massive malspam campaign delivering Ursnif banking Trojan via js files

We have been seeing a massive malspam campaign today delivering Ursnif banking Trojan via js files inside zips. There have been numerous different subjects and campaign themes I will detail some of them here: Our reference: 733092244 pretending to come from Eli Murchison <Hughchaplin@yahoo.de> Hotel booking confirmation (Id:022528) pretending to Continue reading → Continue reading massive malspam campaign delivering Ursnif banking Trojan via js files

fake spoofed DHL Shipment Notification delivers some sort of unknown malware

Continuing with the never ending series of malware downloaders is an email with the subject of DHL Shipment Notification : 1104749373 pretending to come from DHL Customer Support <support@dhl.com>  with a semi-random named zip attachment in the format of Pickup EXPRESS .Date2017-04-26.zip  which delivers or tries to deliver some sort of malware. This is a … Continue reading → Continue reading fake spoofed DHL Shipment Notification delivers some sort of unknown malware

more spoofed DHL Delivery malspam delivers malware

Continuing with the never ending series of malware downloaders spoofing DHL  is an email with the subject of DHL Delivery coming or pretending to come from DHL Express UK. These do look very realistic and if you are expecting a delivery today ( many recipients will be) you can be very easily … Continue reading → Continue reading more spoofed DHL Delivery malspam delivers malware

Refund pretending to come from random delivery, parcel or postal companies malspam delivers Locky

The next in the never ending series of Locky downloaders is an email with the subject of  Refund pretending to come from various randomly chosen delivery, parcel or postal companies with a semi random named zip attachment starting with refund  containing a WSF … Continue reading →

Source

Continue reading Refund pretending to come from random delivery, parcel or postal companies malspam delivers Locky

even more DHL cannot deliver your parcel malspam delivers malware

This one is somewhat different to the Locky downloader I posted about at the end of last week. An email with the subject of  Undelivered Parcel With DHL pretending to come from   Ida MIROIR <Ida.MIROIR@umons.ac.be> with a html attachment which  when … Continue reading →

Source

Continue reading even more DHL cannot deliver your parcel malspam delivers malware

another DHL cannot deliver your parcel malspam delivers Locky

The next in the never ending series of Locky downloaders is an email pretending to be a DHL cannot deliver message with the subject of  Parcel details coming as usual from random companies, names and email addresses  with a semi- random named … Continue reading →

Source

Continue reading another DHL cannot deliver your parcel malspam delivers Locky

Package #DH4946376 pretending to be a DHL unable to deliver message delivers Locky

The next in the never ending series of Locky downloaders is an email with the subject of  Package #DH4946376 [ random numbers ] pretending to come from DHL but actually coming as usual from random  email addresses  with a random … Continue reading →

Source

Continue reading Package #DH4946376 pretending to be a DHL unable to deliver message delivers Locky

Ihre Bestellung ist auf dem Weg zu Ihnen! OrderID 79872 malspam delivers Locky

The next in the never ending series of Locky downloaders is a German language  email with the subject of  Ihre Bestellung ist auf dem Weg zu Ihnen!  OrderID 79872 ( random number) pretending to come from   Kids Party World <service@kids-party-world.de> … Continue reading →

Source

Continue reading Ihre Bestellung ist auf dem Weg zu Ihnen! OrderID 79872 malspam delivers Locky

SPAM MALWARE: shipment address confirmation (re-send)

An email with the subject of shipment address confirmation (re-send) pretending to come from info <info@dhl-services.com>  with a zip attachment that extracts to a  malicious word doc   is another one from the current bot runs which try to download various Trojans and password stealers … Continue reading →

Source

Continue reading SPAM MALWARE: shipment address confirmation (re-send)

Your latest DHL invoice : HSC4387902 – JS malware leads to Locky Ransomware

Last revised or Updated on: 7th March, 2016, 11:23 AMAn email with the subject of  Your latest DHL invoice : HSC4387902 [ random numbered]  pretending to come from e-billing@dhl.com  with a zip attachment is another one from the current bot runs which downloads Locky ransomware. They use email addresses and subjects that will entice a user to read the email and open the attachment. A very high proportion are being targeted at small and medium size businesses, with the hope of getting a better response than they do from consumers. The email looks like: From: e-billing@dhl.com Date: Mon 07/03/2016 10:53 Subject: Your latest DHL invoice : HSC4387902 Attachment:HSC4387902.zip Body content: THIS IS AN AUTOMATED MESSAGE, DO NOT REPLY Dear Customer, Please find attached … Continue reading → Continue reading Your latest DHL invoice : HSC4387902 – JS malware leads to Locky Ransomware