tech support 9

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 29 November 2013

Registered Express Corporation (RGTX) pump and dump spam

Posted on 09:30 by Unknown


It's taken me a few days to get around to this due to moving house, but here's a new pump-and-dump spam run promoting a stock Registered Express Corporation (OTC:RGTX).

As ever, there are a massive number of different subjects and random body-texts, for example:

Subject: This Bottom Bouncer has taken off!Subject: Our analysis right on the MONEY!Subject: Seven Reasons To Love This
Read More
Posted in Pump and Dump, Spam | No comments

Wednesday, 27 November 2013

"ADP - Reference #274135902580" spam / Transaction.exe

Posted on 05:41 by Unknown


Is it Salesforce or ADP? Of course.. it is neither.


Date:      Wed, 27 Nov 2013 11:50:07 +0100 [05:50:07 EST]From:      "support@salesforce.com" [support@salesforce.com]Subject:      ADP - Reference #274135902580We were unable to process your recent transaction. Please verify your details and try again.If the problem persists, contact us to complete your order.Transaction details are shown in
Read More
Posted in ADP, EXE-in-ZIP, Malware, Spam, Viruses | No comments

Tuesday, 26 November 2013

Something evil on 46.19.139.236

Posted on 08:29 by Unknown


46.19.139.236 (Private Layer Inc, Switzerland) seems to be serving up some sort of Java exploit kit via injection attacks which is utilising hijacked legitimate domains, but the domains in use seem to rotate pretty quickly and I haven't got a copy of the payload, but VirusTotal has some examples. These are the domains that I can find running from this IP:

ihavefound.boostprep.com
Read More
Posted in 1&1, GoDaddy, Injection Attacks, Malware, Switzerland, Viruses | No comments

"You requested a new Facebook password!" spam / Recoverypassword.zip and Facebook-SecureMessage.exe

Posted on 06:13 by Unknown



This fake Facebook message comes with a malicious attachment:


Date:      Tue, 26 Nov 2013 04:58:18 +0300 [11/25/13 20:58:18 EST]From:      Facebook [update+hiehdzge@facebookmail.com]Subject:      You requested a new Facebook password!facebookHello,You have received a secure message. You will be prompted to open (view) the file or save (download) it to your computer. For best results, save
Read More
Posted in EXE-in-ZIP, Facebook, Malware, Spam, Viruses | No comments

Monday, 18 November 2013

0844 number scam (08445715179)

Posted on 04:48 by Unknown


This is a particularly insidious scam that relies on mobile phone users in the UK not knowing that an 0844 number is much, much more expensive than a normal phone call. The scam SMS goes something like this:


ATTENTION! We have tried to contact you, It is important we speak to you today. Please call 08445715179 quoting your reference 121190. Thank You.

In this case the sender's number was +
Read More
Posted in Scam, SMS, Spam, Virgin Media | No comments

Friday, 15 November 2013

RingCentral "Bank of America" fax message spam / 442074293440-1116-084755-242.zip

Posted on 09:55 by Unknown


This fake fax message email has a malicious attachment:


Date:      Fri, 15 Nov 2013 12:05:36 -0500 [12:05:36 EST]
From:      RingCentral [notify-us@ringcentral.com]
Subject:      New Fax Message on 11/15/2013 at 09:51:51 CST

You Have a New Fax Message

From
Bank of America

Received:
11/15/2013 at 09:51:51 CST

Pages:
5
   
To view this message, please open the attachment.

Thank you for
Read More
Posted in EXE-in-ZIP, Malware, Spam, Viruses | No comments

Malware sites to block 15/11/2013 (Caphaw)

Posted on 07:16 by Unknown


Thanks to a tip to investigate 199.68.199.178 I discovered that the Caphaw network I looked at yesterday is much bigger than I thought. The following IPs and domains can all be regarded as malicious (.SU domains are normally a dead giveaway for evil activity).

The recommended blocklist is at the end of the post (highlighted). These are the hosts involved either now or recently with hosting
Read More
Posted in .SU, Canada, France, Germany, Hetzner, Intergenia, Malware, OVH, Simply Transit, Taiwan, Viruses | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Registered Express Corporation (RGTX) pump and dump spam
    It's taken me a few days to get around to this due to moving house, but here's a new pump-and-dump spam run promoting a stock Regist...
  • "CEO Portal Statements & Notices Event" spam / report_{DIGIT[12]}.exe
    This fake Wells Fargo email has a malicious attachment: Date:      Fri, 16 Aug 2013 09:51:17 -0500 [10:51:17 EDT]From:      Wells Fargo Even...
  • ACH file ID "999.107" has been processed successfully spam / www.fiscdp.com.airfare-ticketscheap.com
    This fake FISC ACH spam leads to malware on www.fiscdp.com.airfare-ticketscheap.com: Date:      Tue, 10 Sep 2013 17:05:49 +0530 [07:35:49 ED...
  • USPS spam / Label_ZFRLOADD5PGGZ0Z_USPS.zip
    This fake USPS spam has a malicious attachment: Date:      Tue, 15 Oct 2013 09:36:02 -0500 [10:36:02 EDT]From:      USPS Express Services [s...
  • StumbleUpon spam / drugstorepillstablets.ru
    This fake StumbleUpon spam is something new, it leads to a fake pharma site on drugstorepillstablets.ru: Date:      Mon, 4 Feb 2013 01:01:46...
  • "Support Center" spam / phticker.com
    Not malware this time, but this fake "Support Center" spam leads to a fake pharma site at phticker.com: Date:      Mon, 11 Feb 201...
  • inukjob.com fake job offer (also ineurojob.com and hollandsjob.com)
    This fake job offer from inukjob.com involves illegal money laundering, and it also seems that the scammers want to use your identity for ...
  • Dealerbid.co.uk "Quotation.zip" spam with malicious VBS script
    The website dealerbid.co.uk has been compromised and their servers hacked in order to send spam to their customer list. Something similar ha...
  • Fake Staples spam leads to malware on tootle.us
    This fake Staples spam leads to malware on a site called tootle.us: Date:      Wed, 2 Oct 2013 08:40:11 -0500 [09:40:11 EDT]From:      suppo...
  • Laughable advanced fee fraud scam promises $2.5
    Two-and-a-half bucks? I think I'll pass. From:     Mr Anthony Freed [johnewele12@cantv.net]Reply-to:     dhlcorriadeliveryservice@live.c...

Categories

  • .SU
  • 1&1
  • 419
  • ADP
  • Advanced Fee Fraud
  • Advertising
  • Adware
  • AICPA
  • Amazon
  • Amerika
  • Android
  • Anti-Virus Software
  • AOL
  • Apple
  • Aruba
  • Australia
  • Austria
  • BBB
  • Black Hat
  • Blackhole
  • Blogging
  • Botnet
  • Brazil
  • Bulgaria
  • Canada
  • Chile
  • China
  • CNN
  • Colombia
  • CookieBomb
  • Crime
  • CyberBunker
  • Data Breach
  • DHL
  • DOC
  • Domains
  • Dynamic DNS
  • eBay
  • Edis
  • eFax
  • Egypt
  • Emailmovers Ltd
  • Endurance International Group
  • Estonia
  • Evil Network
  • EXE-in-ZIP
  • Facebook
  • Fail
  • Fake Pharma
  • False Positive
  • FedEx
  • Finland
  • France
  • Gandi
  • Germany
  • GHOSTnet
  • GoDaddy
  • Google
  • Greece
  • Hacked sites
  • Hetzner
  • HMRC
  • Hosting
  • Hungary
  • India
  • Injection Attacks
  • Intergenia
  • INTUIT
  • Iran
  • IRS
  • Israel
  • Italy
  • Japan
  • Job Offer Scams
  • Joe Job
  • Jolly Works Hosting
  • Kelihos
  • Kenya
  • Korea
  • Latvia
  • Law
  • Leaseweb
  • LinkedIn
  • Linode
  • Lithuania
  • Lithunia
  • logol.ru
  • Macintosh
  • Magnitude
  • Malware
  • Mea Culpa
  • Microsoft
  • Moldova
  • Money Mule
  • Mongolia
  • NACHA
  • NATO
  • Netherlands
  • Neutrino
  • Nuclear Fallout Enterprises
  • OVH
  • Pakistan
  • Patches
  • PayPal
  • Philippines
  • Phishing
  • Phishtank
  • Phones
  • Pinterest
  • Pizza
  • Poland
  • Politics
  • Porn
  • PPI
  • Printer Spam
  • Privacy
  • Pump and Dump
  • Retro
  • Romania
  • RU:8080
  • Russia
  • Sally Gaskell
  • Scam
  • Scams
  • Senegal
  • Serbia
  • Serverius
  • Sidharth Shah
  • Simply Transit
  • Singapore
  • Slicehost
  • SMS
  • South Africa
  • Spain
  • Spam
  • Stupidity
  • Sweden
  • Sweet Orange
  • Switzerland
  • Syria
  • Taiwan
  • Telepests
  • Thailand
  • TheFirst-RU
  • ThreeScripts
  • Tor
  • Turkey
  • UAE
  • UK2.NET
  • Ukraine
  • UPS
  • US Airways
  • USPS
  • VBScript
  • Virgin Media
  • Viruses
  • Waledac
  • Weather
  • Xeex
  • Yahoo
  • YouTube
  • Zbot
  • Zeus

Blog Archive

  • ▼  2013 (500)
    • ▼  November (29)
      • Registered Express Corporation (RGTX) pump and dum...
      • "ADP - Reference #274135902580" spam / Transaction...
      • Something evil on 46.19.139.236
      • "You requested a new Facebook password!" spam / Re...
      • 0844 number scam (08445715179)
      • RingCentral "Bank of America" fax message spam / 4...
      • Malware sites to block 15/11/2013 (Caphaw)
      • Malware sites to block 14/11/2013 (Caphaw)
      • The EXE-in-ZIP spam storm continues
      • PayPal "Identity Issue" spam / Identity_Form_04182...
      • "Rodrigo Sawyer and Associates" fake job offer
      • "2012 and 2013 Tax Documents; Accountant's Letter"...
      • "Important - New Outlook Settings" spam / Outlook.zip
      • "You have received new messages from HMRC" spam, H...
      • Dynamic DNS sites you might want to block, 12/11/13
      • "Identity Issue #PP-716-097-521-587" spam / Identi...
      • "To all Employees - Confidential Message" spam / T...
      • "Consumer Benefit Ltd" adware sites to block
      • "African Development Humanitarian Council" (adhcou...
      • "Voicemail Message" spam / MSG00049.zip and MSG000...
      • Malware sites to block 8/11/2013 (Nuclear EK)
      • Fake "Financial Times Survey Team" spam / ft-surve...
      • "You received a voice mail" spam / Voice_Mail.exe
      • "Voice Message from Unknown" spam / VoiceMail.zip
      • "Invoice 17731 from Victoria Commercial Ltd" spam ...
      • USPS spam / Label_442493822628.zip
      • "ACH Notification : ACH Process End of Day Report"...
      • "Payment Overdue - Please respond" spam / Payrol...
      • CCDCOE.org "Information Security Audit" spam
    • ►  October (37)
    • ►  September (46)
    • ►  August (44)
    • ►  July (62)
    • ►  June (42)
    • ►  May (39)
    • ►  April (67)
    • ►  March (67)
    • ►  February (60)
    • ►  January (7)
Powered by Blogger.

About Me

Unknown
View my complete profile