TG Soft's C.R.A.M. (Anti-Malware Research Center) examined malware campaigns spread via email to Italian users March 07, 2018 Cyber-criminals developed "Social engineering" methods for fraudulent mass mailings, to induce the victim to open infected attachments or click on links in the body of the message. If you received a suspicious email, send it to C.R.A.M. (Center for Anti-Malware Research): How to send suspicious emails |
INDEX==> "New order" Campaign
==>Campaign "***SPAM*** BANK TRANSFER FORM" ==> Campaign "Payment against your P.I 467301" ==>Campaign "Port agency appointment- MV Frontier Lodestar" ==> Campaign "TM Project Inquiry" ==> Campaign "Request for the submission of Technical Bid" ==> Campaign"Contract prolongation" / "DHL SHIPMENT 03-07-18" ==> How to identify a fake email ==> How to send suspicious emails ==> Integrate protection with Vir.IT Lite ==> For Vir.IT eXplorer PRO users.. |
Subject: New order |
Buongiorno, Dear Mr, Sirs, Good morning. Thanks for your reply. ^^ We sent our new order(P/O SAT-18-014) by e-mail. Please find the attached PURCHASE ORDER of P/O SAT-18-014. Please send confirmation on or 13th, March. 2018. Description PT-320-T01 7EA PT-10MLD-10 2EA We look forward to hearing your good reply. If you have any problem, please feel free to contact me by E-mail. With kind and best regards. |
Example of a malicious email click to enlarge |
Name SAT180313.jar MD5: 1E1CB0AE838CAD992444F9B3317025FB Size 555.653 byte |
Subject: BANK TRANSFER FORM |
Dear, We were instructed earlier by your client to help him remit your outstanding payment,cause he will be on vacation from 03/03/2018 to 06/04/2018 Please reconfirm your bank details asap in the attached Bank Transfer Form before we proceed to the bank for payment. Thanks & Best Regards. Bernard Galvan General Manager |
Example of a malicious email click to enlarge |
Name: BANK TRANSFER FORM201873.ace MD5: 7792A36210492332E13DFD97D90DE84F Size: 286.572 byte |
Subject: Payment against your P.I 467301 |
i didn't receive your mail. I've called your Office by Phone but its not going through and i don't have your mobile number. Attach payment for this first Order Looking forward for your prompt reply. Regards Santhosh Roys joseph I Sr. Sales Executive Faisal Al Qatami Steel Trad. Co. (Al-Rai Branch) P.O.Box: 23090 Safat, 13091 Kuwait Tel: (965) 24735460 ; (965) 24735416 Mobile: (965) 97254467 ; Fax: (965) 24735461 E-Mail: alrai@qatamisteel.net Website: www.qatamisteel.com |
Example of a malicious email click to enlarge |
Nome: PaymentCopy_pdf.zip MD5: 2FC699A0EC5026B466F79DA8E80FC6D3 Size: 320.050 byte |
Subject: Port agency appointment- MV Frontier Lodestar |
Dear Sir, We are pleased to appoint your good company as agents for our vessel MV FRONTIER LODESTAR which is expected to arrive your PORT on 19 March,2018 at around AM HRS. Vessel will be discharging 90k MAC FINE IRON ORE as per attached BL's and Vessel particulars attached. We will appreciate if you could kindly advise us your best PDA to enable us confirm agency. Do let us know if you require any further information/documents from our end. Thanks & Regards Steven tao ?? |
Example of a malicious email click to enlarge |
Nome: scan_F4BC20F_pdf.gz MD5: B223CD88F60851EA140B98573AF151AC Size: 231.499 byte |
Subject: TM Project Inquiry |
Dear Sales Team, We have in discussions the TM project with saudi Arabia Ministry of commerce and industry and according to the file attached, so please send us the quotations accordingly and also some pictures will be helpful. Thank you very much and best regards, MOHAMMAD SAMIR KHAN HEAD OF PROCUREMENT EASTERN Dammam Head Office: Al-Manar Arabian Trading & Contracting Corp. King Khalid Street, Near Dammam Central Hospital, Opposite Carrefore Market P.O. BOX 10257, Dammam-31433, Dammam, Saudi Arabia Tel: +96613 – 851 – 7007 Fax: +96613 – 852 – 3881 Al-Hassa Branch Hofouf P.O. BOX 8531- Al-Hassa-S 1982, KSA Tel: +96613 – 575 – 4805 Fax No: +96613 – 575 – 6648 CENTRAL Riyadh Branch King Abdul Aziz Street,Above Kawasaki Showroom, P.O. BOX 19116, Riyadh-11435, Riyadh, K.S.A Tel: +96611 – 225 – 4519 Fax: +96611 – 225 – 4517 WESTERN Jeddah Branch Al-Sameer District Anqra street, Al-Sameer Neighbourhood, Jeddah, K.S.A Tel: +96612 – 688–1772 / +96612 – 688 – 0331 Fax: +96612 – 688 – 0265 Tabuk Branch Prince Abdul Aziz Street, Al-Moroj District, Against Al-Khozamy Palace, Tabuk, K.S.A Tel: +96614 – 432 – 0580 Prime Contact in the Event of Clarification Being Required: Name: Saeed Mohd. Zahrani Position: General Manager Tel. No.: +96613 – 851 – 7007 FaxNo.: +96613 – 852 – 3881 Address: P.O. BOX 10257- Dammam -31433, K.S.A e-Mail: info@manararabian.com |
Example of a malicious email click to enlarge |
Nome: TM Project Inquiry.ace MD5: 16D593EAC631DCE07341AA1C0CAB129B Size: (243.818 byte) |
Subject: Request for the submission of Technical Bid |
Gents, Please find herewith attached specification and RFQ for AD DUQM GSS PROJECT. (Client: OGC) You are requested kindly submit your technical quote for the same. All participating vendors shall be requested to submit the attached data sheet / TOC / RED FORM / VDRL duly filled up and stamped. Vendors who are not submitting the filled up data sheet / TOC / RED FORM / VDRL will be disqualified. 1. AS PER ATTACHED REF. SPEC.: M1-047/16-5-019-4 REV 0 Terms & Conditions: · Please submit your Technical quotation/bid by email. · Please do not alter RFQ quantities. In case you are offering quantities different than RFQ Qty., Please mention in a separate column as "Offered Quantity". · Delivery period is the essence of the contract and as the materials are required for AD DUQM GSS PROJECT. Please quote your best delivery schedule. · Deviations from OGC specification, if any, shall be brought out clearly at the time of quoting. · The quotation shall be for materials strictly in accordance with the specifications, Inspection, Certification & Quality documentation in line with the requirement of OGC & applicable Data Sheet (Non MESC items). · The last date for the technical bid submission shall be 15.03.2018. No further extension will be entertained thereafter. Hence please rush with your technical quote at the earliest on or before the closing of bid submission date. · Please quote the Enquiry Reference no. mentioned above in all correspondence related to this enquiry without fail. Regards, Immagine rimossa dal mittente. Description: ATE Emblem 1 Ketul Gandhi Al Turki Enterprises L. L. C. Address : P. O. Box 2803, P. C. 112, Ruwi, Oman. Office : +968 24621200 EXT: 1165 Fax :+968 24590212 GSM : +968 98049160 Short-code : 1084 Web :www.alturki.com Our new ATE (PDO) office address: 1st floor, Al Nab'a House, Way no. - 277, Bldg No. - 1240, Al Atta Street, Ghala Industrial, Muscat |
Example of a malicious email click to enlarge |
Name: Technical_Specifications pdf..ace / M1-04716-5-019-4 REV 0 pdf..ace MD5: 14ABBD0DD304498533F6657D99994FB9 / FEF68AC1B76087150506581C52A209E3 Size: (243.356 byte) |
Subject: Contract prolongation / DHL SHIPMENT 03-07-18 |
Dear Sir, Please find new contract for the year 2018 in the attachment. The wording of the Contract is the same as it was before. In case you have no amendments, please send it back duly signed&stamped. Regards. Güneş Koç Kalite Güvence Sorumlusu / Quality Assurance Associate Altera Tıbbi Malzeme San. ve Tic. A. Ş. - a Meditera Group Company T: +90 232 513 501 10 / Ext: 225 | F: +90 232 5103 51 14 A: İbni Melek OSB Mah. TOSBİ Yol 4 Sok. No: 29 Tire Organize Sanayi Bölgesi, Tire / İzmir / Turkey E: GUNES.KOC@meditera.com.tr W: www.mediteragroup.com Click here for legal notice / Yasal uyarı için tıklayınız… ######################SECONDA MAIL####################################### Dear Customer, Attached is the Original Shipping documents as assigned to deliver to you. Notification for shipment event group "Pick Up" for 08 Mar 18. Best Wishes, Nina Lin Gateway Import Customs Clearance DHL Express (China) Corp. --------------------------------------------- T: 03-398-15805 | F: 03-399-25860 E:nina.lin@dhl.com | 0800-769-888 |
Example of a malicious email click to enlarge |
Nome: ORIGINAL SHIPMENT DOCUMENT 03072018.zip / EMSTEC- Contract Draft 2018.zip MD5: DA2B8843E9535ADCDEC1ECAC45CA0AC4 / D7C3A92617785DD30688BB5C7DB700D6 Size: (577.262 byte) |
For Vir.IT eXplorer PRO owners, it is also possible to contact for free TG Soft's technical phone support.The details can be found on the support page CLIENTS.
|