Yet another Spoofed Lloyds Bank Incoming BACs malspam delivers trickbot

An email with the subject of Incoming BACs   pretending to come from Lloyds Bank  but actually coming from a look-a-like domain <noreply@lloydsbacs.co.uk>  with a malicious word doc attachment  is the next  today’s latest spoof of a well known company, bank or public authority delivering Trickbot banking Trojan They are using email addresses and Continue reading → Continue reading Yet another Spoofed Lloyds Bank Incoming BACs malspam delivers trickbot

Spoofed Nat West Bank financial activity statement malspam delivers trickbot

An email with the subject of Nat West Bank pretending to come from Nat West Bank but actually coming from a look-a-like domain  <noreply@natwestdocuments6.ml>  with a malicious word doc attachment  is the first of today’s latest spoof of a well known company, bank or public authority delivering Trickbot banking Trojan Continue reading → Continue reading Spoofed Nat West Bank financial activity statement malspam delivers trickbot

Another Spoofed HMRC Company Excel Documents delivers trickbot

An email with the subject of Secure email message pretending to come from HMRC  but actually coming from a look-a-like domain HM Revenue & Customs <Gary.Brooks@hrmccommunication.co.uk>   with a malicious Excel XLSM attachment  is today’s latest spoof of a well known company, bank or public authority delivering Trickbot banking Trojan. It is a Continue reading → Continue reading Another Spoofed HMRC Company Excel Documents delivers trickbot

Spoofed Vodafone Online Bill Manager – Your Phone Bill is ready to view delivers banking Trojan

Another big malspam campaign pretending to be a Vodafone bill. These started earlier this morning with links in the email to a compromised or fraudulently set up SharePoint business site that soon stopped delivering the malware payloads. They then quickly switched to a  whole host of other compromised sites to Continue reading → Continue reading Spoofed Vodafone Online Bill Manager – Your Phone Bill is ready to view delivers banking Trojan

Another spoofed HMRC You have a new secure communication malspam delivers Trickbot banking trojan

An email with the subject of You have a new secure communication pretending to come from HMRC  but actually coming from a look-a-like domain and email address HM Revenue & Customs <donotreply@hmrccommunication.co.uk>  with a malicious word doc attachment  is today’s latest spoof of a well known company, bank or public authority delivering Continue reading → Continue reading Another spoofed HMRC You have a new secure communication malspam delivers Trickbot banking trojan

Spoofed Santander You have a new secure message waiting malspam delivers Trickbot banking trojan

An email with the subject of You have a new secure message waiting pretending to come from Santander  but actually coming from a look alike domain Santander <pleasedonotreply@santandersecuremessage.com> with a malicious word doc attachment  is today’s latest spoof of a well known company, bank or public authority delivering Trickbot banking Trojan They Continue reading → Continue reading Spoofed Santander You have a new secure message waiting malspam delivers Trickbot banking trojan

Scanned image from MX-2600N with password protected word docs deliver malware

Back to an old regular email template today with an email with the subject of  Scanned image from MX-2600N pretending to come from noreply@your own email address  with a malicious word doc  delivering malware. I am not sure what it is yet but will either be a banking Trojan like Trickbot Continue reading → Continue reading Scanned image from MX-2600N with password protected word docs deliver malware

Emotet / Geodo delivered via fake invoices using updated word docs with encoded sections

Following on from THIS fake invoice email is a newer version with a different word doc at the end of the link in the email. Today’s  email with the subject of re: Invoice 622806 pretending to come from  senders with a known connection to the recipient. The link in the email Continue reading → Continue reading Emotet / Geodo delivered via fake invoices using updated word docs with encoded sections

Invoice notification with id number: 40533 delivers malware

An email with the subject of  Invoice notification with id number: 40533 pretending to come from random senders with a link in the email to a malicious word doc   delivers some sort of malware. I am not sure what these are but am guessing at possibly Emotet banking Trojan They are using Continue reading → Continue reading Invoice notification with id number: 40533 delivers malware

Spoofed HSBC Account secure documents malspam delivers trickbot

An email with the subject of Account secure documents pretending to come from HSBC but actually coming from a look alike domain <noreply@hsbcdocs.co.uk>  with a malicious word doc attachment  is today’s latest spoof of a well known company, bank or public authority delivering Trickbot banking Trojan They are using email addresses and Continue reading → Continue reading Spoofed HSBC Account secure documents malspam delivers trickbot