do the same before the price explodes.
You can guarantee that the promise of a future big payout is a lie. For comparison, the INCT stock promoted last month crashed from 13 cents to 3 cents now and the promised buy-out of that company never happened.

But surely this is different? QSMG stock went up 60% yesterday..

Well, as you can see from the chart.. it took a sudden dive and then shot up again. It looks like someone sold 26,000 shares and maybe more (maybe at a discount last week), followed by a small purchase of just 100 shares at apparently a higher price. A casual passer-by might think that that was someone trying to manipulate the stock price.


Financials indicate that QSMG has never really done much in the way of business, and the stock price nosedived from an epic $2000 a share a year ago to less than $2 today.


Market cap is currently quoted at $119m with 70 million shares outstanding, which is a lot for a company with a turnover of a few thousand dollars a quarter. There's a 1000:1 reverse split in there from October. So a year ago, the company appears to have been valued at an even more insane amount.

Probably utterly coincidentally, an agreement was recently made for a legitimate US investment company to acquire 46 million shares of QSMG. Perhaps someone else holding QSMG stock is looking for a payday?

Anyway.. most stocks promoted by pump and dump spam crash and burn. Buying stocks based on a tip from an illegal spam run would be extremely unwise in my personal opinion.

UPDATE 1

We'll probably see several different versions of this illegal botnet-driven spam. Here is the second one..

From:    Lottie Nash
Date:    11 April 2017 at 19:31
Subject:    This biotech has developed a cure for cancer and its shares are soaring.

One of my friends at Goldman told me to buy QSMG this morning.

He is an expert at this stuff and has never let me down before. After researching the company, it seems that he may be right.

I am going to buy 5,000 shares now because it's all I can afford, but you should buy as little or as many as you possibly can...

Their biotech arm, Stemvax has developed a cure for cancer and just completed successful human trials under the FDA's supervision.

The stock has jumped 3X already since last week and is guaranteed to go to at least 20 dollars this month based on his research.

Once QSMG's official announcements for the cure become public, there's no saying how high their share price will go.

I expect some very serious stuff to be announced in the coming 2 weeks. Act quickly so you don't miss out.

UPDATE 2

Another one. Incidentally, the email address used for some of these illegal spam emails appears to have been obtained from CompareTheMarket.com. Nice.

From:    Fay Vinson
Date:    12 April 2017 at 09:19
Subject:    An imminent green light from the fda will send this drug maker soaring.

There are very few times in life when we truly get the chance to be part of something big, and profitable at the same time.

The doctors at QSMG have been working nonstop for more than 20 years to get to this moment a cure for cancer.

They completed animal trials last year which were very positive, and completed human trials just a few days ago with the fda's blessing.

The results are not out yet but according to my sources, the human trials were very successful as well and cancer cells were successfully killed in 40% of all cases.

40% might not seem like a passing grade, but it is above and beyond what everyone was expecting. This makes it the most successful cancer drug on earth, and best of all it is non-invasive.

The results will be announced this month, and once they are out the stock will jump to $25 a share overnight and will continue up to $50 or more quickly after.

Want to feel like a genius? Buy QSMG right now while it's still at just 2 dollars, and wait it out 2 weeks. You will be rewarded handsomely.

UPDATE 3

Another version of this spam is attached below. This "Stemvax" company is not actually part of QSMG, but according to a press release yesterday it's an intended acquistion. I wonder how they're paying for that company? Cash? Stocks? More after this spam..

From:    Araceli Rutledge
Date:    12 April 2017 at 15:34
Subject:    This company found a cure for cancer. Their stock is flying.

This is a super rare opportunity that may never come again. This biotech company has finally found a cure for cancer after more than 20 years of stem cells and immunotherapy research.

They had very positive trials both on animals and humans (according to my sources) where tumors got killed at a rate of 41%

Their medicine is going to change the world once it gets rolled out in a few months. We are awaiting an official announcement form the company in the next couple of weeks, but it seems I am not the only one in the know because their stock has quadrupled since last week.

QSMG is guaranteed to hit 25 bucks a share overnight once they release their announcement to the public. You really need to think about buying shares right now before it shoots up higher.
So.. I was researching this whole takeover thing and also found a similar but rather promotional commentary on a site oracledispatch.com which attributes the bump in QSMG shares to the Stemvax acquisition rather than the spam run.
Quest Management Inc (OTCMKTS:QSMG) had a nice day yesterday moving higher by 15% adding some needed liquidity. The driver for this move came from a Letter of Intent to acquire immunotherapy Biotech company Stemvax, Inc., from Dr. Dwain Morris-Irvin PhD. Upon Closing, Dr. Morris-Irvin will simultaneously become CEO of the newly formed Biotech division of Quest.
 Wait a minute. Let's look at that logo on this "news" site.



 My goodness, that looks very much like the logo of the entirely unrelated Oracle Corporation.

Anyway, every stock on that mentioned on that site looks like it could be a part of a paid promotion. That's not illegal per se. Spamming out millions of emails from a botnet of hacked machines is.

UPDATE 4

Another spam.. this time it's a "friend at the FDA" rather than "One of my friends at Goldman". Yead right.

From:    Teri Dunn
Date:    13 April 2017 at 08:58
Subject:    An imminent event is sending this stock price through the roof.

What if I told you that I know of a company that has actually found a cure for cancer.

They have proven its efficacy in animal tests and have recently just completed their testing on humans.

The results of the tests on the human subjects are not out yet, we are expecting them to become public some time in the next two to three weeks,
but a friend of mine who works at the FDA told me that they are life changing.

It seems that in around forty percent of cases, tumors were successfully destroyed. This number is absolutely huge!
It means that more than a third of the people with cancer can be cured with this therapy.

This is going to change the world, and once the announcement becomes public,
it is guaranteed that their stock price will go to more than 24 to 30 bucks in a matter of hours.

This is why I highly, highly recommend that you buy QSMG as soon as you can today. Get in ahead of the herd.
UPDATE 5

Another one. Perhaps the "I have a good friend who works at the fda" part should read "I have a good friend who is going to jail for securities fraud"?

From:    Socorro Conrad
Date:    13 April 2017 at 18:48
Subject:    Here is a tip that could change your life

I have a good friend who works at the fda, and from time to time he tells me about things before they happen.

This is why I am sending you this message today. Earlier this week he told me about a
company that has found a way to kill cancer tumors in 40% of all breast and prostate cases.

While this isn't a one hundred percent method, it works good enough to save over 50 million lives a year.
The company just completed human trials a couple of weeks ago and have yet to release the results.

Once those positive results hit the public, the company's shares are going to go nuts.

QSMG is currently at under 3 bucks a share. I can guarantee that it will pass 25 to 30 before the end of the
month when those results are out.

Act quickly by getting in now and securing yourself a position ahead of the herd.
UPDATE 6

Surprisingly, the US stock markets are open on Easter Monday so yet another version of this illegal pump-and-dump spam is coming out to prime people. In this case the P&D spam has driven the stock price up.. expect a sharp drop when people realise that it is bullshit.

From:    Milagros Galloway
Date:    17 April 2017 at 09:47
Subject:    This trading idea could tenfold your portfolio this month

In case you missed my email last week, timing is getting very tight now.

You must read on to understand why you must act quickly for your benefit, and the benefit of your friends and family.

If you recall, I told you that I have a friend who works at the food and drug administration who told me about a small company that has just completed human trials for a life-saving cancer therapy.

It seems that in about forty percent in instances, cancer receded. This is an enormous number.

There is nothing else on the market at the moment that can save 40% of patients with breast or prostate cancer.

This drug does.

The small company’s stock is going to go up from 2 dollars to over 30 dollars the moment that this announcement is made public within the next two weeks.

Your window opportunity to buy shares of QSMG is quickly closing. You must act quickly before you miss out.
UPDATE 7

It looks like the bubble has burst on this P&D spam, as there is a note of desperation here..

From:    Alta Stewart
Date:    17 April 2017 at 17:15
Subject:    Do not miss on this chance to triple your money in the market

There is a rare opportunity in the market right now, so rare that it may only happen once in a lifetime.

I have it on good information that a small biotech company is about to receive approval from the f d a for a life-saving medicine.

This medicine is poised to become the next biggest seller in the world as it has just been shown to kill cancer.

This is why there has been a lot of activity surrounding the stock. People are trading it on wrong information, and it's in the red today because of that.

I highly suggest that you buy in right now while fools are getting out, and the stock is cheap because it's going to go up twenty fold in the next 2 weeks

when the public announcement comes out, and the medicine is officially approved. Move quickly though, because otherwise you will miss out.

The opportunity to buy QSMG at these discounts will not last long, and you will regret you didn't jump in when you had the chance.
Yup.. the stock has crashed and burned today. Hardly surprising..


(Even as I am writing this the stock has just crashed below the $1 barrier). Ah well, anyone fooling enough to pay over the odds for this stock has just been burned. But who is actually making money from this stock manipulation?


UPDATE 8

QSMG stock continues to crater, but it hasn't stopped the spammers trying again..

From:    Jesus Cote
Date:    18 April 2017 at 09:39
Subject:    This stock tip is for your eyes only. The chance may never come again

I know of a cutting edge company that has just completed the development of a new life saving medicine. A friend who works at a high position, at a secretive place told me about it.

This medicine has been proven in both lab tests, and human tests to destroy tumors in almost 50% of of instances.

For all practical purposes, I would call it a cure for one of the most deadly diseases of our times.

Being the type of person that I am, I asked myself how we can profit from this information.

The answer is very simple. Within the next week or two, QSMG will make the announcement public and once they do, their stock will go up to over 20 bucks overnight.

So the trick is to grab shares right now, while their price is still dirt cheap and while nobody knows what's about to come.

This is how you get your big break. This is how your life will finally change. Take the leap forward.


---
Best Regards,
Jesus Cote

Yesterday it dropped 73%. It will be interesting to see if it continues its race to the bottom today.

UPDATE 9

After a few days off, the pump and dump spammers are trying again at the share price sticks at 72 cents. It says "This is probably the last time that I will contact you  with this information".. we can only hope. Perhaps coincidentally, QSMG announced they are in negotiations to buy another company.

From:    Arlene Sanders
Date:    24 April 2017 at 09:27
Subject:    This time sensitive information could make you very wealthy

If you missed my heads up over this last week and a half, this is finally your time to act because in just 48 hours something big is going to happen.

This is probably the last time that I will contact you  with this information.

My friend at goldman gave me a call over the weekend and told me that the big acquisition we’ve been waiting for is going to occur on Wednesday. The day after tomorrow.

Pfizer is going to complete the purchase of QSMG (a small, public company) at a price of 23.79 dollars a share. For those of you doing the math out there, that's approximately 30 times higher than where the stock is at now.

If you're wondering why it's happening at such a high price, that’s because these guys just completed human trials on a cancer drug which has proved to be effective in around 40% of cases, and big pharma wants this for itself.

I suspect that I am not the only one who might have heard of this news so the stock may start climbing today and tomorrow before the big announcement becomes public on Wednesday evening.

This is quite literally the chance of a lifetime. If you miss out, you'll probably never be able to make 30x on your money so fast again.

Ten grand into QSMG today will turn into a quarter million bucks by Thursday.


***
King Regards,
Arlene Sanders

UPDATE 10

It turns out that the last one wasn't the last one! You might even think that they are lying. And wait.. QSMG doesn't stand for Quest Science Management Gate at all, does it?

From:    Jeanne David
Date:    24 April 2017 at 16:30
Subject:    I have a tip to share with you

In less than 2 days, this stock will go up 20 times overnight.


I've done a lot for you over the years and you've made an insane amount of profits listening to me.

Today and tomorrow is your last chance to seize the opportunity before it disappears.

My good friend who works at a firm I will not mention in upstate NY told me that a big takeover is about to happen.

A little American biopharma company discovered a new treatment for cancerous tumors and one of the biggest companies (starts with a P) is going to announce the official takeover on Wednesday (in 2 days).

The price at which this will happen more than 20 times what their stock is trading at now. Literally at 23 bucks a share from a current 80 cents.

Write this symbol down, it's the first letter of each word: Quest Science Management Gate that's q followed by s then m and g

This is the 4 letter symbol you need to tell your broker you want to buy, or just type it in yourself in your brokerage.

I hope you're ready to make it big. I expect a big thank you and an invite for steak this weekend.




---
Best Regards,
Jeanne David

UPDATE 11

This spam mentions "Wednesday night" as being when this nonexistant takeover of this crappy stock will take place. Will the spam stop then?

From:    Patsy Sandoval
Date:    25 April 2017 at 09:24
Subject:    By tomorrow evening this stock will be twenty times higher

Did you read my urgent email yesterday?

I outlined very specifically a game plan for you to make more than 20 times on your principle within the next 48 hours.

Let me hit you with the gravy and leave out all the boring details… there's a friend of mine who works at a top 50 firm upstate and he was privy to details of a take over.

In a nutshell there is a very large pharmaceutical company (its name starts with a P) who is finalizing the acquisition of a small public corporation that is currently trading at around 80 cents.

The take over price will be a little over 20 bucks and the official announcement is coming tomorrow night (wed night).

They're paying this much for it because of a novel stem cell treatment which eradicates cancer.

I don't need to tell you what will happen to the share price when this announcement hits the news outlets.

The company's trading symbol is Q as in Quest, S as in Sam, M as in Mother, G as in Great.

These are the 4 letters you need to type into your brokerage account to buy the stock or give to your broker over the phone.

Just ten thousand bucks into this will turn into over two hundred grand by Thursday morning.

You need to act quickly though because it seems I may not be the only one with this information, as I am seeing the price creep up a little already since Monday.



-----
Best Regards,
Patsy Sandoval 
UPDATE 12

This one claims QSMG's "share price is going through the stratosphere". Umm no, it's just bouncing around in the somewhat volatile pumped range that it has been in all week. In my opinion the true value is probably rather closer to $0.00.



From:    Dante Odonnell
Date:    25 April 2017 at 15:54
Subject:    This company's being acquired tomorrow

Its share price is going through the stratosphere.



The cat might be out of the bag now but there is still a massive opportunity to benefit.

I say that the secret is out because the stock price has gone up two days in a row but the reality is that it must be very few people who know information otherwise it would've gone ten times higher.

In case you missed my message yesterday, here is what is happening.. A big pharma corp is acquiring a minuscule public co and this is happening at a price that is 20 times greater than where it currently is.

This means that if you can put 10 thousand in right now, you will take out 200 grand by Thursday morning.

This info is solid. It comes from an attorney who's a long time friend of mine and who literally saw the acquisition documents with his own eyes.

You must be wondering what the company's trading symbol is, and I will not tease you any longer… it's Q like in Quality, S like in Straight, M like Mary and G like Gold

These four letters together make up the company's ticker and that's what you will need to give to your broker, or type into your online account to purchase the stock.

I highly recommend you do this as quickly as possible because there is no guarantee that the price will remain this low much longer.

I expect it'll continue to rise and rise as the insider information spreads. Nonetheless the potential to benefit is absolutely gigantic here.




-----
Best Regards,
Dante Odonnell
UPDATE 13

If you believe the lies this spam is pushing, QSMG are going to be the subject of a takeover bid by Pfizer today. Obviously this is crap, but the spam still keeps trying to pump the share price up nevertheless.

From:    Reba Sykes
Date:    26 April 2017 at 07:28
Subject:    Your chance to make an amazing move is quickly slipping away

There is reason for excitement. A good friend of mine who works at a high place which I will not name told me about a crazy opportunity...

There is an acquisition about to be completed by a very large company.

They're buying out a small medical firm at more than 20 times what it's currently trading at.

This means that every ten thousand bucks you put in will turn into two hundred grand the moment the announcement becomes public.

The symbol for this company is the first letter of each of the following words: Quick, Should, Must, Get.

These 4 letters are what you must type in to your brokerage account or tell your broker in order to get the shares.

I really, really recommend you move on it quickly because the announcement will become public at any day now and this may be your last chance to get in before it's too late.


-------
Best Wishes,
Reba Sykes
UPDATE 15

This one (the 16th version) says (amongst other crap) "This guy has always been right so far. In fact if you remember, the tip I gave you last year… the one on which you made 15x in 2 weeks was from him. Yes, that's right." Funny I don't remember that particular investment. 'Cos it didn't happen.

From:    Jeromy Humphrey
Date:    26 April 2017 at 14:42
Subject:    This is your opportunity to get a 20 bagger in the market very fast

One of my closest buddies, who happens to be a banker, let me in on a little tip earlier on.

There's this really awesome small bio technology firm which has discovered something ground breaking,

and because of this unprecedented discovery they're about to be bought out for a little over 20 times their current value.

One of the most prominent large firms in America is about to make this news public.

When that happens, the small company's stock is going to virtually go up more than twenty three fold overnight.

Let me put this in perspective for you. It means that every 10 thousand bucks you put in this will turn into almost a quarter million when the news is out.

This guy has always been right so far. In fact if you remember, the tip I gave you last year… the one on which you made 15x in 2 weeks was from him. Yes, that's right.

So before I forget, here is the stock symbol.. It's the 1st letter of each of the following words: Quickly Super Mouse Green

I'm giving it to you in “code” in order to avoid potentially prying eyes, in case you are at the office, a cafe or something.

So with the first letter of each of these words, you've got your four letter symbol.

Input this in your online account to buy the stock or call your broker and give it to him and he will make the purchase for you.

One last thing, I don't know if I am the only one who knows this information so it's possible that the price will go up on other people buying,

but nonetheless if you can get in at under a buck twenty, I really recommend you jump on it as soon as physically possible.



--
Best Wishes,
Jeromy Humphrey

UPDATE 16

After a week or so of being quiet, the QSMG spam has started again. No mention of course of the non-existant takeover last week, but somebody somewhere must feel the need to pump up that stock price once more. The stock value has almost halved in a week. Oddly, QSMG's latest press release makes no mention of this stock manipulation.. now would be a good time to do so.



From: Ron Manning
Subject: Here's a life changing tip that will guide you through trump's America
Date: Tue, 02 May 2017 13:12:49 +0530

Given the current political climate, there are very few certain things in this world.

I can tell you first hand that I've had a hard time profiting in the market since Trump's administration came in a few months ago.

So I've looked long and hard for opportunities to leverage this unusual situation we find ourselves in here in America, and I have found the way.

Special circumstances call for special measures, and a friend of mine reached out to me over the weekend telling me that there's a small company on the verge of being bought out by a top 500 firm.

The price at which this will happen? 21 bucks a share from a current paltry 60 cents.

This means that every ten thousand of stock you buy, you'll make around 350k when the announcement comes out to the public in a few days.

Why am I telling you this? I want like-minded people to benefit as well and I'm tired of all the big shots making the big bucks.

Take it the way you will, but watch symbol : Quick Sure Mary Garage (use the first letters of each word to make up your 4 letter symbol which you'll use to buy the stock)

One way or another, whether you get in or not, this buy out is going to happen and people are going to make 35x on their principle.

Why not get a piece of the action?


***
Best Wishes,
Ron Manning
UPDATE 17

Amazingly, after a month and a half the pump-and-dump spam for QSMG has started again..

From:    Quentin Johnson
Date:    16 June 2017 at 07:33
Subject:    You can make more than ten times your principle with just this 1 stock


It's been at least a few months since the last time I had the chance to share something amazing with you but if you recall you really made a mint on that last company.

Earlier today I got lucky because as I was having a bite with one of my good friends who works at a top banking firm, he let me in on a little "secret".

Basically they're working on closing a deal for a forbes 100 pharmaceutical company to purchase the entirety of a small drug maker that's just completed a cure for prostate tumors.

The company that's being acquired is trading at just a few pennies right now but the big pharma is paying around a buck a share for it.

This means if you grab shares today you'll be able to make at least ten times what you put in.

The symbol which you need to give your broker or put into your brokerage is the first letter of each of these words:

Quick
Sun
Main
Goal


Together they make up the 4 letter symbol which you need. Act quickly before other people get wind of this.
Since the spam run started weeks ago, the share price has dropped from $1.70 to just 7.5 cents today.


Basically, the shares have lost 95% of their value since then (and I suspect they are actually worth nothing at all). That's pretty typical for a pump-and-dump promoted stock, but what is unusual with this one is the sheer length of time it has been going on.

UPDATE 18

Yet another stupid pump and dump spam. Funnily enough I don't remember quadrupling my money on an apps company.

From:    Marva Gilliam
Date:    16 June 2017 at 15:20
Subject:    This biotech stock is guaranteed to jump 10x next week

This is going to sound crazy, but you remember last year when I told you to buy the mobile apps company before Sony acquired it and you quadrupled your money in just a few days?

I've got another one of those situations, and the information is just as reliable as last time...

It's from my same friend who works at Goldman up in new york.

This time around though it's a biotechnology company that finally completed human trials on an amazing life saving cancer medicine.

The results are not out yet but this guy told me that a large pharma is already aware of the success of the medicine and they are going to buy them out at a buck a share next week.

The current price of Q S M G (this is the symbol you need to enter in your account to buy)

is just around 10 cents so if you get in quickly you can make a really fast 10x in just a few days.

Thank me later.
UPDATE 19

This spam mentions an upcoming acquisition. It is perhaps just a coincidence that a press release from QSMG claims that some medical company called sanavida.online is being eyed for a takeover. Apropos of nothing, I wonder if that's a cash or stock acquisition?

From:    Alice Bowman
Date:    19 June 2017 at 11:39
Subject:    In less than 5 days this company could yield you a ten bagger

Good morning!

I've been involved in the markets for a few decades now and I'll be the first to tell you that things have never been as uncertain as they are today.

With a new administration heading our country, it's becoming increasingly difficult to get the edge in the markets.

At least, we can always count on lady luck to come in handy when we need her.

A friend of mine founded a small medical company a few years ago and he has been researching a novel way of using the immune system to kill tumors.

After extensive tests and lengthy approval processes, he finally got the green light on this life changing new therapy.

Because of that, a big pharma has put in an offer to buy out the entire company. At essentially 10 times the current trading value.

This guarantees that if you get shares today at under 20 cents each, you will cash out ten times that amount by Friday.

The ticker which you need to use to buy is the first letter of each of these words:

Quest, Start, Mega, Great

Together they make up the 4 letter symbol which you need. Get in as fast as you can before the price jumps.
UPDATE 20

And another one.. what's the betting that the stock won't shoot up tenfold on Friday?

From:    Loretta Head
Date:    19 June 2017 at 17:35
Subject:    Can you really make ten fold on your principal in just a few days?

With today's political climate, it is becoming increasing difficult to find winning stocks.

It's even more difficult to find that once in a blue moon company that you can get in and get a big hit with real quick.

Trump's policies are changing every day and there's no way to know what tomorrow brings to the markets.

That's why I am very fortunate to have stumbled upon a sure bet...

There's a small company that has just discovered a ground breaking medicine for tumors.

Without boring you with details, it's essentially the most effective treatment for cancer right now.

That caught the attention of the big boys and they're buying out this small company for about ten times its current market price.

This is set to occur by Friday. When the news is made public, the price will jump overnight. It's now at just around 0.20.

You do the math. Your upside is big.

The symbol is q.s.m.g

This is what you need to use in order to get shares. Move quick before others find out.

UPDATE 21

I think this passed the ridiculousness threshold some time ago.

From: "Hallie Robles"
Subject: Not sure where to invest? Here's a sure bet.
Date: Tue, 20 Jun 2017 17:33:16 +0600

Our country is going through a strange era. Recent political changes have oddly affected the markets and pretty much most stocks are on over drive right now.

If you have just a few thousand bucks to put into something, picking a winning company is not very easy since everything is so inflated.

I do however know of one that could be life changing. You know, it's a situation like one of those that you only read in the newspaper.

How a guy got really lucky when he put a few thousand in some small company and he made out like a bandit.

Is it just luck though? Or is there more to it than meets the eye?

I have it on good authority that a small medical research company has made a giant breakthrough in getting approval for a rare form of cancer.

Their shares were at over 2 bucks a couple of months ago, but sank to just a few cents when rumors spread that the treatment was ineffective in people.

Those rumors were not false, but they were based on segmented information.

The truth is that the treatment works and the company just got it past government approval.

The news is not public yet, though. At just a few cents a share, you have no downside. You can get in right now at rock bottom and watch it go right back to where it was a few months ago (to over 2 bucks) in a matter of hours once the announcement is out.

The symbol you need to use for the stock is q-s-m-g without the hyphens of course. You just give that to your broker or put it in yourself online in your portal and get in.

Maybe, you too, can make the newspapers for being a "lucky" person but you and I both know the real story.

UPDATE 22

This one tried to make excuses for the fact that QSMG stock has cratered. It's all bullshit of course.

From:    Ben Cain
Date:    20 June 2017 at 15:59
Subject:    This company just found a huge cure and no one knows about it yet!

Did you ever read an article online, or in a magazine praising some so called guru for making a few hundred grand out of just a few thousand by buying just one stock?

These articles are very common and they always make it seem like the guy (or gal) was an expert at this stuff.

I know for a fact that the only way to win in this is to have information that others don't. It's that simple.

If you know that something is going to happen before everyone else does, then you've got the edge.

Just in May, this company I've been watching was trading at a little over 2 bucks alright?

Within days, it got pummeled to just pennies. Apparently, on the incorrect rumor that their new immune  medicine wasn't working.

Now that the dust has settled, it's clear that the information was completely wrong. It just caused a panic, and herd mentality prevailed.

I have an “in” at the company and I know for a fact that not only does this new ground breaking treatment work, but that it just got approved by the f d a.

While this info isn't public yet, once it does become so, you can expect the share price to go right back up to over two dollars. Quite literally overnight. And I am expecting this announcement to come in the next few days.

The symbol you need to buy the stock is q/s/m/g without the / of course. You just give that to your broker or go to your online account and get at least twenty thousand shares.

If you act quickly and get in right now, maybe you'll be one of those cool winner stories people write about in magazines and articles.
UPDATE 23

Another one making excuses for the plumetting share price - "For some odd reasons though, their share price crashed through the floor" - which is nothing to do with them being virtually worthless. Oh no.
From:    Herbert Donovan
Date:    21 June 2017 at 08:18
Subject:    Here's an idea that could make you a small fortune...

Hi [redacted],

I'm not one to just go around and tell my friends random things… If you know me, then you know that I always like to make sure that I know what I'm talking about first.

This is why I waited so long before telling you what is in this email.

One of my closest friends works at a high tech medical firm. They discovered a very successful cure for a certain type of tumor.

For some odd reasons though, their share price crashed through the floor. It went from 2 bucks to like 10 cents over the last few weeks.

My buddy believes that this is due to people being misinformed regarding a new trump policy.

The reality is, the company I'm telling you about right now is about to get f d a approval in the next few weeks and their price is guaranteed to go up more than 15 times its current price.

This is why I think you should take a very close look at q's'm'g (without the apostrophes of course). This is the ticker of the company in question.

If you want something that's practically a sure bet, I recommend you get in this stock today. Even if it's for a modest amount.

You'll be in for a good ride.


Best Regards,
Herbert Donovan
UPDATE 24

More excuses.. and a nice little formatting error at the end.

From:    Ruth Slater
Date:    21 June 2017 at 15:32
Subject:    Let me share with you something that could make you big bucks

I have been around the block. I'm a veteran in this market. I was making my subscribers profits through both Bush, Obama and now Trump.

Back in the Bush Sr. days, I was just an article writer. I wrote for the WS in the Analyst column.

The internet has really changed everything.

Information now travels really fast and is much more accessible to everyone.

I had a lunch meeting with an old colleague a few days ago and he let me in on a little secret.

There's a tiny drug maker that's discovered a spectacular immune medicine. It will change the world and save millions of lives.

The information isn't public yet. In fact, that company was actually about to go bankrupt when the discovery happened. That's why their price dropped from a little over 2 bucks to just 0.10 now.

Long story short, when the news comes out publicly, this thing is going to shoot through the roof.

Based on my decades of experience, I expect it to at least go up 15 to 30 fold in a matter of hours.

The information will be public some time by next week. I recommend you grab shares quickly today if you can.

The symbol you need to use to get the shares is q>s>m>g obviously without the > I put that in there just to make it clearer.

If you miss out, this is on you. It's a rare chance that may never come again.
</html
UPDATE 25

After more that a month, this stupid pump and dump spam starts again. This is the twenty-sixth spam run that I have seen for this stock, although there could be more..

From:    Trina Guerra
Date:    31 July 2017 at 10:20
Subject:    I guarantee that this company will quadruple before Friday. Check it out

Did you know that markets are at an all time high?

Even non traditional places to stash some savings like bitcoin are out of control at an all time high.

Given that, it's so hard to make any serious scratch these days. Most things are overinflated and offer very little upside.

That's why I was super relieved when I stumbled upon a small medical company that's so undervalued I couldn't believe my eyes.

They just announced the results of trials which were extremely positive and I believe that the share value is poised to quadruple by this Friday.

At this time it's trading at an all time low of just five cents... It literally has no where to go but up.

I am going to grab a nice position this morning, and in your place, I'd seriously consider getting in today before the masses find out what's happening and the price shoots up.

The ticker is.  q s m g

Check it out now, you'll be glad you got in at under ten cents. You should also tell all your friends about this. I am expecting it to double today.

UPDATE 26

"I won't waste your time with nonsense" it says..

From:    Dominique Pugh
Date:    31 July 2017 at 15:22
Subject:    This stock is gonna go up 4 fold before the end of the week.

I won't waste your time with nonsense. I'll get right to it...

One of my best friends who happens to be employed at the largest firm in new york told me that I should really consider buying a specific stock today.

Without going into specifics he told me that it's going to at least quadruple in price this week.

It's a small company that's basically trading at rock bottom prices, and after digging a bit more into it I think that they are about to make a really massive announcement any day now.

If you can get in at between 7 and 10 cents in the next few minutes I really recommend you jump on it quickly. It's trading under the symbol q,s,m,g (just the letters without the commas). Type this in your account to buy it.

Don't waste any more time because before the day is over I think it will be much, much higher so now is your chance.


Best Wishes,
Dominique Pugh


Malware spam: "DHL Urgent Delivery"

This fake DHL spam includes the recipients real name. In this case it was sent to someone in Germany, but written in English. The malware payload is identical to this one in Polish.

Von: DHL Parcel [mailto:info@glaefcke.de]
Gesendet: Dienstag, 11. April 2017 11:03
An: [redacted]
Betreff: DHL Urgent Delivery

YOUR DELIVERY IS TODAY


Hi, [redacted]

The scheduled delivery is Tue Apr 11 2017 before End of Day.

Please check your shipment and contact details below. If you need to make a change or track your shipment, click

http://nolp.dhl.com/set_identcodes.do&email=[redacted] . (JS-Document)
SHIPMENT CONTENTS:DELIVERY INFORMATION


Shipment number: 9670515551
Scheduled Delivery Date: Tue Apr 11 2017
Delivery Time: before End of Day
Email Address: [redacted]

Thank you for using On Demand Delivery.

DHL Express - Excellence. Simply delivered. 


Malware spam: "Sprawdź stan przesylki DHL"

This spam targeting Polish victims seems quite widespread. It leads to malware. The email is personalised with the victim's real name which has been harvested from somewhere.

From: DHL Express (Poland) [mailto:biuro@nawigatorxxi.pl]
Sent: Monday, April 10, 2017 7:09 PM
To: [redacted]
Subject: Sprawdź stan przesylki DHL

Sprawdź stan przesylki DHL
Szanowny Kliencie, [redacted]

Informujemy, że w serwisie DHL24 zostało zarejestrowane zlecenie realizacji przesyłki, której jesteś odbiorcą.

Dane zlecenia:
- numer zlecenia:
9653788657

- data złożenia zlecenia:
poniedziałek, 10. kwietnia

Informacje o aktualnym statusie przesyłki znajdziesz na http://dhl24.com.pl/report.html&report=JavaScript&email=[redacted]. (JavaScript Raport)

Niniejsza wiadomość została wygenerowana automatycznie.

Dziękujemy za skorzystanie z naszych usług i aplikacji DHL24.

DHL Parcel (Poland)

UWAGA: Wiadomość ta została wygenerowana automatycznie. Prosimy nie odpowiadać funkcją Reply/Odpowiedz 

The link goes to a malicious Javascript [example here] [Malwr report] which downloads a binary from:

freight.eu.com/download3696 (159.100.181.107 - World Wide Web Hosting LLC, Netherlands)

..this has a detection rate of 10/60. This Malwr report plus observed activity show traffic to the following IPs and ports:

5.196.73.150:443 (OVH, France)
31.220.44.11:8080 (HostHatch, Netherlands)
46.165.212.76:8080 (Leaseweb, Germany)
109.228.13.169:443 (Fasthosts, UK)
119.82.27.246:8080 (Tsukaeru.net, Japan)
173.230.137.155:8080 (Linode, US)
173.255.229.121:443 (Linode, US)
203.121.145.40:8080 (Pacific Internet, Thailand)
206.214.220.79:8080 (ServInt, US)


There may be other phone home locations not observed.

Recommended blocklist:
5.196.73.150
31.220.44.11
46.165.212.76
109.228.13.169
119.82.27.246
159.100.181.107
173.230.137.155
173.255.229.121
203.121.145.40
206.214.220.79





Monday, 3 April 2017

borezo.info - spam selling anti-spam services

If you are in the business of selling spam filtering.. it is probably not a good idea to do it by sending out spam..

From:    Camille Arpaillange [contact@borezo.info]
To:    contact@[redacted]
Date:    3 April 2017 at 15:55
Subject:    [redacted] - Protect emails received on your domain name
Signed by:    sg.borezo.info

Discover our SaaS solution

Anti-Virus, Anti-Spam and Anti-Phishing SMTP Gateway
Try for free

Bonjour,

This email is intended for your IT service, if any. If you are working with an external partener, feel free to forward him this message.

Your current situation

Today, you are using your provider to handle incoming emails on [redacted].

Often, protection against viruses, spam, phishing and all other threats is not the strong point of this kind of solution.

Our proposal:

free trial without obligation

We offer you to try for free and without obligation our email filtering solution, compatible with your provider.

Easy setup

To filter your emails, you only have to update the MX entry in your DNS records, replacing entry of your provider by the one we will provide you after your subscription. Emails will then be filtered by our infrastructure, and then redistributed to your provider, so you can consult them like before.

Functions

Anti-Virus

You won't have to be afraid of ransomwares anymore

Anti-Spam

No more spam, and you stay in control of settings

Anti-Phishing

Your users will not be exposed to credentials theft

Services

Backup

Each user can access himself his personal backup

Statistics

You can have an overview of incoming email trafic

Settings

Anytime, you can change your filtering settings

Advantages

Simplicity

    No configuration change on your SMTP server or the one of your provider.
    No configuration change on users side.
    No maintenance on your side, we take care of everything (hosting, high availability, upgrade, etc.).

Protection

    Anti-Virus, Anti-Spam and Anti-Phishing protection, without raising the load of your infrastructure or the one of your provider.
    Content-Filtering feature, to filter attachments based on their type and/or extension.

Personalized

    For each domain, you can define options of each modules (Anti-Virus, Anti-Spam, etc.).

Security

    In case of unavailability of your SMTP server or the one of your provider, your emails are stored in security on our infrastructure, and delivred as soon as SMTP is back online.

Try for free

This email has been sent to contact@[redacted], click here to unsubscribe.

https://borezo.info/in-k/ - SIRET 53021905400026

Clicking on the link does appear to take you to some sort of business site at https://borezo.info/in-k/

Mail headers match the domain, borezo.info does seem to be the culprit..

Received: from dc3-1.borezo.info (dc3-1.borezo.info [212.83.146.78]) by [redacted] (Postfix) with ESMTP id 191E44A38D for <contact@[redacted]>; Mon,
  3 Apr 2017 15:55:08 +0100 (BST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=simple/simple; s=dkim; d=sg.borezo.info; t=1491231308; h=from:subject:date: message-id; bh=IfD7xgIgVLQy8yLzdCSO+L7mXRn/PImws7LTh1D1pws=; b=j9sTfOH7r3XUTaSD5urHMd1b5EUDq1P9chByrurkie+ckpZjyHojSRUJKSF0lj7OvZ1ze2 Yjlsfl7Q/UQ+U+F2IlFrcMseqXbPLB8xhOVPPh3Ei39qNIgyO+MVApaxDt1WhXcf/npcle 6GjoCgCAGPXFLoTogZGqI3RBB5JBbdE=
Received: tmail deliverd remote 302c5d48ea2a327a67769562d3ece1ce930df6bd; 03 Apr 2017 16:55:08 +0200
X-Env-From: Ym91bmNlLTEtY29udGFjdEBkeW5hbW9vLmNvLnVr@sg.borezo.info
Received: from 212.83.146.78 (dc3-1.borezo.info.) (localhost) (authenticated
   as noreply@borezo.info) by 212.83.146.78 (dc3-1.borezo.info.) with ESMTPS TLS
   1.2 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256; tmail 0.1.7;
   4a5b9f00fa05b580ff586bd74659fbea91085dce; 03 Apr 2017 16:55:02 +0200
WHOIS details seem valid.

Registry Registrant ID: C199006566-LRMS
Registrant Name: Romain Lauret
Registrant Organization:
Registrant Street: office #855805
Registrant Street: c/o OwO, BP80157
Registrant City: Roubaix Cedex 1
Registrant State/Province:
Registrant Postal Code: 59053
Registrant Country: FR
Registrant Phone: +33.972101007
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: pwa3o3znv0b53h47bo8c@v.o-w-o.info


The "Camille Arpaillange" name in the email matches the imprint on the website..


Company registration data is here. I think I will pass on this particular offer..



25.0.0.0/8 is not your private network

A recent phishing email originating from an Office 365 caused some confusion.. apparently originating fom an address in the 25.0.0.0.8 range which according to a WHOIS lookup is the UK's Ministry of Defence.

% Abuse contact for '25.0.0.0 - 25.255.255.255' is 'hostmaster@mod.uk'

inetnum:        25.0.0.0 - 25.255.255.255
netname:        UK-MOD-19850128
country:        GB
org:            ORG-DMoD1-RIPE
admin-c:        MN1891-RIPE
tech-c:         MN1891-RIPE
status:         LEGACY
notify:         hostmaster@mod.uk
mnt-by:         UK-MOD-MNT
mnt-domains:    UK-MOD-MNT
mnt-routes:     UK-MOD-MNT
mnt-by:         RIPE-NCC-LEGACY-MNT
created:        2005-08-23T10:27:23Z
last-modified:  2016-04-14T09:56:26Z
source:         RIPE

organisation:   ORG-DMoD1-RIPE
org-name:       UK Ministry of Defence
org-type:       LIR
address:        Not Published
address:        Not Published
address:        Not Published
address:        UNITED KINGDOM
phone:          +44(0)3067700816
e-mail:         mathew.newton643@mod.gov.uk
admin-c:        MN1891-RIPE
abuse-c:        MH12763-RIPE
mnt-ref:        RIPE-NCC-HM-MNT
mnt-ref:        UK-MOD-MNT
mnt-by:         RIPE-NCC-HM-MNT
mnt-by:         UK-MOD-MNT
created:        2004-04-17T12:18:23Z
last-modified:  2016-10-06T11:09:40Z
source:         RIPE

person:         Mathew Newton
address:        ISS Design Directorate, Joint Forces Command
address:        UK Ministry of Defence
phone:          +44 (0)30 677 00816
e-mail:         mathew.newton643@mod.gov.uk
abuse-mailbox:  hostmaster@mod.uk
notify:         mathew.newton643@mod.gov.uk
nic-hdl:        MN1891-RIPE
created:        2005-03-18T10:42:04Z
last-modified:  2016-12-20T10:33:13Z
source:         RIPE
mnt-by:         UK-MOD-MNT
In this case the connection appeared to come from dm5pr17cu002.internal.outlook.com which does indeed resolve to 25.173.128.134.. which would place it in the MoD's address range. Yes?

Well.. no, because the 25.0.0.0/8 range isn't routable. You can't send traffic to it from the Internet. But it isn't a "private" IP range, it is allocated to the MoD. But it does seem that some companies are taking advantage of this and are using 25.0.0.0/8 for internal networks (much the same as 10.0.0.0/8) when it isn't designed for that.

Of course you can make a DNS record point to anything, it doesn't mean that the server will resolve. A look at all the hosts in 25.173.0.0/16 reveals these apparently active servers:

blserver.net
www.blserver.net
blog.blserver.net
imap.blserver.net
mwhpr13cu002.internal.outlook.com
dm5pr17cu002.internal.outlook.com

25-173-116-219.1334762f6da5400c9f4cbba603d6c121.plex.direct
25-173-129-6.114b489248be4a2489583682ee5d5f3c.plex.direct
sql.engormix.com
has-on.info

In the case of the outlook.com servers the DNS has been misconfigured. What should resolve only PRIVATELY to an 25/8 address is resolving PUBLICALLY to an address in that range. Of course, the servers never respond.And note that this is just one /16, not the whole /8 (reverse DNS for the whole /8 is insane).

The upshot is that the MoD get a lot of abuse calls for bad things that people think originate from their network, but it isn't actually happening.

If you are going to use blocks like 25.0.0.0/8 for internal uses, I would suggest that you take great care not to expose the internal IPs to the outside world. I'm sure the poor people at the MoD would appreciate it.

Friday, 31 March 2017

Leaked documents reveal post-Brexit switch to pre-decimal currency

So with the UK leaving the EU thing kicking off into full swing a lot of interesting stories have been lost in the noise. As expected not only have hard Brexiteers managed to sneak in proposals that we ditch the metric system, it now also seems that they want to ditch decimal currency too.

Madness? Well, they seem to believe that things were better in the old days. Like the 18th Century perhaps. Anyway, these top secret double encoded plans (presuambly leaked by Pro-Bremoaner criminals) have come to light outlining the steps of this particularly mad scheme. It already has a name in government - Dexit.

Basically, immediately after the UK leaves the EU the currency will change back to pounds, shillings and pence...you remember how that works, yes? 12 pence to a shilling, 20 shillings to a pound making 240 pence per pound... on a date pencilled in as being the first day of April in 2019.

All transactions will have to change at that point. However, the pound will still remain the pound including the new pound coin. Notes will still remain the same, although all new ones will contain animal fat by law. As with decimalisation, some coins will remain the same too - the 50p coin will remain valid as 10 shillings, 20p will be 4 shillings and so on for the 10p and 5p coins. New coins will be minted with the new denominations on, but they will circulate alongside the old ones. Copper coins are more of a problem and they will all be withdrawn and replaced.

The halfpenny will not return (thank goodness) and nor will the farthing (1/960th of a pound!). One might argue that the penny could be eliminated altogether as it isn't worth much these days, but apparently there is determination that it will come back.

All eCommerce sites operating in the UK and software will have to be updated to the new currency. It's not as simple as just changing the currency sign, and the law will state that all new computer software will have to support the new currency natively without mucking about with formulas. Formulae. Whatever.

One sticking point is the name of the coins. Technically the current currency is called "new pence", replacing the pre-decimal "old pence". Suggestions for the new coinage include "new old pence", "indedenpence" (clever!) and "Mike Pence".

There will be some exceptions:
  • In anticipation of Scottish independence, the new currency there will be called the "Groat".
  • In Gibraltar the currency will revert to the Euro when it is handed over to Spain (even though 99% of the population don't want that because democracy is so 2016)
  • In Northern Ireland the currency will be determined by whichever side wins the brutal 20-year civil war that follows Brexit.
All of this is quite a low price to pay for taking back control though, isn't it?

(Yes, this was an April Fool's joke, but not too far what what some Brexiters have actually suggested)

Thursday, 30 March 2017

Malware spam: "Re:Payment Remittance Copy"

This fake financial spam leads to malware.


From:    AL HUDA LTD [ap.office@triumftools.sk]
Date:    30 March 2017 at 09:05
Subject:    Re:Payment Remittance Copy
Signed by:    triumftools.sk

Dear Sir,

As instructed by your customer for your payment,

Find attached formal remittance copy received from our bank and contact your  client for payment confirmation. All payment details is in the attached HSBC TT-Copy.

Please Confirm
Best regards,
================================
Alan Bostock
Manager - Finance and Administration
HSBC Exchanger
TEL: (965) 24338094 -620                                  
FAX: (965) 24332815 Mobile: (965) 600-11-868
==================================


Attached is a .GZ archive HSBC TT-Copy.pdf.gz (this assumes you have a program on your Windows PC that can handle .gz files). This contains a malicious executable doc9876543234500001.exe which currently has a VirusTotal detection rate of 32/60.

Analysis of the binary is pending. You can be certain that it is nothing good.

Monday, 20 March 2017

More highly personalised malspam using hijacked domains

Following on from this spam some weeks ago, another one comes in using a broadly similar technique of including the potential victim's real home address while using apparently hijacked infrastructure (although in this case the hijacking isn't so elaborate).

From: customerservice@newshocks.com [mailto:customerservice@newshocks.com]
Sent: 15 March 2017 18:23
Subject: [Redacted] Your order 003009 details




Hello [redacted],
We are delighted to confirm details of your recent order 003009. We will email you again as soon as the items you have chosen are on their way to you.
If you have an online account with us, you can log in here to see the current status of your order.
You will receive another e-mail from us when we have despatched your order.
Information on order 003009 status here
All prices include VAT at the current rate. A full VAT receipt will be included with your order.
Delivery Address:

[Name and address redacted]

If you have any questions, or something about your order isn't right, please contact us. Or you can simply reply to this e-mail.
Best regards and many thanks,

Contact Us Opening Times Delivery Options Returns Policy Privacy Policy Terms & Conditions


The newshocks.com domain used in the "From" field matches the sending server of rel209.newshocks.com (also mail.newshocks.com) on 185.141.164.209. This appears to be a legitimate but unused domain belonging to a distributor of car parts.

The link in the email goes to clipartwin.com/customers/customer-status-003009-verified which is currently 404ing so I can't tell what the payload is, although the previous payload appears to be Ramnit or similar. This is using another hijacked but apparently legitimate web server.

I don't know where the data has leaked from, but in this case the victim had lived at the address for the past four years.. so the leak cannot be ancient. If you have seen something similar or have an idea of where the data came from, please leave a comment below.