A new type of Spam

Today one of our staff received an email that at first looked very real but upon further analysis it was hiding an obvious Trojan payload.

the body of the email was

From: Rodrigo Hansen [mailto: disconnectionsms@ramblinexpress.com This e-mail address is being protected from spambots. You need JavaScript enabled to view it ]

Sent: Thursday, July 22, 2010 3:11 PM

To: XXXXXXXXXX

Subject: Scan from a Xerox WorkCentre Pro N 1209257

 

Please open the attached document. It was scanned and sent to you using a Xerox WorkCentre Pro.

 

Sent by: Guest

Number of Images: 1

Attachment File Type: ZIP [DOC]

 

WorkCentre Pro Location: machine location not set Device Name: XRX8204AA56CDB0655494s was an attachment

 


The attachment was xerox_scan_2772341.zip

I have to give them kudos as they did a good job of making this look harmless as we use our printer to send emails all the time. Its a very convenient way of sending scanned documents.

As always, if you don't know the person then you probably can't trust their attachments and should delete the emails.

Mark....

 


Tags:

Comments/Links: