Confirmed on my end. 31 of these hit us in the last hour starting at 10:03 a.m. EST. 80% of these would have passed spam blocking without the extra filtering that we have in place for this sort of thing. It appears to not be seeding, but a real virus spreading in the wild based on the fact that these are mostly clean IP's and they come from all over the place.

Matt



John Carter wrote:

We are currently getting hit with a blast of emails with ZIP attachments.
They are showing clean, at least with F-Prot and ClamAV under Declude, plus
a manual scan by Trend Micro.  They fake our user as sender.

Attachments are among others: info_price.zip, text_sms.zip, max.zip,
Health_and_knowledge.zip, and others.

John C

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.


---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to