Dynamoo's Blog

Malware, spam, scams and random stuff, by Conrad Longmore.

Tuesday, 27 October 2009

"Facebook Password Reset Confirmation" trojan

›
This trojan claims to be something to do with a Facebook password reset, but it's a plain old EXE-in-ZIP trojan attack. Subject: ...
Saturday, 24 October 2009

Uh.. what?

›
A case of "WTF is this spam trying to do"? It looks like this noobie spammer thinks that sending out millions of copies of their b...
Tuesday, 20 October 2009

Police Fail

›
Never mind the slightly dubious issue of mapping crime hotspots, the announcement of a new service using data from the UK's police for...
Monday, 19 October 2009

Google indexing private Google Voice transcripts?

›
A disturbing item from the Boy Genius Report indicates that seemingly private Google Voice transcripts are appearing in Google search resul...
Wednesday, 14 October 2009

"A new settings file for the blah@blah.blah mailbox"

›
A clever bit of social engineering, looks like Zbot: From: alert@blahblah.tld Subject: A new settings file for the name@blahblah.tld mailbox...
2 comments:

Suspect ad network leads to PDF exploit

›
This was picked up from an ad apparently running on grooveshark.com An ad from ad.technoratimedia.com loads an ad from ad.yieldmanager.co...
Tuesday, 13 October 2009

Piradius.net running Zbot infrastructure servers

›
Piradius.net appears to be up to its dark grey hat antics again with a server at 124.217.251.179 which is providing services to ...
3 comments:
Wednesday, 7 October 2009

Orwellian Black Opel

›
I thought I'd get a photo of the Google Streetview car while it was having a rest.. and before it got me :)
Tuesday, 6 October 2009

htmlads.ru injection attack

›
Another injection attack following on from this one , htmlads.js looks like it is being injected into IIS 6.0 servers. In this case, the st...
2 comments:
Monday, 5 October 2009

Are your personal details on Jigsaw.com?

›
An interesting post caught my eye about a site called Jigsaw.com over at the CluBlog . It's a sort of collective where people trade othe...
Sunday, 4 October 2009

Injection attacks: adbnr.ru

›
adbnr.ru seems to be the latest domain to be used by the bad guys in this current round of injection attacks. The injected code to look fo...
Thursday, 1 October 2009

ads-t.ru and adtcp.ru: Asprox is back

›
I haven't had time to look at this fully, but it seems that a fresh round of Asprox attacks have started after several months of inactiv...
Wednesday, 23 September 2009

max-apprais.com and top-name.net scam

›
max-apprais.com and top-name.net appear to be two fake domain appraisal companies being "recommended" to domain owners as part o...
2 comments:
Tuesday, 15 September 2009

Rogue ads on answers.com: dotastoc.com

›
I'm still trying to track this one down, but somewhere on answers.com is a rogue ad that does through several hops to reach a fake anti...

YoHost.org on the move to Dragonara.net

›
It looks like black-hat host YoHost.org is on the move to a set of IP addresses owned by "Dragonara Alliance Ltd" ( dragonara.net...
Thursday, 10 September 2009

Fake HMRC tax refund messages

›
Looks like there's a spam run in progress with the following fake tax refund message: From: HM Revenue & Customs [mailto:rsa.messag...
Friday, 4 September 2009

Macez.com domain scam

›
Yet another fake domain appraisal scam following on from this one , macez.com has actually been registered for a while but only came into u...
Wednesday, 26 August 2009

Razor blade spam

›
Here's a new one.. razor blade spam! Gillette Mach 3 Blades are apparently the most stolen retail product in the world, so perhaps it i...
Tuesday, 25 August 2009

CurrencyVendor.com: can you trust it?

›
Another doubtful World of Warcraft site is currencyvendor.com hosted on the same server as these other WoW scam sites . Does it look trustw...
6 comments:

$1 + $3 + $8 + $20 + $52 = $84

›
This is a interesting gambling spam which tries to entice you to an online casino called worldelitecasino.net hosted in China. Subject: ...
‹
›
Home
View web version
Powered by Blogger.