Malicious Sales Invoices Being Sent by Cybercriminals

Malicious Sales Invoices Being Sent by Cybercriminals

Would you share this Article with others?  +

Cybercriminals are attempting to trick online users into opening malicious email attachments disguised a sales invoices or bills. If opened, the malicious attachments can infect the recipients' computers or mobile device with a virus, trojan horse, or ransomware. Therefore, recipients of suspicious sales invoice emails are asked to be careful when opening email attachments and should never attempt to open the attachments we are have listed below.

Before opening an attachment, online users should check the attachments' name and ensure that they do not end with the following:

  • .exe
  • .img
  • .iso
  • .gz
  • .tar

The list of extensions above can infect your computer with viruses and malware, therefore, they should never attempt to open them. There are also malicious Microsoft Word documents with names ending with ".docx" that may contain Macro viruses, so it is not recommended to enable Macro or "Edit" when opening suspicious or unexpected Microsoft Word documents via email.

Some Malicious Sales Invoices We Have Received

Subject: revised PI RGP-00332-19

Attachment: REVISED PI_pdf.gz(232 KB)

Dear Sir/madam,

This is a courtesy email regarding the proforma invoice that you

sent to my colleague, please review it immediately as it is not

workable for us.Kindly please double check and confirm by

correcting the following:

1. We agreed on 30% advance but PI is stated 50% advance.

2. Expected time of delivery is different from earlier agreed

shipment date.

Kind Regards,

Santosh Malekar.

Subject: Payment Receipt

Attachment: PaymentReceipt.tar

432 KB


Please confirm the payment advise as attached together with the PI. We want to confirm before we proceed in accordance with a request from your customer to complete the payment process.

Thanks and Best Regards,


Attachment: #10114300988.ace (228 KB)

Good day,

I can't reach you with my main email.

Are you sure your Spam filter is not blocking me out?

All my mails to youstarted bouncing since yesterday

Please as your IT to check what is the problem.

I am now writing with my private email. Hope you receive this one.

Find the attached the payment swift for the part payment from our customer to your account.

Please revert to my other email where we have been communicating.

The payment receipt has references of the invoices paid.

I await your reply with confirmation of receipt of funds.

Best Regards,



Attachment: Order_August#64533,pdf.iso (1,294 KB)

Dear Sir,

I would like to confirm, if the below quotation is still valid?

Your prompt reply is highly appreciated to enable us proceed with order.

Awaiting your reply.

With Best Regards

Anita Wen

Fazlur Rahman

Admin and Procurement

Sr. Assistant Manager (Procurement)


Subject: Required Supplier contact Email IDs - System updates 2019.

Attachment: ZINKLLC072019PO.IMG (1,216 KB)

is this order coming too late? can we get this order urgently? How soon can we get this order shipped? please revert back with invoice of attached order and possibility of shipment as soon as possible.


Nabil S. Kawar P.I.C P.M.P E.P.S

General Manager

Attachment: po.doc.exe (862 KB)

Dear Sir

We are interested to Purchase your product, i got your contact information

from two of our customers.

Please contact us with the following below:-

- Your minimum order quantity.

- Your FOB Prices and FOB Port.

- Your estimated delivery time.

Please fine attached company details and requirements below to preview the samples/specifications needed.

Best Regard


Note: Some of the names, addresses, email addresses, telephone numbers or other information in samples on this website may have been impersonated or spoofed.

Check the comment section below for additional information and share what you know or ask a question about this article by leaving a comment below.

Remember to forward suspicious, malicious, or phishing email messages to us at the following email address: And, report missing persons, scams, untrustworthy, or fraudulent websites to us. Tell us why you consider the websites untrustworthy or fraudulent. Also, to quickly find answers to your questions, use our search engine.

You can help maintain Online Threat Alerts (OTA) by paying a service fee. Click here to make payment.

Comments, Questions, Answers, or Reviews

There are no comments as yet, please leave one below or revisit.

To help protect your privacy, please do not post or remove, your full name, telephone number, email address, username, password, account number, credit card information, home address or other sensitive information in or from your comments, questions, or reviews. Also, remember to keep comments, reviews, answers respectful.

Write Your Comment, Question, Answer, or Review

Write your comment, question, answer, or review in the box below to share what you know or to get answers. NB: We will use your IP address to display your approximate location to other users.

Your comment, question, answer, or review will be posted as an anonymous user because you are not signed in. Anonymous posts cannot be edited or deleted. Sign-in.

Keep your comment respectful or it will not be posted.

Malicious Sales Invoices Being Sent by Cybercriminals