Today one of our staff received an email that at first looked very real but upon further analysis it was hiding an obvious Trojan payload.
the body of the email was
From: Rodrigo Hansen [mailto: disconnectionsms@ramblinexpress.com This e-mail address is being protected from spambots. You need JavaScript enabled to view it ]
Sent: Thursday, July 22, 2010 3:11 PM
To: XXXXXXXXXX
Subject: Scan from a Xerox WorkCentre Pro N 1209257
Please open the attached document. It was scanned and sent to you using a Xerox WorkCentre Pro.
Sent by: Guest
Number of Images: 1
Attachment File Type: ZIP [DOC]
WorkCentre Pro Location: machine location not set Device Name: XRX8204AA56CDB0655494s was an attachment
The attachment was xerox_scan_2772341.zip
I have to give them kudos as they did a good job of making this look harmless as we use our printer to send emails all the time. Its a very convenient way of sending scanned documents.
As always, if you don't know the person then you probably can't trust their attachments and should delete the emails.
Mark....