The attachment is a hidden executable (does run some code on the victim's machine, despite not being an .EXE or .COM), containing malicious code - a virus, for example, or a keylogger for stealing passwords, etc.
It is very important to remember that due to the insecure environment that e-mail currently is, the legitimate companies DO NOT send attachments. They ocnduct business via secure websites instead. |