Dynamoo's Blog
Malware, spam, scams and random stuff, by Conrad Longmore.
Monday, 13 October 2014
Malware spam: "You have received a new secure message from BankLine" / "You've received a new fax"
›
A couple of unimaginative spam emails leading to a malicious payload. You have received a new secure message from BankLine From: B...
"Your Amazon.co.uk order" spam with malformed DOC attachment
›
A whole bunch of these just came through: From : AMAZON.CO.UK [order@amazon.co.uk] To : 1122@eddfg.com Date : 13 October 20...
1 comment:
Friday, 10 October 2014
Malware spam: "You've received a new fax" / "You have received a new secure message from BankLine"
›
A pair of malware spams this morning, both with the same payload: "You've received a new fax" From: Fax [fax@victimd...
Thursday, 9 October 2014
Spam: Confederation MineraIs / Confederation Minerals (CNRMF) pump-and-dump
›
This high-volume pump-and-dump spam run is promoting the Confederation Minerals ( CNRMF ) stock, although the spam itself intentionally m...
15 comments:
chinaregistry.org.cn domain scam
›
This is an old scam that can safely be ignored. From : Henry Liu [henry.liu@chinaregistry.org.cn] Date : 9 October 2014 07:53 ...
Nuclear EK active on 178.79.182.106
›
It looks like the Nuclear exploit kit is active on 178.79.182.106 (Linode, UK), using hijacked subdomains of legitimate domains using AF...
Wednesday, 8 October 2014
Malware spam: Lloyds "Important - Commercial Documents" and NatWest "You have a new Secure Message"
›
There's a familiar pattern to this malware-laden spam, but with an updated payload from before: Lloyds Commercial Bank: "Impo...
Tuesday, 7 October 2014
DHL-themed phish goes to a lot of effort and then spoils it with Comic Sans
›
This DHL-themed phish is trying to harvest email credentials, but instead of just spamming out a link, it spams out a PDF file with the li...
Friday, 3 October 2014
"Thanks for shopping with us today!" malspam spreads via Dropbox
›
This spam email leads to malware hosted on Dropbox: From : pghaa@pghaa.org To : victim@victimdomain.com Date : 3 October...
2 comments:
Thursday, 2 October 2014
Sky doesn't understand "opting out" of marketing emails
›
When I opt out of marketing emails, I expect to stay opted out. This kind of crap sent from Sky really gets my goat. Are you making the...
Wednesday, 1 October 2014
uktservices.com "Booking Cancellation" spam / 37.235.56.121
›
I just had a mass of these purporting to be from uktservices.com ("UK Travel Services"), but in fact it is a forgery and does n...
Something evil on 87.118.127.230
›
Quite what exploit kit this is I cannot determine, but there's something evil on 87.118.127.230 (Keyweb, Germany) which is using hija...
3 comments:
"Homicide Suspect - important" spam
›
Ohmigod, the New York City police have finally tracked me down for eviscerating that spammer in Times Square. From : ALERT@police.u...
Tuesday, 30 September 2014
Alzheimer's Association (act.alz.org) abused by spammers
›
The Alzheimer's Association in the US (alz.org) operate some sort of tell-a-friend system which is apparently easily abused by spamme...
Malware spam: NatWest "You have a new Secure Message" / "You've received a new fax"
›
The daily mixed spam run has just started again, these two samples seen so far this morning: NatWest: "You have a new Secure Mess...
2 comments:
Monday, 29 September 2014
Malware spam: "Lloyds Commercial Bank" / "HSBC Bank UK"
›
Two different banking spams this morning, leading to the same malware,. Lloyds Commercial Bank "Important - Commercial Documents...
Sunday, 28 September 2014
This is why I don't use Network Solutions
›
I recently acquired a domain name which ended up being registered at Network Solution, not my usual registrar.. so I then wanted to move tha...
Evil network: Shellshock and MangoHost (mangohost.net) / 83.166.234.0/24
›
I came across this particular sewer while looking in my logs for Shellshock access attempts yesterday. I noticed that some cheeky b--stard...
Friday, 26 September 2014
Malware spam: "HMRC taxes application with reference" / "Important - BT Digital File" / RBS "Outstanding invoice"
›
Another bunch of spam emails, with the same payload at this earlier spam run . HMRC taxes application with reference LZV9 0Q3E W5SD N3G...
Malware spam: "Employee Documents - Internal Use" / "You have a new voice" / "BACS Transfer : Remittance for JSAG244GBP" / "New Fax"
›
Whoever is running this spam run is evolving it day after day, with different types of spam to increase clickthrough rates and now some tr...
‹
›
Home
View web version