Fake HERBALIFE Order Number invoice malspam delivers Locky ykcol

The next in the never ending series of Locky downloaders is an email with the subject of  HERBALIFE Order Number: 6N01000137 ( random numbers)   pretending to come from Herbalife <svc_apacnts_8169@herbalife.com> (random numbers as well ). Today’s version continue to use the ykcol  extension for encrypted files. They use email addresses and Continue reading → Continue reading Fake HERBALIFE Order Number invoice malspam delivers Locky ykcol

Fwd: Re: Invoice with a r24 extension delivers ( or tries to deliver) malware

Following on from Yesterday’s attempt with a .r24 attachment the next in the never ending series of malware downloaders is an email with the subject of  FW:: Re: invoice pretending to come from Care@Jafra.co.id The email content is identical to yesterday’s version. They use email addresses and subjects that will persuade, entice, shock or Continue reading → Continue reading Fwd: Re: Invoice with a r24 extension delivers ( or tries to deliver) malware

Re: Revised invoice malspam tries to delivers malware using an r24 extension

The next in the never ending series of malware downloaders is an email with the subject of  Re: Revised invoice pretending to come from Sales <Sales@machinery.com> They use email addresses and subjects that will entice a user to read the email and open the attachment. machinery.com has not been hacked or had their Continue reading → Continue reading Re: Revised invoice malspam tries to delivers malware using an r24 extension

more Necurs botnet sent fake invoices deliver malware

The next in the never ending series of malware downloaders being sent from the Necurs botnet is a typical generic spam email with the subject of  Copy of Invoice 487391( random numbers)  pretending to come from Customer Service <service@randomdomain.tld>. There is no attachment with these today, just a link in the email body Continue reading → Continue reading more Necurs botnet sent fake invoices deliver malware

Spoofed DNB bank ( Norway) Viktig – Sikre documenter delivers Trickbot banking Trojan

An email with the subject of Viktig – Sikre documenter pretending to come from DNB (A Norweigian bank ) but actually coming from a look-a-like domain DNB <secure@dnbdocs.com>  or  DNB <secure@dnbdoc.com> with a malicious word doc attachment  is today’s latest spoof of a well-known company, bank or public authority delivering Trickbot Continue reading → Continue reading Spoofed DNB bank ( Norway) Viktig – Sikre documenter delivers Trickbot banking Trojan

New BT Online bill malspam delivers Dridex banking trojan

An email with the subject of New BT Online bill pretending to come from BT but actually coming from a different domain btbusiness@bt-europe.com  that can very easily be mistaken for a genuine BT email address is today’s latest spoof of a well-known company, bank or public authority delivering Dridex banking Continue reading → Continue reading New BT Online bill malspam delivers Dridex banking trojan

How to disable or hide the search box in Internet Explorer 11’s navigation bar

The September 2017 monthly rollup for W7  (KB4038777), W8.1 (KB4038792) and  W10 (KB4038782) which includes the Cumulative Internet Explorer Security  update has changed the layout and behaviour of Internet Explore 11. This update has brought back the search box beside the URL bar. This update also automatically changes tabs to be Continue reading → Continue reading How to disable or hide the search box in Internet Explorer 11’s navigation bar

Posted in Uncategorized

Fake Your Amazon.co.uk order has been dispatched tries to deliver malware

The next in the never ending series of malware downloaders coming from the Necurs botnet  is an email with the subject of  Your Amazon.co.uk order 172-3041149-3373628 has been dispatched ( random numbers)  pretending to come from Amazon.co.uk <auto-shipping@amazon.co.uk> These will be supposed to deliver either Locky Ransomware of Trickbot banking Continue reading → Continue reading Fake Your Amazon.co.uk order has been dispatched tries to deliver malware

Fake Your Amazon.co.uk order has been dispatched tries to deliver malware

The next in the never ending series of malware downloaders coming from the Necurs botnet  is an email with the subject of  Your Amazon.co.uk order 172-3041149-3373628 has been dispatched ( random numbers)  pretending to come from Amazon.co.uk <auto-shipping@amazon.co.uk> These will be supposed to deliver either Locky Ransomware of Trickbot banking Continue reading → Continue reading Fake Your Amazon.co.uk order has been dispatched tries to deliver malware

Fake Bankwest – You have a new eStatement mass malspam delivers Trickbot Banking Trojan

The next in the never ending series of Trickbot banking Trojan  downloaders is an email with the subject of  Bankwest – You have a new eStatement pretending to come from Bankwest <bob.mailbox@bankwest.com.au> They use email addresses and subjects that will entice a user to read the email and open the attachment. Bankwest Continue reading → Continue reading Fake Bankwest – You have a new eStatement mass malspam delivers Trickbot Banking Trojan