Dynamoo's Blog

Malware, spam, scams and random stuff, by Conrad Longmore.

Thursday, 29 September 2016

Malware spam: "Receipt 103-526" / Receipt.xls

›
This spam leads to Locky ransomware: From     rosalyn.gregory@gmail.com Date     Thu, 29 Sep 2016 21:07:46 +0800 Subject     Receipt ...
1 comment:

Malware spam: "Temporarily blocked" leads to Locky

›
The attachment on this spam email leads to Locky ransomware: From : "Ambrose Clements" Subject : Temporarily blocked Date : T...

Malware spam: "Bill for documents" / "Bill for papers" / "Bill for parcel" leads to Locky

›
This spam leads to Locky ransomware. The sample I have seen have no body text, but have subjects in the format:  Bill for documents 3156...
Wednesday, 28 September 2016

Something evil on 69.64.63.77

›
This appears to be some sort of exploit kit leveraging hacked sites, for example: [donotclick] franchidiscarpa[.]com/index.php --> [...

Locky download and C2 locations 2016-09-28

›
It's one of those day where I haven't been able to look at Lock much, but here is some analysis of download locations from my usua...
Tuesday, 27 September 2016

Malware spam: "Attached:Scan(70)" and others leads to Locky

›
This fake scanned document leads to Locky ransomware: Subject :     Attached:Scan(70) From :     Zelma (Zelma937@victimdomain.tld) To :...
Tuesday, 20 September 2016

Evil network: 178.33.217.64/28 et al (evolution-host.com, customer of OVH)

›
This customer of OVH appears to be registered with fake details, and are distributing malware via a block at 178.33.217.64/28 . Currently,...
1 comment:

Malware spam: "Tracking data" leads to Locky

›
This spam has a malicious attachment leading to Locky ransomware: From :    Loretta Gilmore Date :    20 September 2016 at 08:31 Subj...
Monday, 19 September 2016

Malware spam: "Order: 28112610/00 - Your ref.: 89403" leads to Locky

›
This fake financial spam has a malicious attachment that leads to Locky ransomware. Subject :     Order: 28112610/00 - Your ref.: 89403...

Malware spam: "Express Parcel service" leads to Locky

›
This spam has a malicious attachment: From :    Marla Campbell Date :    19 September 2016 at 09:09 Subject :    Express Parcel servi...
1 comment:
Friday, 16 September 2016

Locky download locations 2016-09-16

›
I haven't had a chance to look at Locky today, but here are the current campaign download locations (thanks to my usual source).. 1e...

Inspiral Carpets hacked, leads to The Quantum Code binary options spam

›
This type of binary options scam spam comes in waves every so often: Subject :     Welcoming speech From :     jeffriesvx@mail2nancy.c...

Malicious domains to block 2016-09-16

›
These domains are part of a cluster, some of with are serving the EITEST RIG exploit kit (similar to that described here ). They all share...
Tuesday, 13 September 2016

Malware spam: "Attached is the tax invoice of your company. Please do the payment in an urgent manner." leads to Locky

›
This fake financial spam leads to Locky ransomware: Subject :     Tax invoice From :     Kris Allison (Allison.5326@resorts.com.mx) D...
Monday, 12 September 2016

Malware spam: "Budget report" leads to Locky (and also evil network on 23.95.106.128/25)

›
This fake financial spam leads to Locky ransomware: From :    Lauri Gibbs Date :    12 September 2016 at 15:11 Subject :    Budget re...
Friday, 9 September 2016

Malware spam: "Order Confirmation xxxxx" leads to Locky

›
This fake financial spam leads to malware: From :    Ignacio le neve Date :    9 September 2016 at 10:31 Subject :    Order Confirmat...
Thursday, 8 September 2016

Malware spam: "[Vigor2820 Series] New voice mail message from xxxxx"

›
This spam appears to come from within the victim's own domain, it has a malicious attachment. The telephone number referred to will va...
Wednesday, 7 September 2016

Malware spam: "Agreement form" leads to Locky

›
This fake financial spam leads to malware: Subject :     Agreement form From :     Marlin Gibson Date :     Wednesday, 7 September 20...
Monday, 5 September 2016

Malware spam: "We are sending you the credit card receipt from yesterday. Please match the card number and amount."

›
This fake financial spam has a malicious attachment: From :    Tamika Good Date :    5 September 2016 at 08:43 Subject :    Credit car...
Friday, 2 September 2016

Malware spam: "old office facilities" leads to Locky

›
This spam has a malicious attachment: Subject :     old office facilities From :     Kimberly Snow (Snow.741@niqueladosbestreu.com) D...
‹
›
Home
View web version
Powered by Blogger.