Dynamoo's Blog

Malware, spam, scams and random stuff, by Conrad Longmore.

Wednesday, 7 December 2011

Malware: BBB "Complaint from your customers" and billycharge.com

›
Another day, another spam campaign leading to the Blackhole Exploit Kit. Date:      Wed, 7 Dec 2011 08:33:03 +0000 From:      "::Bet...
16 comments:
Tuesday, 6 December 2011

"Epidemic in Guinea" spam / curedret.ru

›
An interesting twist on malware spam: Date :      Tue, 6 Dec 2011 10:19:25 +0530 From :      "MARIE Grover" [victimname@hotmail...
2 comments:
Monday, 5 December 2011

czredret.ru is getting on my nerves

›
I don't know what has been going on with spam for the past couple of weeks, but there has been a tidal wave of the same old spam hammeri...

Spam: "Federal Tax payment canceled / Rejected Federal Tax payment " and twistloft.com

›
There's nothing particularly new with this IRS spam, but because spammers are stupid , all the examples that I have seen today have an i...
2 comments:

Scam: RockSmith Management / rocksmithmanagement.com

›
This scam has been around for a while, it's part of a nasty cluster of scam sites that have an Australian connection . The spam comes ...
2 comments:
Thursday, 1 December 2011

Spammers are stupid

›
What's wrong with this spam? Date :      Thu, 1 Dec 2011 17:55:30 +0900 From :      "LinkedIn" [linkedin@em.linkedin.com] ...
Saturday, 26 November 2011

Fake jobs: working-ca.com

›
Another fake job domain, working-ca.com seems to be part of this long-running scam . I hadn't spotted this one before, so thanks to our...
Thursday, 24 November 2011

Fake jobs: jobinhollandart.com and europjobs.eu

›
Here are two new domains promoting fake jobs: jobinhollandart.com and europjobs.eu This series of emails seems to be different from this ...
1 comment:
Wednesday, 23 November 2011

b*redret.ru domains to block

›
Some of the recent surge of spam emails going around uses a set of .ru domains with a discernible pattern of b*redret.ru. Blocking these a...

Virus: "Help! I'm in trouble!"

›
Another virus-laden email, technically very similar to this one yesterday : Date: Wed, 23 Nov 2011 08:28:46 +0700 From: Saffi@victimdoma...
1 comment:

Virus: "Hello! Look, I've received an unfamiliar bill, have you ordered anything?"

›
Here's a piece of fairly clever social engineering: Date:      Tue, 22 Nov 2011 12:48:52 +0200 From:      "LILLIE Stinson" ...
Tuesday, 22 November 2011

Spoof ACH mails, neoprenpillar.com and decalintos.com

›
Yet another ACH / NACHA / whatever scam email, they go something like this: Date:      Tue, 22 Nov 2011 10:42:43 +0100 From:      "Th...

Fake Firefox: "Introducing the new and improved Firefox 8,optimized for Facebook."

›
Here's a fake Firefox upgrade message circulating by email: From: Mozilla Firefox [mailto:firefox-update@plrja5f2.fireefox.com] Sent:...
Monday, 21 November 2011

Some work-at-home scams to avoid

›
Only a real idiot would send spam to a spamcop.net address. Here is a real idiot: From: Rock Cruit Management 3dhgubesch@hochrather.at R...
7 comments:
Friday, 18 November 2011

Xvideos.com compromised with abusedfire.com attack and other malware

›
This summary is not available. Please click here to view the post.
2 comments:
Wednesday, 16 November 2011

More NACHA / ACH / Tax / Payment scam emails

›
Following on from yesterday's post , there have been many, many more of these emails with slight variations, presumably ending up with a...
Monday, 14 November 2011

NACHA / Wire Transfer malicious emails

›
I'm not sure if these three incidents are all related or are just using the same approach, but here goes. Date :      Mon, 14 Nov 2011...
Friday, 11 November 2011

financialstatements.mrsdl.com, nookbizkitsad.com and 94.102.11.168

›
This is a pretty common virus laden email: Subject: ACH Transfer was not accepted by our bank Dear Bank Account Operator, I regret to ...
Thursday, 10 November 2011

Rove Digital and Vladimir Tsastsin busted.

›
If you work in IT Security, you'll probably remember the names EstDomains and EstHost, part of a criminal organisation called Rove Digit...
Tuesday, 8 November 2011

Something evil on 193.106.174.220 and 91.194.214.66

›
193.106.174.220 and 91.194.214.66 and are a pair of IP addresses that appear to be involved in injection attacks, possibly distributing the ...
‹
›
Home
View web version
Powered by Blogger.