{"id":516,"date":"2015-05-28T09:51:38","date_gmt":"2015-05-28T13:51:38","guid":{"rendered":"http:\/\/tfr.info-safety.com\/?p=516"},"modified":"2015-05-28T09:51:38","modified_gmt":"2015-05-28T13:51:38","slug":"beware-that-safe-attachment","status":"publish","type":"post","link":"https:\/\/tfr.info-safety.com\/?p=516","title":{"rendered":"Beware That &#8220;Safe&#8221; Attachment"},"content":{"rendered":"<p>Recently, &#8220;my bank&#8221; sent me an email with a notice about my account.\u00a0 Being a security conscious IT guy, I was <a href=\"http:\/\/tfr.info-safety.com\/wp-content\/uploads\/2015\/05\/WellsFargo.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-518\" src=\"http:\/\/tfr.info-safety.com\/wp-content\/uploads\/2015\/05\/WellsFargo.jpg\" alt=\"WellsFargo\" width=\"479\" height=\"216\" srcset=\"https:\/\/tfr.info-safety.com\/wp-content\/uploads\/2015\/05\/WellsFargo.jpg 479w, https:\/\/tfr.info-safety.com\/wp-content\/uploads\/2015\/05\/WellsFargo-300x135.jpg 300w\" sizes=\"auto, (max-width: 479px) 100vw, 479px\" \/><\/a>99.999% sure that no bank would ever send an email with a .html attachment. After updating Norton and Malwarebytes,\u00a0 I got clean scans of the attachment from both.\u00a0 Even though all the links in the email were to Wells Fargo, I was certain that the attachment had malicious intent, and uploaded it to Virus Total, and 1 of the 57 online scanners, 56 gave a green check mark, and 1 correctly said <em>Heuristics.Phishing.Email.SpoofedDomain.<\/em><\/p>\n<p><a href=\"http:\/\/tfr.info-safety.com\/wp-content\/uploads\/2015\/05\/scanresults.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-517\" src=\"http:\/\/tfr.info-safety.com\/wp-content\/uploads\/2015\/05\/scanresults.jpg\" alt=\"scanresults\" width=\"757\" height=\"237\" srcset=\"https:\/\/tfr.info-safety.com\/wp-content\/uploads\/2015\/05\/scanresults.jpg 757w, https:\/\/tfr.info-safety.com\/wp-content\/uploads\/2015\/05\/scanresults-300x94.jpg 300w\" sizes=\"auto, (max-width: 757px) 100vw, 757px\" \/><\/a>Had the attachment been a virus or trojan, the detection rate may have been much higher.\u00a0 Regardless, be careful.\u00a0 Don&#8217;t think that your security software will protect you from willy-nilly clicking on attachments, because it may not. I have had other instances of attached trojans getting clean scans.\u00a0 Only after I uploaded them to my security software vendor did they analyze and update their software to detect and remove them. It&#8217;s dangerous out there.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently, &#8220;my bank&#8221; sent me an email with a notice about my account.\u00a0 Being a security conscious IT guy, I was 99.999% sure that no bank would ever send an email with a .html attachment. After updating Norton and Malwarebytes,\u00a0 I got clean scans of the attachment from both.\u00a0 Even though all the links in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,6,3],"tags":[8,9,5],"class_list":["post-516","post","type-post","status-publish","format-standard","hentry","category-information-security","category-privacy","category-technology","tag-privacy","tag-technology","tag-technology-frustration-remediation"],"_links":{"self":[{"href":"https:\/\/tfr.info-safety.com\/index.php?rest_route=\/wp\/v2\/posts\/516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tfr.info-safety.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tfr.info-safety.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tfr.info-safety.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tfr.info-safety.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=516"}],"version-history":[{"count":3,"href":"https:\/\/tfr.info-safety.com\/index.php?rest_route=\/wp\/v2\/posts\/516\/revisions"}],"predecessor-version":[{"id":521,"href":"https:\/\/tfr.info-safety.com\/index.php?rest_route=\/wp\/v2\/posts\/516\/revisions\/521"}],"wp:attachment":[{"href":"https:\/\/tfr.info-safety.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=516"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tfr.info-safety.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=516"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tfr.info-safety.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}