This email was a reply to what seemed to be a completely legitimate email from a client. The email contained a password-protected .rar file named after the recipient (May have been passed using first & last name in unsuspecting senders contacts list?). The reply message: Hi, I attach a scanned copy of the letter to …