Моє ім’я Shoshana Stoudemire, надсилаю вам вірус. :)

Під виглядом звичайного резюме від шукача роботи маємо вірус.

Вірусний спам: Trojan.SpamDocCrypted.DC


Відправник: Shoshana Stoudemire   <support@tomschedler.com>
Тема: application
Вкладення: Shoshana Stoudemire   Resume.doc
Текст: Hi,
My name is Shoshana Stoudemire   and I’m interested in a job.

I’ve attached a copy of my resume.
The password is “1234”

Looking forward to hearing back from you!


Shoshana Stoudemire

Моє ім'я Shoshana Stoudemire, надсилаю вам вірус. :)

Моє ім'я Shoshana Stoudemire, надсилаю вам вірус. :)

Order Confirmation

Вірусний спам: Trojan.Script.777690


Відправник: “sales” <ma@gmail.com>
Тема: Order Confirmation
Вкладення: PO-374777.docx
Текст: Hello
Kindly note that We have signed the ORDER 049584 on Attachment
Check the attachment and sign it back and send to us

Thanks & Regards
P Samuel Cherian
Sr Manager Sales & Operations
Mob: + 971 50 4629648
Description: Description: Description: cid:image001.png@01D1BA6A.FA208530

Trojan.Script.777690

Trojan.Script.777690

Trojan.Script.777690

Inquiry From Sailor Greenland GmbH

Вірусний спам: Trojan.SpamDocCrypted.CW


Відправник: Christain Zeiler <C.Zeiler@tomaten.at>
Тема: Inquiry From Sailor Greenland GmbH
Вкладення: Sailor Greenland GmbH Sheet.xlsx
Текст: Hello,
Good day.

We got your contact and recommendation from one of our business partner and we have tried to reach your office phone but cannot get to you. Could you please look into the attached immediately and then arrange a quotaion for us with your best prices. If you don’t have any of the item please state the replacement and price too.
Thanks very much for your prompt reply in advance.
Regards,
Christian Zeiler
Purchasing Manager
cid: image001.png@01D33C5B.11439A90
Sailor Greenland GmbH
Kräuterweg 1
A-2433 Margarethen am Moos
T: +43 2259 87072-101
H: +43 664 3851237
ATU: 72040034

Trojan.SpamDocCrypted.CW

Trojan.SpamDocCrypted.CW

Arminda Resume.doc

Вірус Trojan.SpamDocCrypted.CU заблокований TrustPort Mail Antivirus


Відправник: Arminda Fortson   <info@gotlube.net>
Тема: Application
Вкладення: Arminda Resume.doc
Текст: How are you doing?
My name is Arminda and I’m interested in a job.

I’ve attached a copy of my resume.
The password is “1234”
Best regards!
Arminda

Arminda Resume.doc

Arminda Resume.doc

Порно-шантаж на 4 тисячі доларів

Вимагач шантажує на 4 000 доларів.


Відправник: “Info” <Aaron819Smith@yahoo.jp>
Тема: ***SPAM*** Your password is 222222

“I do know 222222 is your pass. Lets get right to point. You may not know me and you’re probably thinking why you’re getting this email? No person has paid me to investigate about you.

Let me tell you, I actually placed a malware on the X vids (adult porn) website and do you know what, you visited this web site to experience fun (you know what I mean). While you were watching video clips, your internet browser began operating as a Remote control Desktop that has a keylogger which gave me access to your screen as well as web camera. Immediately after that, my software program collected all of your contacts from your Messenger, social networks, as well as email . Next I created a double video. First part shows the video you were watching (you have a nice taste hehe), and next part shows the recording of your cam, yeah its you.

You got not one but two solutions. We are going to analyze these possibilities in particulars:

Very first option is to neglect this email. As a result, I most certainly will send out your video recording to all of your personal contacts and then just consider concerning the embarrassment yo u will see. And as a consequence if you happen to be in a relationship, exactly how this will affect?

Number 2 solution should be to compensate me $4000. I will describe it as a donation. Subsequently, I most certainly will without delay discard your video. You will resume your life like this never happened and you never will hear back again from me.

You’ll make the payment via Bitcoin (if you don’t know this, search for “how to buy bitcoin” in Google).

BTC Address: 1J7BWfCsuTfi1kCMRs6TLd1mRGiutUT2o1
[CASE SENSITIVE so copy & paste it]

Should you are looking at going to the cop, okay, this mail cannot be traced back to me. I have dealt with my moves. I am also not attempting to ask you for a lot, I wish to be rewarded.

You now have one day in order to make the payment. I’ve a specific pixel in this e mail, and at this moment I know that you have read through this email message. If I don’t receive the BitCoins, I will definitely send out your video recording to all of your contacts including relatives, colleagues, and so forth. Nonetheless, if I receive the payment, I’ll erase the recording immediately. If you need evidence, reply Yes! and I definitely will send out your video recording to your 7 friends. It’s a nonnegotiable offer that being said do not waste my personal time & yours by responding to this e-mail”

BTC Address: 1J7BWfCsuTfi1kCMRs6TLd1mRGiutUT2o1

Lavera.doc

Вірусний спам: W97M.Downloader.HBI
TrustPort Mail Antivirus видалив вірусне вкладення


Відправник: Lavera Muck   <help@0937.org>
Тема: Job Application
Вкладення: Lavera.doc
Текст: How is your day?
My name is Lavera and I’m interested in a position.

I’ve attached a copy of my resume.
The password is “1234”
Best regards!
Lavera

Lavera.doc

Lavera.doc

Below find statement as at 31st July 2018

Вірусний спам: Java.Trojan.GenericGB.BG

TrustPort Mail Antivirus заблокував вірусне вкладення.


Відправник: Midway Travel <carmel@midwaymalta.com>
Тема: Statement
Вкладення: Oustanding Payments.zip
Текст: Dear Sir,
Below find statement as at 31st July 2018:-

Inv11904 8th May 2018 €430.00c.
Inv11984 4th July 2018 €2,100.00c.
Inv11989 10th July 2018 €340.00c.
Inv12000 26th July 2018 €619.00c.
Inv12001 26th July 2018 €354.00c.

Please settle at your earliest.
Thanks,

Carmel Farrugia
MIDWAY TRAVEL SERVICES LTD
PORTOMASO SHOPPING CENTRE
PORTOMASO PTM01
TEL: (356) 21378138/21378187
All quotations stated above are subject to currency fluctuations and seasonal supplements without prior notice. Midway Travel Services Ltd can not be liable for any damages arising from such changes. Please be sure to check visa/vaccination for your trip. If holding separate tickets, airlines and travel agent are not reponsible for missed connections. When making booking please ensure that all the names provided match their corresponding travel documents (passport/ID), exactly

Below find statement as at 31st July 2018

Below find statement as at 31st July 2018

SKM-42738493JK_pdf.rar

Вірусний спам: Exploit.SpamMalware-RAR.Gen

Заблоковано TrustPort Mail Antivirus


Відправник: Rita Rollmann <Rita.Rollmann@hoppecke.com>
Тема: P/O Inquiry
Вкладення: SKM-42738493JK_pdf.rar
Текст: Hello Sir/Madam,
The attached is our Company new order Specifications/Images and the quality needed from your esteemed company.
Shipment: September 2018
Payment will be made by 50% TT Against Production and 50% balance on delivery (Unless quote otherwise)
Waiting for your urgent reply.
With kind regards / Mit freundlichen Grüßen
Rita Rollmann
– Customer Service Team Reserve Power –
HOPPECKE Batterien GmbH Co. KG
Bontkirchenerstr. 1
D – 59929 Brilon-Hoppecke / GERMANY
phone:+49 (0) 2963 / 61-208
fax:+49 (0) 2963 / 61-502
e-mail:Rita.Rollmann@hoppecke.com
www.HOPPECKE.com

SKM-42738493JK_pdf.rar

SKM-42738493JK_pdf.rar

Re:Order confirmation ref. no. QP214.R8/PO 18-049 dated 12th march, 2018.

Вірусний спам: Exploit.CVE-2017-0199.Gen

Відправник: JHOSUA CERVANTES ZAVALA  <r.fatullayeva@tamizshahar.az>
Тема: Re:Order confirmation ref. no. QP214.R8/PO 18-049 dated 12th march, 2018.
Вкладення: PO OMULQP214.docx
Текст: Date : 29th August 2018
Ref. No.:  PO OM/UL/QP214.R8/PO 18-049
Subject : order  confirmation

Dear Sir,
Good day from  TASTY TREAT, S.L. .
We refer to your email dated 12th march, 2018.
Please find attached our confirmation for your order acknowledgement.
including the additional order,
Appreciate if you could kindly sign and get stamped on our PO OM/UL/QP214.R8/PO 18-049.
We request you to kindly let us have your invoice with complete correspondence address including email address & contact nos. along with your detailed requirement for shipment.
Awaiting your early feedback,
Thanks

Best Regards
JHOSUA CERVANTES ZAVALA
Supply Chain/Imports/Exports
TASTY TREAT, S.L.
Avda.  Països Catalans, 1, 3º A
17820 Banyoles – Girona
Tlf: 00 34 972 850908
Fax: 00 34 972 850994

Exploit.CVE-2017-0199.Gen

Exploit.CVE-2017-0199.Gen