[65635] in North American Network Operators' Group
Re: new nasty email virus trick to bypass scanners
daemon@ATHENA.MIT.EDU (Steven M. Bellovin)
Wed Dec 3 22:06:00 2003
From: "Steven M. Bellovin" <smb@research.att.com>
To: Mike Tancsa <mike@sentex.net>
Cc: nanog@nanog.org
In-Reply-To: Your message of "Wed, 03 Dec 2003 17:24:19 EST."
<6.0.1.1.0.20031203171513.089a6c00@209.112.4.2>
Date: Wed, 03 Dec 2003 22:05:10 -0500
Errors-To: owner-nanog-outgoing@merit.edu
In message <6.0.1.1.0.20031203171513.089a6c00@209.112.4.2>, Mike Tancsa writes:
>
>
>OK, here is a nasty virus trick. The message gets sent in a password
>protected zip file. The text of the messages says here are my pics and
>enter in the passwd xxxx to view the archive.
>
Is this in the wild yet? Any other details worth looking for?
Symantec's AV site apparently has nothing on it.
--Steve Bellovin, http://www.research.att.com/~smb