Dynamoo's Blog

Malware, spam, scams and random stuff, by Conrad Longmore.

Thursday, 28 September 2017

Malware spam: "Emailing: Scan0xxx" from "Sales" delivers Locky or Trickbot

›
This fake document scan delivers different malware depending on the victim's location: Subject :       Emailing: Scan0963 From :  ...
2 comments:
Tuesday, 26 September 2017

Malware spam: "AutoPosted PI Notifier"

›
This spam has a .7z file leading to Locky ransomware. From :      "AutoPosted PI Notifier" [NoReplyMailbox@redacted.tld] Subj...
Thursday, 21 September 2017

Malware spam: "Invoice RE-2017-09-21-00xxx" from "Amazon Marketplace"

›
This fake Amazon spam comes with a malicious attachment: Subject :       Invoice RE-2017-09-21-00794 From :       "Amazon Marketp...
4 comments:
Monday, 18 September 2017

Malware spam: "Status of invoice" with .7z attachment

›
This spam leads to Locky ransomware: Subject :       Status of invoice From :       "Rosella Setter" ordering@[redacted] Da...
Wednesday, 6 September 2017

QTUM Cryptocurrency spam

›
This spam email appears to be sent by the Necurs botnet, advertising a new Bitcoin-like cryptocurrency called QTUM. Necurs is often used t...
1 comment:
Tuesday, 5 September 2017

Malware spam: "Scanning" pretending to be from tayloredgroup.co.uk

›
This spam email pretends to be from tayloredgroup.co.uk but it is just a simple forgery leading to Locky ransomware. There is both a mali...
Friday, 25 August 2017

Malware spam: "Voicemail Service" / "New voice message.."

›
The jumble of numbers in this spam is a bit confusing. Attached is a malicious RAR file that leads to Locky ransomware. Subject :      ...

Malware spam: "Your Sage subscription invoice is ready" / noreply@sagetop.com

›
This fake Sage invoice leads to Locky ransomware. Quite why Sage are picked on so much by the bad guys is a bit of a mystery. Subject ...
Thursday, 24 August 2017

Multiple badness on metoristrontgui.info / 119.28.100.249

›
Two massive fake "Bill" spam runs seem to be under way, one claiming to be from BT and the other being more generic. Subject ...
Wednesday, 23 August 2017

Malware spam: "Customer Service" / "Copy of Invoice xxxx"

›
This fairly generic spam leads to the Locky ransomware: Subject :       Copy of Invoice 3206 From :       "Customer Service" ...

Malware spam: "Voice Message Attached from 0xxxxxxxxxxx - name unavailable"

›
This fake voice mail message leads to malware. It comes in two slightly different versions, one with a RAR file download and the other wit...
1 comment:
Tuesday, 22 August 2017

Malware spam from "Voicemail Service" [pbx@local]

›
This fake voicemail leads to malware: Subject :       [PBX]: New message 46 in mailbox 461 from "460GOFEDEX" <8476446077...
1 comment:
Monday, 21 August 2017

Cerber spam: "please print", "images etc"

›
I only have a couple of samples of this spam, but I suspect it comes in many different flavours.. Subject :       images From :       ...
Wednesday, 19 July 2017

Necurs oddity II: avto111222@bigmir.net

›
Yesterday I saw a series spam emails from Necurs apparently attempting to collect replies to super.testtesttest2018@yahoo.com . Although t...
Tuesday, 18 July 2017

Necurs oddity: super.testtesttest2018@yahoo.com / "hi test"

›
This email is sent from the Necurs botnet and appears to be collecting automatic replies, using a Reply-To email address of super.testtest...
1 comment:

Malware spam: UK Fuels Collection / "invoices@ebillinvoice.com"

›
This fake invoice comes with a malicious attachment: From :    invoices@ebillinvoice.com Date :    18 July 2017 at 09:37 Subject :   ...
Tuesday, 13 June 2017

Bellatora Inc (ECGR) pump-and-dump spam

›
It's been a little while since we've since an illegal pump-and-dump spam from the Necurs botnet, but here is a new one pushing a ...
20 comments:
Monday, 5 June 2017

Malware spam: "John Miller Limited" / "Invoice"

›
This spam pretends to come from John Miller Ltd (but doesn't) and comes with a malicious payload. The domain mentioned in the email d...
Thursday, 11 May 2017

Malware spam with "nm.pdf" attachment

›
Currently underway is a malicious spam run with various subjects, for example: Scan_5902 Document_10354 File_43359 Senders are random,...
Tuesday, 2 May 2017

Malware spam: DHL Shipment 458878382814 Delivered

›
Another day and another fake DHL message leading to an evil .js script. From : DHL Parcel UK [redacted] Sent : 02 May 2017 09:30 To : [...
‹
›
Home
View web version
Powered by Blogger.