Info collector

Archive for December, 2016

02085258899 – tech support scam (using anydesk.com, teamviewer.com and supremofree.com)

By on December 23, 2016 in Latest SPAM

If these people ring you DO NOT GIVE THEM ACCESS TO YOUR PC and either hang up – or waste their time like I do. It seems there are some prolific technical support scammers ringing from 02085258899 pretending to be from BT. They had a very heavy Indian accent, and they have made many silent […]

Continue Reading »

Malware spam: “Payslip for the month Dec 2016.” leads to Locky

By on December 19, 2016 in Latest SPAM

This fake financial spam leads to Locky ransomware: From:    PATRICA GROVESDate:    19 December 2016 at 10:12Subject:    Payslip for the month Dec 2016.Dear customer,We are sending your payslip for the month Dec 2016 as an attachment with this mail.Note: This is an auto-generated mail. Please do not reply. The name of the sender will vary. Attached […]

Continue Reading »

Malware spam: “Payment Processing Problem” leads to Locky

By on December 15, 2016 in Latest SPAM

This fake financial spam leads to Locky ransomware: From:    Juliet LangleyDate:    15 December 2016 at 23:17Subject:    Payment Processing ProblemDear [redacted],We have to inform you that a problem occured when processing your last payment (code: 3132224-M, $789.$63).The receipt is in the attachment. Please study it and contact us.-King Regards,Juliet Langley The name of the sender will

Continue Reading »

Malware spam: “Amount Payable” leads to Locky

By on December 15, 2016 in Latest SPAM

This fake financial spam leads to Locky ransomware: From:    Lynn DrakeDate:    15 December 2016 at 09:55Subject:    Amount PayableDear [redacted],The amount payable has come to $38.29. All details are in the attachment.Please open the file when possible.-Best Regards,Lynn Drake The name of the sender will vary, although the dollar amount seems consistent in all the samples […]

Continue Reading »

Malware spam: “New(910)” leads to Locky

By on December 12, 2016 in Latest SPAM

This spam leads to Locky ransomware: From:    Savannah [Savannah807@victimdomain.tld] Reply-To:    Savannah [Savannah807@victimdomain.tld] Date:    12 December 2016 at 09:50 Subject:    New(910) Scanned by CamScanner Sent from Yahoo Mail on Android The spam appears to come from a sender within the victim’s own domain, but this is just a simple forgery. The attachment name is a .DOCM […]

Continue Reading »

Malware spam: “Invoice number: 947781” leads to Locky

By on December 12, 2016 in Latest SPAM

This fake financial spam comes from multiple senders and leads to Locky ransomware: From:    AUTUMN RHINES Date:    12 December 2016 at 10:40 Subject:    Invoice number: 947781 Please find attached a copy of your invoice. Tel: 0800 170 7234 Fax: 0161 850 0404 For all your stationery needs please visit Stationerybase. The name of the sender […]

Continue Reading »

Malware spam: “Firewall Software” leads to Locky

By on December 9, 2016 in Latest SPAM

This spam appears to come from multiple senders and leads to Locky ransomware: From:    Herman MiddletonDate:    9 December 2016 at 07:40Subject:    Firewall SoftwareHey [redacted], it is Herman. You’ve asked me to order new firewall software for our office computers.Done and ready. Here, in the attachment, is the full invoice of the software counteragent.Please check it […]

Continue Reading »

SMS phish: “Your AppIe ID is due to expire today.” / appieid-support.com

By on December 6, 2016 in Latest SPAM

This SMS spam is actually a phishing message: AppCareFinal NotificationYour AppIe ID is due to expire today. Prevent this by confirming your AppIe ID at http://appIeid-support.comAppIe Inc Note that the "l" in all the mentions of "Apple" has been substituted with an uppercase "I" which is quite hard to tell. This is one of those […]

Continue Reading »

Malware spam: “Shipping status changed for your parcel # 1996466” / ups@ups-service.com

By on December 5, 2016 in Latest SPAM

This fake UPS spam has a malicious attachment: From:    UPS Quantum View [ups@ups-service.com] Date:    5 December 2016 at 17:38 Subject:    Shipping status changed for your parcel # 1996466 Your parcel has arrived, but we were unable to successfully deliver it because no person was present at the destination address. There must be someone present at […]

Continue Reading »

Malware spam: “Please Consider This” leads to Locky

By on December 5, 2016 in Latest SPAM

This fake financial spam leads to malware: From:    Aimee GuyDate:    5 December 2016 at 13:32Subject:    Please Consider ThisDear [redacted],Our accountants have noticed a mistake in the payment bill #DEC-5956047.The full information regarding the mistake, and further recommendations are in the attached document.Please confirm the amount and let us know if you have any questions. Attached

Continue Reading »

Top