New Trojan
Alex Broens
ms-list at alexb.ch
Thu Jul 24 16:23:06 IST 2008
On 7/24/2008 4:58 PM, Anthony Cartmell wrote:
>>> Not according to VirusTotal!
>>> ClamAV, Microsoft, and VBA32 are the only ones which dtect my sample.
>>
>> OK, it may have morphed, but Sophos has been detecting something in
>> the UPS invoice zip files, which clamav didn't since the weekend.
>
> It seems to be morphing quite a bit, and clamav has had several more
> updates: I'm seeing 7814 at the mo.
>
are the file names consistent?
if yes, a SA mimeheader header rule can do the magic
More information about the MailScanner
mailing list