massive malspam campaign delivering Ursnif banking Trojan via js files

We have been seeing a massive malspam campaign today delivering Ursnif banking Trojan via js files inside zips. There have been numerous different subjects and campaign themes I will detail some of them here: Our reference: 733092244 pretending to come from Eli Murchison <Hughchaplin@yahoo.de> Hotel booking confirmation (Id:022528) pretending to Continue reading → Continue reading massive malspam campaign delivering Ursnif banking Trojan via js files

massive malspam campaign delivering Ursnif banking Trojan via js files

We have been seeing a massive malspam campaign today delivering Ursnif banking Trojan via js files inside zips. There have been numerous different subjects and campaign themes I will detail some of them here: Our reference: 733092244 pretending to come from Eli Murchison <Hughchaplin@yahoo.de> Hotel booking confirmation (Id:022528) pretending to Continue reading → Continue reading massive malspam campaign delivering Ursnif banking Trojan via js files

more fake photo or fotki malspam tries to deliver malware but appears to fail

Continuing with the never ending series of malware downloaders is an email with the subject of Re: fotki or re: photo  coming or pretending to come from random companies, names and email addresses with a semi-random named zip attachment in the format of mg_0943276325764803298_JPG.zip  which tries to deliver some sort of malware but … Continue reading → Continue reading more fake photo or fotki malspam tries to deliver malware but appears to fail

more fake photo or fotki malspam tries to deliver malware but appears to fail

Continuing with the never ending series of malware downloaders is an email with the subject of Re: fotki or re: photo  coming or pretending to come from random companies, names and email addresses with a semi-random named zip attachment in the format of mg_0943276325764803298_JPG.zip  which tries to deliver some sort of malware but … Continue reading → Continue reading more fake photo or fotki malspam tries to deliver malware but appears to fail

fake spoofed DHL Shipment Notification delivers some sort of unknown malware

Continuing with the never ending series of malware downloaders is an email with the subject of DHL Shipment Notification : 1104749373 pretending to come from DHL Customer Support <support@dhl.com>  with a semi-random named zip attachment in the format of Pickup EXPRESS .Date2017-04-26.zip  which delivers or tries to deliver some sort of malware. This is a … Continue reading → Continue reading fake spoofed DHL Shipment Notification delivers some sort of unknown malware

Changes to fake USPS delivery messages delivering malware

We have all become accustomed to seeing USPS, UPS, DHL. FEDEX and all the other delivery companies being spoofed with emails pretending to be from them delivering all sorts of malware, usually via zip attachments containing JavaScript files. There have been 2 main campaigns that I have documented HERE and HERE Recently … Continue reading → Continue reading Changes to fake USPS delivery messages delivering malware

more spoofed DHL Delivery malspam delivers malware

Continuing with the never ending series of malware downloaders spoofing DHL  is an email with the subject of DHL Delivery coming or pretending to come from DHL Express UK. These do look very realistic and if you are expecting a delivery today ( many recipients will be) you can be very easily … Continue reading → Continue reading more spoofed DHL Delivery malspam delivers malware

Locky Ransomware, Kovter Click-Fraud Malware Spreading in Same Campaigns

Locky ransomware and Kovter click-fraud malware are being spread in the same email campaign for the first time, with malicious .lnk files being used to infect computers. Continue reading Locky Ransomware, Kovter Click-Fraud Malware Spreading in Same Campaigns

Your shipment malspam email delivers Locky

The next in the never ending series of Locky downloaders is an email with the subject of  Your shipment  coming as usual from random companies, names and email addresses  with a semi-random named zip attachment starting with  shipment_ containing a … Continue reading →

Source

Continue reading Your shipment malspam email delivers Locky