Japanese language spoofed travel reservation and invoice malspam delivers Ursnif banking Trojan

Continuing with the never ending series of malware downloaders is a Japanese language malspam email with the subject of 予約完了[るるぶトラベル] (Reservation complete [Ruu Travel])   pretending to come from support@rurubu.travel with a zip attachment with a Japanese character set name  which delivers ursnif / Gozi / ISFB banking Trojan. We are also seeing these Continue reading → Continue reading Japanese language spoofed travel reservation and invoice malspam delivers Ursnif banking Trojan

fake Japan Post Express Mail Service (EMS) malspam delivers Ursnif /Gozi /Papras banking trojan

Continuing with the regular series of Japanese language malspam emails is today’s overnight onslaught with the subject of Express Mail Service (EMS) pretending to come from japanexpress@post.japanpost.jp. I am also getting a lot of emails with a malformed subject line ?iso-2022-jp?B?RU1TGyRCR1tDIz51NjckTjNORycbKEIgLSAbJEJNOUpYNkkbKEIgLSAbJEJGfEtcTTlALxsoQg==?=   or  ?iso-2022-jp?B?GyRCTT05cEw1JDckTk8iTW1AaEpROTkkZCUiJUklbCU5SlE5ORsoQiA=?=  which I assume is an encoding error and it is … Continue reading → Continue reading fake Japan Post Express Mail Service (EMS) malspam delivers Ursnif /Gozi /Papras banking trojan

fake Japan Post Express Mail Service (EMS) malspam delivers Ursnif /Gozi /Papras banking trojan

Continuing with the regular series of Japanese language malspam emails is today’s overnight onslaught with the subject of Express Mail Service (EMS) pretending to come from japanexpress@post.japanpost.jp. I am also getting a lot of emails with a malformed subject line ?iso-2022-jp?B?RU1TGyRCR1tDIz51NjckTjNORycbKEIgLSAbJEJNOUpYNkkbKEIgLSAbJEJGfEtcTTlALxsoQg==?=   or  ?iso-2022-jp?B?GyRCTT05cEw1JDckTk8iTW1AaEpROTkkZCUiJUklbCU5SlE5ORsoQiA=?=  which I assume is an encoding error and it is … Continue reading → Continue reading fake Japan Post Express Mail Service (EMS) malspam delivers Ursnif /Gozi /Papras banking trojan

more Japanese language “photos” malspam delivers malware

Looks like we are back to Japanese malspam today with  an email with the subject of 写真 ( photo)  coming or pretending to come from random companies, names and email addresses with a semi-random named zip attachment   which delivers malware which looks like Ursnif banking Trojan I don’t suppose many UK … Continue reading → Continue reading more Japanese language “photos” malspam delivers malware