Try this on for size: http://www.f-secure.com/weblog/archives/00001303.html " Malicious PDF file (report.pdf or debt.2007.pdf or overdraft.2007.10.26.pdf or so) has been massively spammed through email during last hour and the spam run is still continuing."
Andrew. > -----Original Message----- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On > Behalf Of Don Brown > Sent: Friday, October 26, 2007 1:54 PM > To: declude.virus@declude.com > Subject: [Declude.Virus] bloodhound exploit 163 - Slipping Through > > A customer running Norton reports receiving several infected > e-mails today. > > We are only running the built-in AVG scanner at this time, which isn't > catching this new virus. > > The Symantec site is not too helpful about the characteristics, which > would better enable writing a filter. > > http://www.symantec.com/security_response/writeup.jsp?docid=20 > 07-102318-0451-99 > > Our customer reports they show: From: Lorena Bernal, Subject: > Statement of retained earnings However, no doubt there are other > variants. > > They are caught upon receipt by his Norton anti-virus and quarantined, > so he really can't (and I don't want him to) supply more info. > > Anyone else noticing this virus slipping through? > > Any suggestions appreciated. > > Thanks, > > ---- > Don Brown - Dallas, Texas USA Internet Concepts(r) > [EMAIL PROTECTED] http://www.inetconcepts.net > (972) 788-2364 Fax: (972) 788-5049 > ---- > > > > --- > This E-mail came from the Declude.Virus mailing list. To > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and > type "unsubscribe Declude.Virus". The archives can be found > at http://www.mail-archive.com. > > --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.