Dynamoo's Blog

Malware, spam, scams and random stuff, by Conrad Longmore.

Tuesday, 28 May 2013

fab.com spam

›
[Via the WeAreSpammers blog] I've never heard of fab.com before, but online comments are very negative .  Originating IP is 65.39.2...
Monday, 27 May 2013

Citibank spam / Statement 57-27-05-2013.zip

›
This fake Citibank email has a malicious attachment: Date:      Mon, 27 May 2013 23:25:06 +0530 [13:55:06 EDT] From:      Millard Hint...
Friday, 24 May 2013

Chase "Incoming Wire Transfer" spam / incoming_wire_05242013.zip

›
This fake Chase "Incoming Wire Transfer" email has a malicious attachment. Date:      Fri, 24 May 2013 09:18:23 -0500 [10:18:...
Tuesday, 21 May 2013

prospectdirect.org (Emailmovers Ltd) spam

›
Everything that this spammer says is a lie: From :     Emily Norton [emily.norton@prospectdirect.org] To :     [redacted] Date :     21...

Delivery_Information_ID-000512430489234.zip

›
The file Delivery_Information_ID-000512430489234.zip is being promoted by a spam run (perhaps aimed at Italian users, although all the ho...
1 comment:
Sunday, 19 May 2013

Something evil on 50.116.28.24

›
50.116.28.24 (Linode, US) is hosting the callback servers for some Mac malware as mentioned here and here plus some other suspect sites....
Friday, 17 May 2013

Newegg.com spam / balckanweb.com

›
This fake Newegg.com spam leads to malware: Date:      Fri, 17 May 2013 10:29:20 -0600 [12:29:20 EDT] From:      Newegg [info@newegg.c...

"Referral link" spam / rockingworldds.net and parishiltonnaked2013.net

›
This spam comes from a hacked AOL email account and leads to malware on 62.76.190.11 : From: [AOL sender] Sent: 17 May 2013 14:12 To: [...
Thursday, 16 May 2013

Wells Fargo and Citi spam / SecureMessage.zip and Securedoc.zip

›
This fake Wells Fargo message contains a malicious attachment: Date:      Thu, 16 May 2013 23:24:38 +0800 [11:24:38 EDT] From:      ...

Walmart.com spam / virgin-altantic.net

›
Another variant of this spam is doing the rounds, this time leading to a landing page on virgin-altantic.net : From: Wallmart.com [mai...
5 comments:

Walmart.com spam / bestunallowable.com

›
This fake Walmart spam leads to malware on bestunallowable.com: From:     Wallmart.com [deviledm978@news.wallmart.com] Date:     16 Ma...
5 comments:

HMRC spam / VAT Returns Repot 517794350.doc

›
This fake HMRC (UK tax authority) spam contains a malicious attachment: From: noreply@hmrc.gov.uk [mailto:noreply@hmrc.gov.uk] Sent: 1...
2 comments:

"Invoice Copy" spam / invoice copy.zip

›
This fake invoice email contains a malicious attachment: Date:      Thu, 16 May 2013 00:27:41 -0500 [01:27:41 EDT] From:      Karen Pa...
1 comment:
Wednesday, 15 May 2013

ADP spam / outlookexpres.net

›
This fake ADP spam leads to malware on outlookexpres.net : Date:      Wed, 15 May 2013 22:39:26 +0400 From:      "donotreply@adp....

Something evil on 184.95.51.123

›
184.95.51.123 (Secured Servers LLC, US / Jolly Works Hosting, Philippines) appears to be trying to serve the Blackhole Exploit kit throug...

Facebook spam / otophone.net

›
This fake Facebook spam leads to malware on otophone.net : Date:      Tue, 14 May 2013 15:29:24 -0500 [05/14/13 16:29:24 EDT] From:   ...
Tuesday, 14 May 2013

Something evil on 94.242.198.16

›
I'm not entirely sure what this is, I think it's an injection attack leading to a malware server on 94.242.198.16 (Root SA, Luxe...

Bank of America spam / RECEIPT428-586.doc

›
This fake Bank of America message has a malicious Word document attached: Date:      Tue, 14 May 2013 10:16:05 +0500 [01:16:05 EDT] Su...
Monday, 13 May 2013

"Confidential - Secure Message from AMEX" spam / SecureMail.zip

›
This fake Amex email has a malicious attachment: Date:      Tue, 14 May 2013 01:34:36 +0600 [15:34:36 EDT] From:      American Express...

Something evil on 188.241.86.33

›
188.241.86.33 (Megahost, Romania) is a malware server currently involved in injection attacks, serving up the Blackhole exploit kit, Zbot...
‹
›
Home
View web version
Powered by Blogger.