more fake voicemail messages [PBX]: New message 10 in mailbox 101 from “100GOFEDEX” delivers Locky

The next in the never ending series of Locky downloaders is an email with the subject of  [PBX]: New message 10 in mailbox 101 from “100GOFEDEX” <7820413853> pretending to come from Voicemail Service <pbx@local> The new message number, mailbox number, gofedex number and telephone number are all random. All of Continue reading → Continue reading more fake voicemail messages [PBX]: New message 10 in mailbox 101 from “100GOFEDEX” delivers Locky

Fake spoofed HSBC Payments request delivers Trickbot banking Trojan

An email with the subject of Payments request  pretending to come from HSBC  but actually coming from a look-a-like domain <message@hsbc-mail.co.uk>  with a malicious word doc attachment  is today’s latest spoof of a well known company, bank or public authority delivering Trickbot banking Trojan They are using email addresses and subjects that Continue reading → Continue reading Fake spoofed HSBC Payments request delivers Trickbot banking Trojan

Metro Bank – Important Information about your account – Phishing

We see lots of phishing attempts for your bank details. Metro bank is one of the UK smaller banks which is quite new  and I don’t often see them targetted. They use email addresses and subjects that will entice a user to read the email and open the attachment. A Continue reading → Continue reading Metro Bank – Important Information about your account – Phishing

Fake O2 bill delivers Emotet banking Trojan

Continuing with the never ending series of malware downloaders is an email with the subject of My O2 Business – Your O2 Bill is ready – (recipient’s name) coming from random senders  which delivers Emotet banking Trojan There has also been several different fake invoice versions spoofing or faking various companies, some Continue reading → Continue reading Fake O2 bill delivers Emotet banking Trojan

More fake, spoofed , imitated NatWest Bank Financial Statement delivering Trickbot banking Trojan

Following on from Friday’s Trickbot failure imitating / spoofing Natwest Bank we start Monday with a working copy An email with the subject of NatWest pretending to come from NatWest but actually coming from a look-a-like domain New post NatWest Bank <noreply@natwest96.ml> with a malicious word doc attachment is today’s Continue reading → Continue reading More fake, spoofed , imitated NatWest Bank Financial Statement delivering Trickbot banking Trojan

Your order no 8194788 has been processed malspam delivers malware

Continuing with the never ending series of malware downloaders is an email with the subject of Your order no 8194788 ( random numbers) has been processed coming from random  names @ creatingkindly.com which delivers some sort of malware eventually. These pretend to be an order confirmation for cotton material  from a random Continue reading → Continue reading Your order no 8194788 has been processed malspam delivers malware

Outstanding invoices email 1 of 2 malspam delivers Locky ransomware

An email with the subject of Outstanding invoices email 1 of 2 pretending to come from  random names and email addresses with a malicious word doc attachment  delivers Locky Ransomware They are using email addresses and subjects that will scare or entice a user to read the email and open the attachment. Remember Continue reading → Continue reading Outstanding invoices email 1 of 2 malspam delivers Locky ransomware

another fake / spoofed Natwest bank malspam from the Trickbot gang that currently fails

It looks like the apprentice must be in charge today at the Trickbot HQ. The first round of emails are being sent malformed with no body content, no subject and no malware attachment. It is very kind of them to give us a heads up which bank they are spoofing Continue reading → Continue reading another fake / spoofed Natwest bank malspam from the Trickbot gang that currently fails

another fake / spoofed Natwest bank malspam from the Trickbot gang that currently fails

It looks like the apprentice must be in charge today at the Trickbot HQ. The first round of emails are being sent malformed with no body content, no subject and no malware attachment. It is very kind of them to give us a heads up which bank they are spoofing Continue reading → Continue reading another fake / spoofed Natwest bank malspam from the Trickbot gang that currently fails

fake Xero accounting software invoice delivers Dridex banking Trojan

Continuing with the never ending series of malware downloaders is an email with the subject of Your Xero Invoice INV-0855485  coming from subscription.notifications@xeronet.org which uses compromised sharepoint aka onedrive for business accounts to deliver Dridex banking Trojan Note: this was forwarded to me by a contact this morning who received it yesterday. Continue reading → Continue reading fake Xero accounting software invoice delivers Dridex banking Trojan