PDF Invoice Attachment Spam
The email in this campaign appears to be intentionally vague and seemingly safe yet somewhat urgent, to induce the recipient into opening the attached PDF file. The message body is short and non-specific, such as:
The attached PDF files we've seen follow a simple naming convention. The one attached to the above message would be named "Sales Invoice 123456.pdf". You should never open such an attachment, even a PDF file that passes a virus scan, unless you are expecting it and are absolutely sure it is OK.
PDF Malware Details
The email headers look something like this:
Date: Fri, 24 Apr 2015 11:08:36 +0530
Subject: Invoice 123456
Thread-Topic: Invoice 123456
Accept-Language: en-US, en-GB
acceptlanguage: en-US, en-GB
To get instantaneous updates on the latest email spam, follow us on Twitter @SpamStopsHere
Slips Past Antivirus
Antivirus vendors are having more and more difficulty detecting zero-day threats. Antivirus typically only scans the downloaded files, which mutate faster than a/v vendors can push out new definitions. As of more than 5 hours ago, only 2 out of 57 antivirus vendors were detecting the PDF file as a threat. And only 7 were doing so about 5 hours later.
Your best defense against this type of threat is a robust Cloud-based spam filter. Cloud antispam can analyze entire delivery mechanisms and global traffic patterns for spammy behavior, which we have learned how to detect almost instantly. We blocked this campaign within moments and still have it locked down with several independent filter rules designed to detect variants.
We've discussed this issue before, that antivirus programs can't keep up with today's quickly changing email threats.
SpamStopsHere is updated every two minutes, 24/7/365. Because it works in the Cloud, spam filtering updates take effect immediately without the user downloading or installing anything.
If you're having trouble keeping up with these threats, consider trying SpamStopsHere FREE for 30 days. It blocks 99.5% of spam with a false positive rate of less than 0.001%. That means we block fewer that 1 out of 100,000 good emails, which is why businesses and professionals love our service.
Marks used in this article are the properties of their respective owners. This article is for informational purposes. No endorsement by third parties is implied and none should be inferred.