Skip to content

Jason Rush

Pseudo-random blatter of Jason Rush

  • Projects

Tag Archives: vb

DocuSign Phishing

Over the last week or so I’ve received two batches of slightly different DocuSign phishing attempts. They are typical “click a link in the email that downloads a malicious .doc you have to enable macros in” attacks, though the first time I’ve seen DocuSign as the bluff. Also somewhat interesting that these attacks seem to …

Continue reading “DocuSign Phishing”

Posted byJason RushMay 19, 2017May 19, 2017Posted inSpam Email BreakdownsTags: .doc, docusign, encoded, phishing, vb, vba, vbscriptLeave a comment on DocuSign Phishing

Re: unknown charge on my card

I received the following email from our address on a clients system (with their email domain name redacted): From: denise@chefspecialties.com [mailto:denise@chefspecialties.com] Sent: Thursday, June 16, 2016 6:36 AM Subject: Re: unknown charge on my card What is this $816.27 charge on my credit card? It shows this amount charged by <REDACTED DOMAIN NAME>. Please check …

Continue reading “Re: unknown charge on my card”

Posted byJason RushJune 16, 2016June 24, 2016Posted inSpam Email BreakdownsTags: .doc, spam, vb, vba, vbscriptLeave a comment on Re: unknown charge on my card

letter.hta – Ransomware

This email was a reply to what seemed to be a completely legitimate email from a client. The email contained a password-protected .rar file named after the recipient (May have been passed using first & last name in unsuspecting senders contacts list?). The reply message: Hi, I attach a scanned copy of the letter to …

Continue reading “letter.hta – Ransomware”

Posted byJason RushJune 24, 2013January 11, 2016Posted inSpam Email BreakdownsTags: .FILEBLOCKED, .hta, .onion, .rar, encoded, powershell, ransomware, tor, vb, vbscriptLeave a comment on letter.hta – Ransomware
Jason Rush, Proudly powered by WordPress.
  • Spam Email Breakdowns
  • Fixes
  • Announcements
  • Contact