massive malspam campaign delivering Ursnif banking Trojan via js files

We have been seeing a massive malspam campaign today delivering Ursnif banking Trojan via js files inside zips. There have been numerous different subjects and campaign themes I will detail some of them here: Our reference: 733092244 pretending to come from Eli Murchison <Hughchaplin@yahoo.de> Hotel booking confirmation (Id:022528) pretending to Continue reading → Continue reading massive malspam campaign delivering Ursnif banking Trojan via js files

fake spoofed DHL Shipment Notification delivers some sort of unknown malware

Continuing with the never ending series of malware downloaders is an email with the subject of DHL Shipment Notification : 1104749373 pretending to come from DHL Customer Support <support@dhl.com>  with a semi-random named zip attachment in the format of Pickup EXPRESS .Date2017-04-26.zip  which delivers or tries to deliver some sort of malware. This is a … Continue reading → Continue reading fake spoofed DHL Shipment Notification delivers some sort of unknown malware

More USPS delivering Zbot Zeus Panda via fake Word online sites

We are so used to seeing USPS, UPS, DHL. FEDEX and all the other delivery companies being spoofed with emails pretending to be from them delivering all sorts of malware, usually via zip attachments containing JavaScript files. There have been 2 main campaigns that I have documented HERE and HERE Recently the … Continue reading → Continue reading More USPS delivering Zbot Zeus Panda via fake Word online sites

Changes to fake USPS delivery messages delivering malware

We have all become accustomed to seeing USPS, UPS, DHL. FEDEX and all the other delivery companies being spoofed with emails pretending to be from them delivering all sorts of malware, usually via zip attachments containing JavaScript files. There have been 2 main campaigns that I have documented HERE and HERE Recently … Continue reading → Continue reading Changes to fake USPS delivery messages delivering malware

More USPS delivery messages delivering mole ransomware

We are so used to seeing  USPS, UPS, DHL. FEDEX and all the other delivery companies being spoofed and emails pretending to be from them delivering all sorts of malware, usually via zip attachments containing JavaScript files. I saw this post on Sans Security blog yesterday  and expected that I … Continue reading → Continue reading More USPS delivery messages delivering mole ransomware

more spoofed DHL Delivery malspam delivers malware

Continuing with the never ending series of malware downloaders spoofing DHL  is an email with the subject of DHL Delivery coming or pretending to come from DHL Express UK. These do look very realistic and if you are expecting a delivery today ( many recipients will be) you can be very easily … Continue reading → Continue reading more spoofed DHL Delivery malspam delivers malware

USPS Delivery Confirmation malspam email tries to deliver malware but fails

The next in the never ending series of malware downloaders is an email with the subject of  USPS Delivery Confirmation pretending to come from USPS Delivery Department <ecnpbsog@sling-ease.com> that attempts to download malware but currently fails. They use email addresses and subjects … Continue reading →

Source

Continue reading USPS Delivery Confirmation malspam email tries to deliver malware but fails

USPS Delivery Confirmation malspam email tries to deliver malware but fails

The next in the never ending series of malware downloaders is an email with the subject of  USPS Delivery Confirmation pretending to come from USPS Delivery Department <ecnpbsog@sling-ease.com> that attempts to download malware but currently fails. They use email addresses and subjects … Continue reading →

Source

Continue reading USPS Delivery Confirmation malspam email tries to deliver malware but fails

malspam email Wrong tracking number delivers Locky

The next in the never ending series of Locky downloaders is an email with the subject of  Wrong tracking number coming as usual from random companies, names and email addresses  with a semi-random named zip attachment starting with  tracking_number_ containing … Continue reading →

Source

Continue reading malspam email Wrong tracking number delivers Locky

Fake / spoofed FedEx ” unable to deliver” malspam emails continue to deliver ransomware

We are seeing an uptick in the FedEx ” unable to deliver” malspam emails this week. We see them daily and I don’t normally bother to post about them, because they are so common and I always get 1 or … Continue reading →

Source

Continue reading Fake / spoofed FedEx ” unable to deliver” malspam emails continue to deliver ransomware