Dynamoo's Blog

Malware, spam, scams and random stuff, by Conrad Longmore.

Monday, 23 January 2017

WARNING: pmacademyusa.org / "Project Management Academy USA"

›
For the past six years I have been following the exploits of Patchree "Patty" Patchrint and Anthony Christopher Jones who claim...
3 comments:
Thursday, 19 January 2017

Malware spam: "The Insolvency Service" / "Investigations Inquiry Notification" / chucktowncheckin.com / chapelnash.com

›
This malware spam in unusual in many respects. The payload may be some sort of ransomware [ UPDATE : this appears to be Cerber]. From :...
2 comments:
Thursday, 12 January 2017

Scam: 01254522444, the fake BT engineer and 888DCA60-FC0A-11CF-8F0F-00C04FD7D062

›
In the past few weeks I have seen a huge upsurge in the number of Indian tech support scammers ringing, both at home and my place of work....
29 comments:
Friday, 23 December 2016

02085258899 - tech support scam (using anydesk.com, teamviewer.com and supremofree.com)

›
If these people ring you DO NOT GIVE THEM ACCESS TO YOUR PC and either hang up - or waste their time like I do. It seems there are some...
2 comments:
Monday, 19 December 2016

Malware spam: "Payslip for the month Dec 2016." leads to Locky

›
This fake financial spam leads to Locky ransomware: From :    PATRICA GROVES Date :    19 December 2016 at 10:12 Subject :    Payslip f...
Thursday, 15 December 2016

Malware spam: "Payment Processing Problem" leads to Locky

›
This fake financial spam leads to Locky ransomware: From :    Juliet Langley Date :    15 December 2016 at 23:17 Subject :    Payment P...

Malware spam: "Amount Payable" leads to Locky

›
This fake financial spam leads to Locky ransomware: From :    Lynn Drake Date :    15 December 2016 at 09:55 Subject :    Amount Payabl...
1 comment:
Monday, 12 December 2016

Malware spam: "New(910)" leads to Locky

›
This spam leads to Locky ransomware: From :    Savannah [Savannah807@victimdomain.tld] Reply-To :    Savannah [Savannah807@victimdomai...

Malware spam: "Invoice number: 947781" leads to Locky

›
This fake financial spam comes from multiple senders and leads to Locky ransomware: From :    AUTUMN RHINES Date :    12 December 201...
Friday, 9 December 2016

Malware spam: "Firewall Software" leads to Locky

›
This spam appears to come from multiple senders and leads to Locky ransomware: From :    Herman Middleton Date :    9 December 2016 at ...
Monday, 5 December 2016

Malware spam: "Shipping status changed for your parcel # 1996466" / ups@ups-service.com

›
This fake UPS spam has a malicious attachment: From :    UPS Quantum View [ups@ups-service.com] Date :    5 December 2016 at 17:38 Su...
2 comments:

Malware spam: "Please Consider This" leads to Locky

›
This fake financial spam leads to malware: From :    Aimee Guy Date :    5 December 2016 at 13:32 Subject :    Please Consider This Dea...

Malware spam: "Emailing: _9376_924272" / "No subject" leads to ".osiris" Locky.

›
This spam comes in a few different variants, and it leads to Locky ransomware encrypting files with an extension ".osiris" The...
Tuesday, 29 November 2016

Fake eFax spam uses hacked Sharepoint to spread malware

›
This fake fax leads to a malicious ZIP file: From :    eFax [message@inbound-efax.org] Date :    29 November 2016 at 16:01 Subject :   ...
1 comment:

Malware spam: "Please find attached a XLS Invoice 378296" / creditcontrol@somecompany.com / Ansell Lighting

›
This fake financial spam comes with a malicious attachment, purporting to come from Ansell Lighting: Subject :     Please find attached...
Friday, 25 November 2016

Malware spam: [Vigor2820 Series] New voice mail message from 014xxxxxxxx on %date%

›
This fake voicemail spam leads to Locky ransomware and appears to come from within the victim's own domain, but this is just a simple ...

Malware spam: "Important Information" leads to Locky

›
This spam leads to Locky ransomware: Subject :     Important Information From :     Etta Figueroa Date :     Friday, 25 November 2016, ...

Moar Locky 2016-11-25

›
This data comes from my trusted usual source, so far I have only seen a single example. This morning's spam run has a subject with o...
Wednesday, 23 November 2016

Malware spam: "financial records subpoena" / lawfirmofoklahoma.com

›
This spam purports to come from Michael T Diver who is a real Oklahoma attorney, but it doesn't really and is jut a simple forgery: ...
1 comment:

Moar Locky: "Bill-12345" from victim's own domain

›
This spam has no body text and appears to come from within the sender's own domain. It leads to Locky ransomware. For example: From...
‹
›
Home
View web version
Powered by Blogger.