New Trojan

Alex Broens ms-list at alexb.ch
Thu Jul 24 16:23:06 IST 2008


On 7/24/2008 4:58 PM, Anthony Cartmell wrote:
>>> Not according to VirusTotal!
>>>  ClamAV, Microsoft, and VBA32 are the only ones which dtect my sample.
>>
>> OK, it may have morphed, but Sophos has been detecting something in 
>> the UPS invoice zip files, which clamav didn't since the weekend.
> 
> It seems to be morphing quite a bit, and clamav has had several more 
> updates: I'm seeing 7814 at the mo.
> 

are the file names consistent?

if yes, a SA mimeheader header rule can do the magic



More information about the MailScanner mailing list