Fake “Scan from a HP OfficeJet” email lead to malware

Posted by | February 28, 2012 | Software security tools | No Comments


A hot topic of the end of the month is the Fake “Scan from a HP OfficeJet” email lead to malware

In the last few weeks there has benn notifications going around about documents having been scanned and sent via a HP OfficeJet printer/scanner that are trying to mislead users again and trick them to open the attached HTML files:

Fake "Scan from a HP OfficeJet" email lead to malware

This campaign is very spread, but the subject lines and the content of the emails, and also the name of the attached file, are continuously changed a little so that they can bypass spam filters.

The attached HTML files of the Fake “Scan from a HP OfficeJet” email lead to malware carry a malicious script that forces the victims’ browser to visit third-party sites likely laden with exploit code and/or malware.

“Attacks which cloak their true intentions by posing as a emailed scan from a printer are nothing new, and in the past have helped cybercriminals infect computers with Java and Adobe exploits,”points out Graham Clueley. “Computer users need to learn to be wary of unsolicited attachments, and not blindly click on something just because it pretends to be an official communication.”

The Fake “Scan from a HP OfficeJet” email lead to malware is only a small bit of the attacks that are currently roaming online.

About Network Security

At SecurityNet.org we believe each of us plays an important role in network security, and data protection. The articles on this site were written to keep each of us informed on the ever changing security scene so that we might stay one step ahead of those who would compromise our systems. If you have an article that you feel our visitors would benefit from please submit it via the contact form, or via email and we will publish it in the next available slot.