Fake Bank Of Scotland Important – Account Documents malspam delivers trickbot banking trojan

An email with the subject of Important – Account Documents pretending to come from Bank Of Scotland  but actually coming from a look-a-like domain Bank of Scotland <secure@bankofscotIand.com>  or Bank of Scotland <secure@bankofscotlanddocs.com> with a malicious word doc attachment  is today’s latest spoof of a well-known company, bank or public Continue reading → Continue reading Fake Bank Of Scotland Important – Account Documents malspam delivers trickbot banking trojan

another fake order email with rtf attachment delivers malware

An email with the subject of Fwd: Re: Order pretending to come from info@anashin.am with a malicious word doc attachment  delivers malware They are using email addresses and subjects that will scare or entice a user to read the email and open the attachment. A very high proportion are being targeted at Continue reading → Continue reading another fake order email with rtf attachment delivers malware

Emotet banking Trojan delivered by fake invoice reminder emails appearing to come from a known contact

A very simple email but potentially very dangerous and very likely to be opened, read and acted upon by the recipient. This was sent to a small charity that I administer the website and email service for. I managed to intercept the email, just in time. The alleged sender is Continue reading → Continue reading Emotet banking Trojan delivered by fake invoice reminder emails appearing to come from a known contact

Fwd: BL copy malspam uses RTF exploit CVE-2017-0199 to deliver malware

An email with the subject of Fwd: BL copy  coming from  pedro.estaba@cindu.com.ve with a malicious word doc  attachment  delivers malware using the  RTF exploit CVE-2017-0199. The word doc is actually a RTF doc. It is highly likely that recipients will get a similar email with different senders and email body content, imitating Continue reading → Continue reading Fwd: BL copy malspam uses RTF exploit CVE-2017-0199 to deliver malware

Pagamento malspam delivers malware

An Italian language email with the subject of Pagamento  pretending to come from rita.fossen@zwjnv.191.it  with a malicious Excel XLS spreadsheet attachment  delivers some sort of malware, most probably a Zeus Panda / Zbot variant They are using email addresses and subjects that will scare or entice a user to read the email and Continue reading → Continue reading Pagamento malspam delivers malware

Spoofed DNB bank ( Norway) Viktig – Sikre documenter delivers Trickbot banking Trojan

An email with the subject of Viktig – Sikre documenter pretending to come from DNB (A Norweigian bank ) but actually coming from a look-a-like domain DNB <secure@dnbdocs.com>  or  DNB <secure@dnbdoc.com> with a malicious word doc attachment  is today’s latest spoof of a well-known company, bank or public authority delivering Trickbot Continue reading → Continue reading Spoofed DNB bank ( Norway) Viktig – Sikre documenter delivers Trickbot banking Trojan

Trickbot delivered via fake eFax messages

An email with the subject of eFax pretending to come from EFax but actually coming from a whole range of look-a-like domains and for some strange reason today they are also coming from spoofed servicepaypal and NatWest domains with a malicious word doc attachment is today’s latest spoof of a well-known Continue reading → Continue reading Trickbot delivered via fake eFax messages

Another fake New Secure Message Royal Bank of Scotland delivers Trickbot banking trojan

An email with the subject of New Secure Message Royal Bank of Scotland pretending to come from Royal Bank of Scotland but actually coming from a whole range of look-a-like domains with a malicious word doc attachment is today’s latest spoof of a well-known company, bank or public authority delivering Continue reading → Continue reading Another fake New Secure Message Royal Bank of Scotland delivers Trickbot banking trojan

Trickbot banking Trojan delivered by spoofed Canadian Imperial Bank of Commerce messages

An email with the subject of Canadian Imperial Bank of Commerce  pretending to come from CIBC but actually coming from a  whole range of look-a-like domains and for some strange reason today they are also coming from spoofed eFax and NatWest domains  with a malicious word doc attachment  is today’s latest spoof of Continue reading → Continue reading Trickbot banking Trojan delivered by spoofed Canadian Imperial Bank of Commerce messages

More Fake NatWest Bank messages with a password protected word doc delivers trickbot

An email with the subject of Important : Incoming BACs Documents pretending to come from NatWest Bank but actually coming from a look-a-like domain Natwest <message@natwestbacs.co.uk>   or  Natwest <message@natwestbacs.com> with a password protected malicious word doc attachment  is today’s latest spoof of a well-known company, bank or public authority delivering Trickbot banking Trojan Continue reading → Continue reading More Fake NatWest Bank messages with a password protected word doc delivers trickbot