Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

August 25th, 2011, 14:52 GMT · By

New Wave of Xerox WorkCentre Malicious Spam Hits Email Inboxes

SHARE:

Adjust text size:


Fake Xerox WorkCentre emails spread trojan
Enlarge picture
Security researchers warn of a new wave of spam emails posing as automated messages from Xerox WorkCentre Pro multifunctional devices that carry malicious attachments.

The Xeros WorkCentre Pro devices are popular and likely to be found in many business offices. This suggests that the primary targets of this campaign are companies and not individuals.

The rogue emails bear subjects of the form "Scan from a Xerox WorkCentre Pro #[number]" and claim to contain scanned documents.

The emails spoof the automated messages sent by the devices when their real email function is used. They read:

"Please open the attached document. It was scanned and sent to you using a Xerox WorkCentre Pro. Sent by: Guest. Number of Images: 1. Attachment File Type: ZIP [DOC]."

The attachements have names like Xerox_Document_08.23_C11125.zip or Xerox_Scan_08.23_K1274.zip and instead of documents they actually contain trojan installers.

This method of passing infected files as scanned documents is not new, but its repeated reuse suggests that the technique is rather successful.

The campaign shows the inventiveness of malware distributors. Users are much more likely to believe a message sent by what they think is one of their internal devices, than a third-party.

In fact, even users who usually treat email attachments with suspicion, might be tempted to just open and run the file thinking its one of the company's documents.

"As always, be very careful opening unsolicited attachments - even if you do think at first that they could have been sent to you by one of the photocopiers in your office building," advises Graham Cluley, a security expert from Sophos.

Even if your computer has an antivirus program installed, all attachments should be scanned on services like VirusTotal before opening them because they are tested with multiple anitivirus engines.

TELL US WHAT YOU THINK:

959 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


New Wave of Fake Xerox WorkCentre Scan Emails Distribute Trojan

New Xerox WorkCentre Pro Infected Emails in Circulation

Fake Xerox WorkCentre Pro Scans Hide Trojan

READER COMMENTS:


Comment #1 by: lkovnat on 25 Aug 2011, 18:49 UTC reply to this comment

Thanks for spreading the word about these suspicious looking e-mails; as you mentioned this method isn’t a new phenomenon and is something we’ve been advising customers on for more than a year now. I agree with Graham - it’s important that customers be suspicious of all scan-to-e-mail files that they were not expecting to receive and to pay attention to the “From” field of these e-mails. The spam e-mail may fill in the “From” field with a user name to make the e-mail look safe, as opposed to a machine name (i.e. wcp245@xerox.com). I advise all users to only open email attachments that are sent from a reliable, identifiable source. I encourage your readers to check Xerox.com/information-security/news for ongoing tips and advice. Larry Kovnat, Sr. Manager, Product Security

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM