Last revised or Updated on: 14th March, 2016, 2:04 PMAn email with the subject of Emailing: IMG_18977 [ random numbered] pretending to come from admin at your own email domain with a zip attachment is another one from the current bot runs which downloads what looks like either Locky ransomware or Dridex banking Trojan They use email addresses and subjects that will entice a user to read the email and open the attachment. A very high proportion are being targeted at small and medium size businesses, with the hope of getting a better response than they do from consumers. The email looks like: From:admin admin@victim domain.tld Date: Mon 14/03/2016 12:14 Subject: Emailing: IMG_18977 Attachment: IMG_18977.zip Body content: Your message is ready to be sent … Continue reading →