Great British Prank: Company Name Contains XSS Hack

A prankster registered a British company name containing a cross-site scripting (XSS) attack. Hilarity ensued.
The post Great British Prank: Company Name Contains XSS Hack appeared first on Security Boulevard.
Continue reading Great British Prank: Company Name Contains XSS Hack

Fake Companies House “Company report” delivers Trickbot

We are back to a slightly more complicated or involved Trickbot download campaign today with links in the email to download the XLS file instead of attachments. This malware campaign delivery method was first mentioned on 22 October 2018 when I missed … Continue reading Fake Companies House “Company report” delivers Trickbot

Fake Companies House WebFiling Authentication Code delivers Trickbot

This example is an email containing the subject of “WebFiling Authentication Code” pretending to come from Companies House but actually coming from “web-filing@companiesshouse.co.uk” which is a look-a-like,  typo-squatted or oth… Continue reading Fake Companies House WebFiling Authentication Code delivers Trickbot

fake Companies House eReminder Service delivers Trickbot

This example is an email containing the subject of “Urgent Action is required. – Companies House eReminder Service ” pretending to come from ereminders@companieshouse.gov.uk  but actually coming from “DoNotReply@gov-delivery.uk&… Continue reading fake Companies House eReminder Service delivers Trickbot

Trickbot via Fake Companies House E-billing “June’s Invoices / Documents ” malspam

Trickbot is back targeting the UK again today after a short break. This example is an email containing the subject of “June’s Invoices / Documents ” pretending to come from Companies House eBilling but actually coming from a look-a-li… Continue reading Trickbot via Fake Companies House E-billing “June’s Invoices / Documents ” malspam

Fake Companies House “CC(01) Company Complaint – 5GBV2LXEK5ULLKW” delivers Ursnif banking trojan via BlackTDS

  Following on from last Thursday and Friday when a ursnif campaign spoofing HMRC started to use blacktds via compromised SharePoint sites we have a fake Companies House campaign today using the same system. Blacktds is a method of severely restri… Continue reading Fake Companies House “CC(01) Company Complaint – 5GBV2LXEK5ULLKW” delivers Ursnif banking trojan via BlackTDS

Fake Companies House Company ID : XXXXX391 malspam delivers Trickbot banking Trojan

An email with the subject of Company ID : XXXXX391 pretending to come from Companies House but actually coming from a look-a-like domain Companies House <message@companieshouseemail.uk>   or  Companies House <message@companieshousemail.uk> with a malicious word doc attachment  is today’s latest spoof of a well known company, bank or public authority delivering Trickbot Continue reading → Continue reading Fake Companies House Company ID : XXXXX391 malspam delivers Trickbot banking Trojan

another fake companies house complaint malspam delivering a banking trojan

An email with the subject of Company Complaint pretending to come from Companies House  but actually coming from a look-a-like domain Companies House <Web.Fillings@companieshousecomplaint.co.uk>  with a malicious word doc attachment  is today’s latest spoof of a well known company, bank or public authority delivering a banking Trojan which will either be Trickbot, Continue reading → Continue reading another fake companies house complaint malspam delivering a banking trojan

another fake companies house complaint malspam delivering a banking trojan

An email with the subject of Company Complaint pretending to come from Companies House  but actually coming from a look-a-like domain Companies House <Web.Fillings@companieshousecomplaint.co.uk>  with a malicious word doc attachment  is today’s latest spoof of a well known company, bank or public authority delivering a banking Trojan which will either be Trickbot, Continue reading → Continue reading another fake companies house complaint malspam delivering a banking trojan

Spoofed Companies House FW: Case C238260756 delivers unknown malware

An email with the subject of FW: Case C238260756  message pretending to come from Companies House  but actually coming from a look alike domain WebFiling@companieshousewebfilling.co.uk with a malicious  attachment  is today’s latest spoof of a well known company, bank or public authority delivering  some sort of malware This is Trickbot banking Trojan. Continue reading → Continue reading Spoofed Companies House FW: Case C238260756 delivers unknown malware