> Turns out somebody (most likely an EMC/RSA employee) had uploaded the email and attachment to the Virustotal online scanning service on 19th of March.
Would that be some automated system that sends samples - or would the user have to manually find the .msg file and upload it?
Because I really can't see a generic 'office drone' at EMC uploading every bit of malware that comes into their inbox, especially if they're also likely to open this kind of dodgy-looking email...