• Outlook User
  • New Outlook app
  • Outlook.com
  • Outlook Mac
  • Outlook & iCloud
  • Developer
  • Microsoft 365 Admin
    • Common Problems
    • Microsoft 365
    • Outlook BCM
    • Utilities & Addins

Don’t be fooled by unexpected attachments!

Slipstick Systems

› Outlook › Don’t be fooled by unexpected attachments!

Last reviewed on June 2, 2020     No Comments

I checked my email last week and discovered a message from a person saying they received a subpoena sent on my behalf, by email. The message had a Word document attached that was the alleged subpoena. It's obviously infected because subpoenas aren't sent by email (besides, I'm not suing him). I read it on my iPhone and thought about opening it to find out what it was infected with – it won’t infect the phone but I wouldn’t learn much either, so I forwarded it to a friend to check out.

email message

Derek took a quick look and reported that the “malicious word doc has 2 copies of a RTF file embedded inside it (MALWR) that when extracted deliver an embedded fareit password stealing malware. These malicious word docs normally also drop a Upatre downloader that in turn download a dyreza banking malware but although the macro inside the word doc seems to indicate that it should do, I haven’t yet managed to extract it yet”.

As far as I’m concerned, what it is infected with is not as important as what you do when you receive a suspicious document. If you receive a suspicious or questionable message with an attachment, don’t open it, don’t reply to it. Just delete it.

While the reading pane is safe to use for email and most attachments will open in a read-only state, looking at a suspicious file not worth the risk - leave that to the pros. If a message looks a little sketchy, don’t even preview it. Hit Delete and move on.

So what if you have an “oops” moment and accidently open a questionable document? If you are using a modern version of Office and are using the default Office settings you might be protected. Office 2010, 2013, and 2016 have macros disabled and protected view on by default. If you or your company enabled macros, you will be protected by Protected View. Protected view prevents macros from running in documents received from Internet sources, including email. Yes, it can be annoying if you receive a lot of attachments by email, but it helps to keep you safe.

If Protected View mode is turned off and macros are enabled, then opening a malicious word document can infect you. When you preview or open an attachment, Outlook will write it to the SecureTemp folder, where it will be scanned by your virus scanner. If the exploit is older, your scanner may catch it, but it’s not worth the risk. New exploits not yet in the virus definitions will be missed!

Definitely DO NOT enable macros or enable editing to see the content, even if a message in the document says you need to enable macros and editing to read the document. DO NOT DO IT!

If you are using an older version of Office, you should seriously consider upgrading. If that is not in the cards right now, make sure all updates are installed and keep your antivirus updated. And be extra alert for infected attachments.

Should you reply to the sender and let him know he is sending infected messages? If you don't know the person, no. If the sender is a real person, he is an innocent victim. It’s less likely his email system is compromised and more likely that his details were spoofed on the message. If it's a person you know, you can let them know. If you are in their address book, it's more likely their account was compromised and they will need to change their password.

If you are interested in reading about it, Derek's write up on the document I received is here: I got this subpoena in my mail box today. In addition to describing the exploits, Derek tells you what you can do to protect yourself, should you receive an infected attachment.

More Information

"How to check your Macro and Protected View Settings"
"How Safe is the Reading Pane?"

Don’t be fooled by unexpected attachments! was last modified: June 2nd, 2020 by Diane Poremsky

Related Posts:

  • Disable Protected View for Outlook Attachments
  • Outlook and the latest RTF Exploits
  • Block Macros in Office 2013/2016
  • Outlook downloads mail slow in Windows 8

About Diane Poremsky

A Microsoft Outlook Most Valuable Professional (MVP) since 1999, Diane is the author of several books, including Outlook 2013 Absolute Beginners Book. She also created video training CDs and online training classes for Microsoft Outlook. You can find her helping people online in Outlook Forums as well as in the Microsoft Answers and TechNet forums.

Subscribe
Notify of
0 Comments
newest
oldest most voted
Inline Feedbacks
View all comments

Visit Slipstick Forums.
What's New at Slipstick.com

Latest EMO: Vol. 30 Issue 34

Subscribe to Exchange Messaging Outlook






Support Services

Do you need help setting up Outlook, moving your email to a new computer, migrating or configuring Office 365, or just need some one-on-one assistance?

Our Sponsors

CompanionLink
ReliefJet
  • Popular
  • Latest
  • Week Month All
  • Use Classic Outlook, not New Outlook
  • Mail Templates in Outlook for Windows (and Web)
  • How to Remove the Primary Account from Outlook
  • Reset the New Outlook Profile
  • Disable "Always ask before opening" Dialog
  • Adjusting Outlook's Zoom Setting in Email
  • How to Hide or Delete Outlook's Default Folders
  • This operation has been cancelled due to restrictions
  • Change Outlook's Programmatic Access Options
  • Shared Mailboxes and the Default 'Send From' Account
  • Opt out of Microsoft 365 Companion Apps
  • Mail Templates in Outlook for Windows (and Web)
  • Urban legend: Microsoft Deletes Old Outlook.com Messages
  • Buttons in the New Message Notifications
  • Move Deleted Items to Another Folder Automatically
  • Open Outlook Templates using PowerShell
  • Count and List Folders in Classic Outlook
  • Google Workspace and Outlook with POP Mail
  • Import EML Files into New Outlook
  • Opening PST files in New Outlook
Ajax spinner

Recent Bugs List

Microsoft keeps a running list of issues affecting recently released updates at Fixes or workarounds for recent issues in classic Outlook (Windows).

For new Outlook for Windows: Fixes or workarounds for recent issues in new Outlook for Windows .

Outlook for Mac Recent issues: Fixes or workarounds for recent issues in Outlook for Mac

Outlook.com Recent issues: Fixes or workarounds for recent issues on Outlook.com

Office Update History

Update history for supported Office versions is at Update history for Office

Outlook Suggestions and Feedback

Outlook Feedback covers Outlook as an email client, including Outlook Android, iOS, Mac, and Windows clients, as well as the browser extension (PWA) and Outlook on the web.

Outlook (new) Feedback. Use this for feedback and suggestions for Outlook (new).

Use Outlook.com Feedback for suggestions or feedback about Outlook.com accounts.

Other Microsoft 365 applications and services




New Outlook Articles

Opt out of Microsoft 365 Companion Apps

Mail Templates in Outlook for Windows (and Web)

Urban legend: Microsoft Deletes Old Outlook.com Messages

Buttons in the New Message Notifications

Move Deleted Items to Another Folder Automatically

Open Outlook Templates using PowerShell

Count and List Folders in Classic Outlook

Google Workspace and Outlook with POP Mail

Import EML Files into New Outlook

Opening PST files in New Outlook

Newest Code Samples

Open Outlook Templates using PowerShell

Count and List Folders in Classic Outlook

Insert Word Document into Email using VBA

Warn Before Deleting a Contact

Use PowerShell to Delete Attachments

Remove RE:, FWD:, and Other Prefixes from Subject Line

Change the Mailing Address Using PowerShell

Categorize @Mentioned Messages

Send an Email When You Open Outlook

Delete Old Calendar Events using VBA

Repair PST

Convert an OST to PST

Repair damaged PST file

Repair large PST File

Remove password from PST

Merge Two Data Files

Sync & Share Outlook Data

  • Share Calendar & Contacts
  • Synchronize two computers
  • Sync Calendar and Contacts Using Outlook.com
  • Sync Outlook & Android Devices
  • Sync Google Calendar with Outlook
  • Access Folders in Other Users Mailboxes

Diane Poremsky [Outlook MVP]

Make a donation

Mail Tools

Sending and Retrieval Tools

Mass Mail Tools

Compose Tools

Duplicate Remover Tools

Mail Tools for Outlook

Online Services

Calendar Tools

Schedule Management

Calendar Printing Tools

Calendar Reminder Tools

Calendar Dates & Data

Time and Billing Tools

Meeting Productivity Tools

Duplicate Remover Tools

Productivity

Productivity Tools

Automatic Message Processing Tools

Special Function Automatic Processing Tools

Housekeeping and Message Management

Task Tools

Project and Business Management Tools

Choosing the Folder to Save a Sent Message In

Run Rules on messages after reading

Help & Suggestions

Submit Outlook Feature Requests

Slipstick Support Services

Buy Microsoft 365 Office Software and Services

Visit Slipstick Forums.

What's New at Slipstick.com

Home | Outlook User | Exchange Administrator | Office 365 | Outlook.com | Outlook Developer
Outlook for Mac | Common Problems | Utilities & Addins | Tutorials
Outlook & iCloud Issues | Outlook Apps
EMO Archives | About Slipstick | Slipstick Forums
Submit New or Updated Outlook and Exchange Server Utilities

Send comments using our Feedback page
Copyright © 2025 Slipstick Systems. All rights reserved.
Slipstick Systems is not affiliated with Microsoft Corporation.

:wpds_smile::wpds_grin::wpds_wink::wpds_mrgreen::wpds_neutral::wpds_twisted::wpds_arrow::wpds_shock::wpds_unamused::wpds_cool::wpds_evil::wpds_oops::wpds_razz::wpds_roll::wpds_cry::wpds_eek::wpds_lol::wpds_mad::wpds_sad::wpds_exclamation::wpds_question::wpds_idea::wpds_hmm::wpds_beg::wpds_whew::wpds_chuckle::wpds_silly::wpds_envy::wpds_shutmouth:
wpDiscuz

Sign up for Exchange Messaging Outlook

Our weekly Outlook & Exchange newsletter (bi-weekly during the summer)






Please note: If you subscribed to Exchange Messaging Outlook before August 2019, please re-subscribe.

Never see this message again.

You are going to send email to

Move Comment