"Please DocuSign this Document Contract Changes" Virus Email

Please DocuSign this Document Contract Changes Virus Email

The email message below: "Please DocuSign this document: Contract_changes_08_27_2014.pdf," is a fake and has a link to a malicious website that contains a Zip file, which contains a virus or Trojan horse. The message was not sent by DocuSign or ATT, but by cyber-criminals, to trick the recipients into clicking on the link within it, by claiming that ATT has sent a DocuSign document. So, if you receive the same email message, please do not attempt to click on the links within it.

The Virus Email Message

Please DocuSign this Document - Contract_changes_08_27_2014.pdf

Subject: Please DocuSign this document: Contract_changes_08_27_2014.pdf
Please review and sign your document
From: AT&T (service @att.com)


AT&T Contract Changes has sent you a new DocuSign document to view and sign. Please click on the 'View Documents' link below to begin signing.

View Documents' link below to begin signing.

View Documents

Alternately, you can access these documents by visiting docusign.com, clicking the 'Access Document' link, and using this security code:

7OE62SYZ65AD487 0BB791C1EKYC65N5M1

This message was sent to you by AT&T who is using the DocuSign Electronic Signature Service. If you would rather not receive email from this sender you may contact the sender with your request.

If you need assistance, please contact DocuSign Support (service @docusign.com)

The Global Standard For Digital Transaction Management

Clicking on the "View Documents" button or link in the email message will take you to the following malicious website and ask you to download a file disguised as a PDF document.

The Malicious Website

Fake DocuSign Website
Request for Signature
From: Eric Blocker - AT&T Team
Documents (1): Contract_changes_08_27_2014.pdf

Clicking the "Download Document" button or link on the malicious website, will download the file "Contract_changes_08_27_2014.zip" that contains the malicious file "Contract_changes_08_27_2014.exe".

Note: The file name may change.

We found the following threats after scanning the malicious file:

  • Crypt3.ALSX
  • Win32.Malware!Drop
  • Trojan.GenericKD.1826449
  • TR/Dldr.Upatre.AA.18
  • Win32:Malware-gen
  • Trojan.Win32.Waski.bF
  • Trojan.GenericKD.1826449
  • Trojan.Malware.Obscu.Gen.002
  • Packed.Win32.Katusha.1!O
  • TrojWare.Win32.TrojanDownloader .Waski.A
  • Trojan.DownLoad3.33795
  • Win32/TrojanDownloader .Waski.F

The cybercriminals behind these malicious email message aims are to trick the curious recipients into opening the malicious file that will infect their computers with a virus or Trojan horse.

Once your computer has become infected with this malicious Trojan horse, the cybercriminals behind this email message will be able to access and take control of your computer remotely from anywhere around the world. They may spy on you, use your computer to commit cybercrimes, or steal your personal and financial information.

Now, if you have already open malicious file, please do a full scan of your computer with the antivirus software installed on it.

If you don’t have antivirus software installed on your computer, please click here for a list of free antivirus software.

Click here for a list of email attachments you should never open, regardless of where they came from.

For a list of other virus email messages, please click here.

Check the comment section below for additional information, share what you know, or ask a question about this article by leaving a comment below. And, to quickly find answers to your questions, use our search Search engine.

Note: Some of the information in samples on this website may have been impersonated or spoofed.

Was this article helpful?  +
Share this with others:

Comments, Questions, Answers, or Reviews

There are no comments as yet, please leave one below or revisit.

To protect your privacy, please remove sensitive or identifiable information from your comments, questions, or reviews. We will use your IP address to display your approximate location to other users when you make a post. That location is not enough to find you.

Your post will be set as anonymous because you are not signed in. An anonymous post cannot be edited or deleted, therefore, review it carefully before posting. Sign-in.

Write Your Comment, Question, Answer, or Review

"Please DocuSign this Document Contract Changes" Virus Email