[Declude.Virus] bloodhound exploit 163 - Slipping Through

2007-10-26 Thread Don Brown
A customer running Norton reports receiving several infected e-mails today.

We are only running the built-in AVG scanner at this time, which isn't
catching this new virus.

The Symantec site is not too helpful about the characteristics, which
would better enable writing a filter.

http://www.symantec.com/security_response/writeup.jsp?docid=2007-102318-0451-99

Our customer reports they show: From: Lorena Bernal, Subject:
Statement of retained earnings  However, no doubt there are other
variants.

They are caught upon receipt by his Norton anti-virus and quarantined,
so he really can't (and I don't want him to) supply more info.

Anyone else noticing this virus slipping through?

Any suggestions appreciated.

Thanks,


Don Brown - Dallas, Texas USA Internet Concepts®
[EMAIL PROTECTED]   http://www.inetconcepts.net
(972) 788-2364Fax: (972) 788-5049




---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.



RE: [Declude.Virus] bloodhound exploit 163 - Slipping Through

2007-10-26 Thread Colbeck, Andrew
Try this on for size:

http://www.f-secure.com/weblog/archives/1303.html
 
 
 Malicious PDF file (report.pdf or debt.2007.pdf or
overdraft.2007.10.26.pdf or so) has been massively spammed through email
during last hour and the spam run is still continuing.


Andrew.


 

 -Original Message-
 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On 
 Behalf Of Don Brown
 Sent: Friday, October 26, 2007 1:54 PM
 To: declude.virus@declude.com
 Subject: [Declude.Virus] bloodhound exploit 163 - Slipping Through
 
 A customer running Norton reports receiving several infected 
 e-mails today.
 
 We are only running the built-in AVG scanner at this time, which isn't
 catching this new virus.
 
 The Symantec site is not too helpful about the characteristics, which
 would better enable writing a filter.
 
 http://www.symantec.com/security_response/writeup.jsp?docid=20
 07-102318-0451-99
 
 Our customer reports they show: From: Lorena Bernal, Subject:
 Statement of retained earnings  However, no doubt there are other
 variants.
 
 They are caught upon receipt by his Norton anti-virus and quarantined,
 so he really can't (and I don't want him to) supply more info.
 
 Anyone else noticing this virus slipping through?
 
 Any suggestions appreciated.
 
 Thanks,
 
 
 Don Brown - Dallas, Texas USA Internet Concepts(r)
 [EMAIL PROTECTED]   http://www.inetconcepts.net
 (972) 788-2364Fax: (972) 788-5049
 
 
 
 
 ---
 This E-mail came from the Declude.Virus mailing list.  To
 unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
 type unsubscribe Declude.Virus.The archives can be found
 at http://www.mail-archive.com.
 
 


---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.