Dynamoo's Blog

Malware, spam, scams and random stuff, by Conrad Longmore.

Friday, 23 January 2009

Asprox: dbrgf.ru

›
Another domain to look for in SQL injection attacks is dbrgf.ru , still calling script.js . Checking your proxy logs for ".ru/script.js...
Wednesday, 21 January 2009

Asprox: lijg.ru and dbrgf.ru

›
A fresh round of SQL injections seem to be on the march, with (at least) two new domains being injected into vulnerable sites: www.lijg.ru ...
Tuesday, 20 January 2009

"Soft Fund Ltd" scam

›
Soft Fund Ltd is a wholly legitimate Ukrainian company. This email claims to be from Soft Fund Ltd, but isn't. From: support.soft...

"Polish fine art studio" scam

›
Is this a money mule scam? A package reshipping scam? Something else? It's certainly a scam.. perhaps an art scam designed to process f...

Amusing 419 from "EFCC Investigation Office Nigeria"

›
A novel take on the 419 scam: Subject: DID YOU AUTHORIZE MR. JOHN WHEELER FOR YOUR FUND CLAIMS From: Mooreh Rose {mrsrosemooreh4...
2 comments:
Friday, 16 January 2009

Spamcop.net phish

›
Here's a phish being sent to Spamcop webmail users - the approach has also been used for other webmail systems, so it isn't just Spa...
Wednesday, 14 January 2009

MS09-001 prognosis. Install it now? Leave it for later?

›
It's patch Tuesday again, with just a single update from Microsoft: MS09-001 . If you are administering a corporate network, then the ...
1 comment:
Tuesday, 13 January 2009

"SLG-Logistics Company" scam

›
Not to be confused with the legitimate S L G Logistics Ltd based in the UK, "SLG-Logistics Company" is a wholly bogus outfit, pro...
1 comment:
Tuesday, 6 January 2009

Ongoing injection attacks against Chinese domains

›
This looks like a case of the Chinese hacking the Chinese again, with a very large number of domains being injected into legitimate sites. T...
Monday, 5 January 2009

"Dating Service" bogus job offer

›
This is most likely a money mule operation, or perhaps one of those sophisticated scams where the bad guys recruit a whole virtual office st...
Sunday, 4 January 2009

"Your new e-mail has been successfuly added" PayPal phish

›
A slightly different approach from the usual PayPal phish rubbish: Subject: Your new e-mail has been successfuly added From: ...
2 comments:
Friday, 2 January 2009

"podmena traffica test" spam

›
There seem to be some strange spam emails doing the rounds, with a body text of " podmena traffica test ".. what gives? It makes a...
7 comments:
Monday, 29 December 2008

SQL injection: msngk6.ru, dft6s.kz and mcuve.cn

›
A new bunch of domains being used in SQL injection attacks at the moment: www.msngk6.ru www.dft6s.kz These are calling a script called style...
Monday, 22 December 2008

Asprox SQL injections are back

›
The Silent Noise blog reports that a fresh round of SQL injection attacks by the Asprox crew are under way. They seem to be using a variety...
Saturday, 20 December 2008

"Classmates Info Center": Currently planning the 2009 Year Reunion

›
There's a fake "Classmates" email being spammed out, that leads to a fake video that needs a fake "Adoble Media Player...
2 comments:
Friday, 19 December 2008

Beijing AUG Networks Technology Co / augnetworks.cn scam

›
This is certainly spam.. but is it a scam? Most likely.. Subject: Dynamoo Domain name and Internet keyword Registration From: ...
1 comment:
Tuesday, 16 December 2008

MS08-078: Out-of-band patch for IE coming

›
Microsoft are issuing an out-of-band patch tomorrow (17th December) for the well-publicised flaw in Internet Explorer. This is another one o...

"IE 7 users: stop looking at porn now!"

›
This zero day vulnerability in Internet Explorer has already been very widely publicised. There are no effective workarounds for the prob...
Wednesday, 10 December 2008

Vulnerability in WordPad Text Converter Could Allow Remote Code Execution

›
Most people will rarely use WordPad these days, but it's installed on pretty much every Windows system out there. So when Microsoft anno...
Sunday, 7 December 2008

Spammers try and fail with fake Classmates email

›
We've seen this particular attack several times before - an email for a bank or other service that requires some sort of software instal...
‹
›
Home
View web version
Powered by Blogger.