Info collector

Latest SPAM

Malware spam: “Invoice RE-2017-09-21-00xxx” from “Amazon Marketplace”

By on September 21, 2017 in Latest SPAM

This fake Amazon spam comes with a malicious attachment: Subject:       Invoice RE-2017-09-21-00794 From:       “Amazon Marketplace” [yAhbPDAoufvZE@marketplace.amazon.co.uk] Date:       Thu, September 21, 2017 9:21 am Priority:       Normal ————- Begin message ————- Dear customer, We want to use this opportunity to first say “Thank you very much for your purchase!”

Continue Reading »

Malware spam: “Status of invoice” with .7z attachment

By on September 18, 2017 in Latest SPAM

This spam leads to Locky ransomware: Subject:       Status of invoiceFrom:       “Rosella Setter” ordering@[redacted]Date:       Mon, September 18, 2017 9:30 amHello,Could you please let me know the status of the attached invoice? Iappreciate your help!Best regards,Rosella SetterTel: 206-575-8068 x 100 Fax: 206-575-8094*NEW*   Ordering@[redacted].com* Kindly note we will be closed Monday in

Continue Reading »

QTUM Cryptocurrency spam

By on September 6, 2017 in Latest SPAM

This spam email appears to be sent by the Necurs botnet, advertising a new Bitcoin-like cryptocurrency called QTUM. Necurs is often used to pump malware, pharma and data spam and sometimes stock pump and dump. There is no guarantee that this is actually being sent by the people running QTUM, it could simply be a […]

Continue Reading »

Malware spam: “Scanning” pretending to be from tayloredgroup.co.uk

By on September 5, 2017 in Latest SPAM

This spam email pretends to be from tayloredgroup.co.uk but it is just a simple forgery leading to Locky ransomware. There is both a malicious attachment and link in the body text. The name of the sender varies. Subject:       ScanningFrom:       “Jeanette Randels” [Jeanette.Randels@tayloredgroup.co.uk]Date:       Thu, May 18, 2017 8:26 pmhttps://dropbox.com/file/9A30AA– Jeanette Randels

Continue Reading »

Malware spam: “Voicemail Service” / “New voice message..”

By on August 25, 2017 in Latest SPAM

The jumble of numbers in this spam is a bit confusing. Attached is a malicious RAR file that leads to Locky ransomware. Subject:       New voice message 18538124076 in mailbox 185381240761 from “18538124076” From:       “Voicemail Service” [vmservice@victimdomain.tdl]Date:       Fri, August 25, 2017 12:36 pmDear user:just wanted to let you know you were just left […]

Continue Reading »

Malware spam: “Your Sage subscription invoice is ready” / noreply@sagetop.com

By on August 25, 2017 in Latest SPAM

This fake Sage invoice leads to Locky ransomware. Quite why Sage are picked on so much by the bad guys is a bit of a mystery. Subject:       Your Sage subscription invoice is readyFrom:       “noreply@sagetop.com” [noreply@sagetop.com]Date:       Thu, August 24, 2017 8:49 pmDear CustomerYour Sage subscription invoice is now ready to view.Sage subscriptions To […]

Continue Reading »

Multiple badness on metoristrontgui.info / 119.28.100.249

By on August 24, 2017 in Latest SPAM

Two massive fake “Bill” spam runs seem to be under way, one claiming to be from BT and the other being more generic. Subject:       New BT BillFrom:       “BT Business” [btbusiness@bttconnect.com]Date:       Thu, August 24, 2017 6:08 pmPriority:       NormalFrom BTNew BT BillYour bill amount is: $106.84This doesn’t include any amounts brought forward from […]

Continue Reading »

Malware spam: “Customer Service” / “Copy of Invoice xxxx”

By on August 23, 2017 in Latest SPAM

This fairly generic spam leads to the Locky ransomware: Subject:       Copy of Invoice 3206From:       “Customer Service” Date:       Wed, August 23, 2017 9:12 pmPlease download file containing your order information.If you have any further questions regarding your invoice, please call Customer Service.Please do not reply directly to this automatically generated e-mail message.Thank

Continue Reading »

Malware spam: “Voice Message Attached from 0xxxxxxxxxxx – name unavailable”

By on August 23, 2017 in Latest SPAM

This fake voice mail message leads to malware. It comes in two slightly different versions, one with a RAR file download and the other with a ZIP. Subject:       Voice Message Attached from 001396445685 – name unavailable From:       “Voice Message” Date:       Wed, August 23, 2017 10:22 am Time: Wed, 23 Aug 2017 14:52:12 […]

Continue Reading »

Malware spam from “Voicemail Service” [pbx@local]

By on August 22, 2017 in Latest SPAM

This fake voicemail leads to malware: Subject:       [PBX]: New message 46 in mailbox 461 from “460GOFEDEX” From:       “Voicemail Service” [pbx@local] Date:       Tue, August 22, 2017 10:37 am To:       “Evelyn Medina” Priority:       Normal Dear user:         just wanted to let you know you were just left a 0:53 long message (number […]

Continue Reading »

Top