New Trojan

Anthony Cartmell ajcartmell at fonant.com
Thu Jul 24 17:14:31 IST 2008


> are the file names consistent?

Possibly, yes, but I suspect only slightly. The filename in two zip files  
I've seen is

Tax_Invoice_________________________NHHDLS883298792929.exe

Oddly Mailscanner doesn't stop this with .exe filename blocking although I  
have max archive depth set to 3 (so it _should_ extract and inspect the  
zip file contents?).

The unzipped .exe does get blocked as expected.

If I save the nasty carefully to my WinXP machine it appears with a fake  
Word document icon (fake 'cause I use OpenOffice, not Word!).

HTH,

Anthony
-- 
www.fonant.com - Quality web sites


More information about the MailScanner mailing list