Gary, you beat them by a day with your own assessment, but Symantec
blogged about this virus twice today:
http://www.symantec.com/enterprise/security_response/weblog/2007/04/spam
_attack_rared_trojan.html
An interesting point is that they have blocked 1.2 million messages by
tackling the text of
Basically that is what ClamAV is doing. It detects it as a phishing spam.
Original Message
From: Colbeck, Andrew [EMAIL PROTECTED]
Sent: Thursday, April 26, 2007 6:11 PM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] new virus with .rar attachment
Gary, you
.
Original Message
From: Colbeck, Andrew [EMAIL PROTECTED]
Sent: Thursday, April 26, 2007 6:11 PM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] new virus with .rar attachment
Gary, you beat them by a day with your own assessment, but Symantec
blogged about this virus twice
ClamAV is now picking this up as Email.Phishing.RB-686
Original Message
From: Gary Steiner [EMAIL PROTECTED]
Sent: Wednesday, April 25, 2007 1:48 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] new virus with .rar attachment
I started getting some messages