-
Archives
- March 2023
- February 2023
- January 2023
- August 2022
- July 2022
- June 2022
- January 2022
- December 2021
- June 2021
- January 2021
- December 2020
- November 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- January 2020
- October 2019
- August 2019
- July 2019
- June 2019
- March 2019
- February 2019
- January 2019
- December 2018
- November 2018
- October 2018
- September 2018
- August 2018
- July 2018
- June 2018
- May 2018
- April 2018
- March 2018
- February 2018
- January 2018
- December 2017
- November 2017
- October 2017
- September 2017
- August 2017
- May 2017
- February 2017
- January 2017
- December 2016
- November 2016
- October 2016
- September 2016
- August 2016
- July 2016
- June 2016
- May 2016
- April 2016
- March 2016
- February 2016
- January 2016
- December 2015
- November 2015
- October 2015
- September 2015
- August 2015
- July 2015
- June 2015
- May 2015
- April 2015
- March 2015
- February 2015
- January 2015
- December 2014
- November 2014
- October 2014
- September 2014
- August 2014
- July 2014
- June 2014
- May 2014
- April 2014
- March 2014
- February 2014
- January 2014
- December 2013
- November 2013
- October 2013
- September 2013
- August 2013
Monthly Archives: December 2014
Notable CryptoLocker / Zeus infections..
I recently came across a document, dated June 2014, with the reverse DNS names of CryptoLocker infected computers. I’ve detailed the most interesting ones below. It is important to note it may not be company or establishment owned computers that … Continue reading
Posted in Uncategorized
Leave a comment
“CHRISTMAS OFFERS.docx” virus e-mail
Email today sent to one of my spam trap addresses from “Jayne <Jayne@route2fitness.co.uk>” With word attachment “CHRISTMAS OFFERS.doc” containing macro downloader. VirusTotal Report SHA256 211fd58aea279d3c65b46ec8bced1fe0fb63b43d0ca32a6868af651d68335d9c When the word document is opened and macros are enabled it downloads: http://jasoncurtis.co.uk/js/bin.exe – VirusTotal Report … Continue reading
Posted in Uncategorized
Leave a comment
Sage v21 blocked on SBS 2011 – Sage support article 32387
I’m re-posting this as they seem to block this information on their support website and it’s a pain to have to call (or you can’t call because you are doing an upgrade out of hours etc..). Sage 2015 (v21) won’t … Continue reading
Posted in Uncategorized
1 Comment
“Invoice as requested” “UK GEOLOGY PROJECT” malware e-mail
E-mail today with a .doc attachment containing a macro. “UK GEOLOGY PROJECT by “Rough & Tumble” with “Moussa Minerals”” <roughandtumble63@yahoo.co.uk> Subject: Invoice as requested Received: from srvintra.cer83.net (185.21.80.80) Attachment SHA256 0f66b81ba27fa0e18b6545ef0574fc8d1978ff8e6ce27ec14e32951e8e1a4a2b VIrusTotal Report I’m not in a position to investigate … Continue reading
Posted in Uncategorized
Leave a comment
Two more “Windows” scam calls…
As a follow on from the chain of “Your computer has a virus” scam callers claiming to be from Microsoft, Windows or your ISP.. Here are some more to add to the list. Scammer 1: Some malware on a computer … Continue reading
Posted in Uncategorized
1 Comment
“Remittance Advice from Anglia Engineering Solutions Ltd [ID 83162S]” and “Remittance Advice for 374.86 GBP” Virus spam.
Today I investigated two excel spreadsheets with macros that have been making the rounds. Subject: “Remittance Advice from Anglia Engineering Solutions Ltd [ID 83162S]” Dear , We are making a payment to you. Please find attached a copy of our … Continue reading
Posted in Uncategorized
3 Comments
WinZip (as far as I can see .. the actual official WinZip.com!) misleading advertising scam.
Update – 15th January 2016: A year later and they are back with the scam scam messages (“A required driver is missing”). This time I’m seeing the advertisements on YouTube again. I don’t understand how they can get away with such clearly … Continue reading
Posted in Uncategorized
13 Comments
“Remittance Advice for 273.88 GBP” junk email with excel attachment containing macro.
E-mail with attachment “BAC_641952Z.xls” – VirusTotal Report SHA256: 66ed083beb750b7c2d65210607f52ff2136dbdb9b9b89dfe88fdbef3c9cf826e Gwen Henson <Israel.ef@de.colt.net> Fri 05/12/2014 07:32 Please find attached a remittance advice for recent BACS payment. Any queries please contact us. Gwen Henson Senior Accounts Payable Specialist K J Watking & … Continue reading
Posted in Uncategorized
1 Comment
GoDaddy weirdeness / hack?
Saw this in my logs around the time the static content on a website got hacked: 2014-11-24 07:31:33 GET /ts_index.html – 80 184.168.27.80 “aQ0O010O” – 200 6619 123 31 “D:\Hosting\6540401\html\ts_index.html” The user agent of “aQ0O010O” is a bit weird and … Continue reading
Posted in Uncategorized
Leave a comment
Email “Fax Message #6464552 ” junk.
E-mail comes through with a subject line similar to: “Fax Message #5522951 ” with a random number. The message body looks like this: Fax Message [Caller-ID: 1-407-378-1024] You have received a 3 page fax at Mon, 1 Dec 2014 14:16:54 … Continue reading
Posted in Uncategorized
1 Comment