Multiple subject lines, various senders – nm.pdf

This email below has been confirmed as malicious or fraudulent by the Information Security department. If you have received this phishing email, do not open any attachments or follow the link(s) in the message; simply delete the email.

The University has received many recent phishing messages with various subject lines and senders, but all with the attachment “nm.pdf”.  The senders are random names and e-mail addresses from domains around the world.  Examples of sender addresses are “Sandy <sandy.buckman45@aaalogic.com>”, “Randi <randi.crockett101@friseur-ansbach.de>”, and “Graciela <graciela.potts8364@pullan.co.uk>”.  The subject lines are all single words, followed by an underscore and a four- to eight-digit number; examples are “Scan_24339400”, “File_836133”, and “Document_1870842”.  The attachments are all infected PDF files named “nm.pdf”.  An example is shown below.

Article Categories: blog