Sponsored by..

Monday, 20 October 2008

"Report Jan-Oct." trojan

This fake email contains an EXE in a ZIP designed to look like a Word document (complete with authentic looking icon), in this case "Statement1-10.doc .exe" (there are 75 spaces in the filename that blogger strips out)

Subject: [name] Report Jan-Oct.
From: "Clara Slaughter"

Dear Customer,

As you requested, we are sending you this report with details on your account
transactions made between 1/1/2008 and 10/1/2008.

At your service,
The attached ZIP file is called Statement1-10.zip. VirusTotal shows detection is poor with what look like generic detections only.

If you mail filter allows it, you should block EXEs in ZIP files. Postini allows this, I guess other filtering services do too.

1 comment:

really-mystified said...

I have been seeing this a handfull in the past 2 weeks. All messages come on Sunday. Avast doesn't see it as a virus but I know it is.