Today I discovered a new spam on my server that at first I thought might be a 
virus.  It had the subject line "Bill Summary - Invoice #36644" and "August 
Payment Summary, Invoice #48729" with the number being random.  It delivers its 
message inside an attached word document called "invoice.doc". When I sent it 
to www.virustotal.com, nothing was detected. Just to be safe I copied it to an 
old Macintosh, but couldn't open it with MS Word there. I opened the 
invoice.doc file with a text editor and found it contained the standard OEM 
software sales pitch with a link to a web site. I'm still not certain that it 
isn't a new virus hidden behind a spam.

The header seems to contain a strange cr/lf pattern as Declude has trouble with 
it and ends up putting its X-Header messages at the end of the file.  Some were 
picked up by RBLs some were not.

Anyone else seen this before?

Gary




---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail".  The archives can be found
at http://www.mail-archive.com.

Reply via email to