

Macros, used to automate aspects of your documents, are a tried and tested way of infecting a PC with malware.

Opening the document quickly becomes a game of Macro-related risk. This is because the large file size may prove too difficult for the tools to get a handle on and properly analyse. Malware authors are artificially pumping up the size of the document in order to try and fool or break security tools. In fact, a file size of 500MB is a potential indicator that Emotet is lurking in the background. You won’t find many genuine Word documents weighing in at 500MB or more. This file’s size is 548,164 KB (548 MB), which is very suspicious. Opening the attachment up reveals a Word document called W-9 form.doc The attachment, W-9 form.zip, is 709 KB in size. Let me know if you would like a hard copy mailed as well. The rather short message reads as follows: The email, which contains an attachment and very little text, looks like this: Our Senior Director of Threat Intelligence, Jerome Segura, found an email being sent out with the title of “IRS Tax Forms W-9” which appears to have been sent from “IRS Online Center”. In this case, the Form W-9 is being used as a lure for people to download something sinister. Name, address, and Tax Identification Number are all things you can expect to fill in on one of these forms. An IRS W-9 tax form scamĪ Form W-9 is a form you fill in to confirm certain personal details with the IRS. Tax season is upon us and, as with every year, we're seeing tax scammers rearing their heads.īelow, we have an example of a tax scam currently in circulation along with some suggestions for avoiding these kinds of attacks.
