Fake emails – Adobe Critical Upgrade

A new fake email which pretends to be from Adobe is in the wild and spreading on the Internet. The email has an attachment which contains an executable file having PDF icon. If the user gets convinced by this email and executes the file the computer gets infected. The sample I came across installs a […]

New Facebook “Your account has been blocked!” scam

Another Facebook spam pretending that the viewers account has been blocked is currently circulating on the Internet. The subject is: “Facebook Service# Your account has been blocked! Order/8236”. The email comes with an attachment called ‘New_Password_FB_1148.zip’. The zip file contains an executable file ‘New_Password.exe’, which tries to fool the victim by posing as a Microsoft […]

FedEx Scam spreading Rogueware

Today we received a mail which pretends to have come from FedEx and it looks as shown below. As seen from the image, the attachment is actually a UPX packed executable file which looks like an invoice document. After execution of the binary, it dropped a copy of itself and also created a registry key […]

DHL – Email Scam

We all know if you want your ordered goods to be at your doorstep then you opt for DHL. But cyber-criminals are now taking advantage of DHL emails and they are now sending fake emails with the same format to random users. The email shows up the following screenshot: This email pretends to be from […]

Android – RogueSPPush Malware

The growing popularity of Android and the tendency of users to store important data on their mobile phones are attracting many hackers. They are targeting users of Google Android mobile operating system with a malicious application that harvests personal information, controls the system and sends it to a remote server. We have received one such […]

MasterCard spam leads to Fake AV

We’re seeing a significant “spam attached malware” campaign in the past 48 hours with different attachment MD5s. 3305f83abf31fc66fa8f588b35be8eb2 8e3331b64a5884e1ef4f4c8a3d09bc7a The username portion of the email sender is random, using a classic misspelling that has been consistent. Usernames are a single word, followed by a “.”, “_” or “-“, followed by a two or three digit […]

IRS Notification Letter Email scam

The Chepvil malware which comes via email as an attachment is using another trick to spread itself. You may receive an email stating to be from IRS.gov and with the subject line – “IRS Notification Letter”. The email is as shown below: The attachment comes with the name ‘IRS document.rar’. Upon extraction, the user gets […]