Dynamoo's Blog

Malware, spam, scams and random stuff, by Conrad Longmore.

Tuesday, 15 December 2015

Malware spam: "Rockspring Remittance Advice - WIRE"

›
This fake financial spam comes with a malicious attachment: From :    Kristina Salinas Date :    15 December 2015 at 14:59 Subject :   ...

Tainted network: Dmitry Shestakov / vds24.net on OVH

›
vds24.net (apparently belonging to "Dmitry Shestakov ") is a Russian reseller of OVH servers that has come up on my radar a few...

Malware spam: "Invoice Attached" / "Accounting Specialist| Bank of America, N.A., Cabot Oil & Gas Corp."

›
This fake financial spam has a malicious attachment: From :    Ernestine Harvey Date :    15 December 2015 at 11:34 Subject :    Invo...
1 comment:

Malware spam: "Invoice for Voucher ACH-2-197701-35" / "Reservations [res@affordablecarhire.com]"

›
This fake financial spam does not come from Affordable Car Hire but is instead a simple forgery with a malicious attachment. From :    R...
1 comment:

Malware spam: "Order PS007XX20000584" / "Nicola Hogg [NHogg@pettywood.co.uk]"

›
This rather brief spam does not come from Petty Wood but is instead a simple forgery with a malicious attachment: From :    Nicola Hogg...

Malware spam: "Reference Number #89044096, Notice of Unpaid Invoice" leads to Teslacrypt

›
This fake financial spam comes with a malicious attachment. From :    Carol Mcgowan Date :    15 December 2015 at 09:09 Subject :    ...
Monday, 14 December 2015

Malware spam: "Israel Burke" / "BCP Transportation, Inc."

›
This fake invoice comes with a malicious attachment: From :    Israel Burke [BurkeIsrael850@business.telecomitalia.it] Date :    14 Dece...
5 comments:

Malware spam: "Your order #12345678" / "11 Money Way, Pittsburgh, PA 15226"

›
This fake financial spam leads to malware: From :    Giuseppe Sims Date :    14 December 2015 at 14:19 Subject :    Your order #25333...
6 comments:

Malware spam: "Invoice 14 12 15" / "THUNDERBOLTS LIMITED [enquiries@thunderbolts.co.uk]"

›
This terse fake financial spam is not from the awesomely-named Thunderbolts Limited but is instead a simple forgery with a malicious atta...

Malware spam: "Scan from a Samsung MFP" / "Gareth Evans [gareth@cardiffgalvanizers.co.uk]"

›
This fake scanned document does not come from Cardiff Galvanizers but is instead a simple forgery with a malicious attachment. From :  ...
1 comment:
Friday, 11 December 2015

Malware sites and evil networks to block (2015-12-11)

›
This group of domains and IPs are related to this Teslacrypt attack , sharing infrastructure with some of the malicious domains in questio...

Malware spam: "Invoice #66626337/BA2DEB0F" leads to Teslacrypt

›
I have only seen one sample of this fake invoice spam, so it is possible that the invoice references and sender names are randomly generat...
Thursday, 10 December 2015

Malware spam: "Order 311286 Acknowledged" / "sales@touchstonelighting.co.uk"

›
This fake financial spam does not come from Touchstone Lighting but is instead a simple forgery with a malicious attachment. From :   ...
7 comments:

Malware spam: "STMT ACWL-15DEC12-120106" / "accounts@mamsoft.co.uk [statements@mamsoft.co.uk]"

›
This fake financial email does not come from MAM Software but is instead a simple forgery with a malicious attachment. From :    accou...
1 comment:

Malware spam: "Foreman&Clark Ltd" / "Last Payment Notice" leads to Teslacrypt

›
This fake financial spam does not come from the long-defunct Foreman & Clark , but instead it comes with a malicious attachment that l...
21 comments:
Wednesday, 9 December 2015

Fake "Fretter Inc" spam leads to Teslacrypt ransomware

›
This email claims to be from the long-dead retailer Fretter Inc , but it is not. Instead it comes with a malicious attachment leading to t...
1 comment:
Tuesday, 8 December 2015

Malware spam: "EXB (UK) Ltd Invoice" / "Sales [sales@exbuk.co.uk]"

›
This fake financial spam does not come from EXB (UK) Ltd but is instead a simple forgery with a malicious attachment. From :    Sales ...
1 comment:

Malware spam: "Updated Statement - 2323191" / "David Lawale [David.Lawale@buildbase.co.uk]"

›
T his fake financial spam does not come from Buildbase but is instead a simple forgery with a malicious attachment. From :    David L...
1 comment:
Monday, 7 December 2015

Malware spam: "Your receipt from Apple Store, Manchester Arndale" / "manchesterarndale@apple.com"

›
This fake receipt does not come from an Apple Store, but is instead a simple forgery with a malicious attachment: From :    manchestera...
4 comments:

Malware spam: "Transglobal Express - Shipping Documentation (TG-1569311)" / "sales@transglobalexpress.co.uk"

›
This fake shipping spam does not come from Transglobal Express but is instead a simple forgery with a malicious attachment. From :    sal...
2 comments:
‹
›
Home
View web version
Powered by Blogger.