Dynamoo's Blog

Malware, spam, scams and random stuff, by Conrad Longmore.

Tuesday, 29 November 2016

Fake eFax spam uses hacked Sharepoint to spread malware

›
This fake fax leads to a malicious ZIP file: From :    eFax [message@inbound-efax.org] Date :    29 November 2016 at 16:01 Subject :   ...
1 comment:

Malware spam: "Please find attached a XLS Invoice 378296" / creditcontrol@somecompany.com / Ansell Lighting

›
This fake financial spam comes with a malicious attachment, purporting to come from Ansell Lighting: Subject :     Please find attached...
Friday, 25 November 2016

Malware spam: [Vigor2820 Series] New voice mail message from 014xxxxxxxx on %date%

›
This fake voicemail spam leads to Locky ransomware and appears to come from within the victim's own domain, but this is just a simple ...

Malware spam: "Important Information" leads to Locky

›
This spam leads to Locky ransomware: Subject :     Important Information From :     Etta Figueroa Date :     Friday, 25 November 2016, ...

Moar Locky 2016-11-25

›
This data comes from my trusted usual source, so far I have only seen a single example. This morning's spam run has a subject with o...
Wednesday, 23 November 2016

Malware spam: "financial records subpoena" / lawfirmofoklahoma.com

›
This spam purports to come from Michael T Diver who is a real Oklahoma attorney, but it doesn't really and is jut a simple forgery: ...
1 comment:

Moar Locky: "Bill-12345" from victim's own domain

›
This spam has no body text and appears to come from within the sender's own domain. It leads to Locky ransomware. For example: From...

Malware spam "Please Pay Attention" leads to Locky

›
This fake financial spam leads to Locky ransomware: Subject :     Please Pay Attention From :     Bill Rivera Date :     Wednesday, 23 ...
Tuesday, 22 November 2016

Malware spam: "Invoice 123456" from random sender in victim's own domain

›
This fake financial spam appears to come from a random sender in the victim's own domain, but this is just a simple forgery. The paylo...
1 comment:

Malware spam: "Delivery status" leads to Locky

›
This fake financial spam leads to Locky ransomware: Subject :     Delivery status From :     Gilbert Hancock Date :     Tuesday, 22 N...
Monday, 21 November 2016

Malware spam: "Your LogMein.com subscription has expired!" / billing@secure-lgm.com

›
This fake financial spam leads to malware: From :    billing@secure-lgm.com Date :    21 November 2016 at 18:35 Subject :    Your Log...
1 comment:

Something evil on 64.20.51.16/29 (customer of Interserver, Inc)

›
I wrote about this evil network on 64.20.51.16/29 (a customer of Interserver, Inc) over a year ago , identifying it as a hotbed of fraud....
Thursday, 17 November 2016

Malware spam: "Sage Invoice [service@sage-invoices.com]" / "Outdated Invoice" leads to Trickbot

›
This fake financial spam leads to the Trickbot banking trojan. From :    Sage Invoice [service@sage-invoices.com] Date :    17 November...
2 comments:
Wednesday, 16 November 2016

Phishing: "Office 365 Tax Refund Service" / updatemicrosoftonline.com

›
Microsoft Office 365 offering a tax refund service? Really? No, of course not, it's a phishing scam.. From :    Microsoft Office 36...
1 comment:
Wednesday, 9 November 2016

Malware spam: "Shell Fuel Card E-bill 8089620 for Account (rnd(B,S,F,H,A,D,C,N,M,L)}}776324 08/11/2016" leads to Locky

›
This spam has an interestingly malformed subject, however the attachment leads to Locky ransomware: Subject :     Shell Fuel Card E-bil...

Malware spam: "Account temporarily suspended" leads to Locky

›
This fake financial spam leads to Locky ransomware: From :    Nicole Roman Date :    9 November 2016 at 10:44 Subject :    Account temp...

Malware spam: "Your Amazon.com order has dispatched" leads to Locky

›
This summary is not available. Please click here to view the post.
1 comment:
Tuesday, 8 November 2016

Malware spam: "Suspicious movements" leads to Locky

›
This fake financial spam leads to Locky ransomware: Subject :     Suspicious movements From :     Marlene Parrish Date :     Tuesday,...

Malware spam: "Statement" leads to Locky

›
Another terse fake financial spam leading to Locky ransomware: Subject :     Statement From :     accounts@ somedomain.tld Date :    ...
Monday, 7 November 2016

Malware spam: "Financial documents" leads to Locky

›
The never-ending Locky ransomware onslaught continues. This fake financial spam has a malicious attachment: Subject :     Financial doc...
‹
›
Home
View web version
Powered by Blogger.