Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: SpamAssassin: users

Spam Du Jour ? *.XLS

 

 

SpamAssassin users RSS feed   Index | Next | Previous | View Threaded


sa-list at alexb

Jul 21, 2007, 7:23 AM

Post #1 of 6 (173 views)
Permalink
Spam Du Jour ? *.XLS

LOL

investors news-76212.xls, et all

no real challenge


robert at schetterer

Jul 21, 2007, 4:08 PM

Post #2 of 6 (156 views)
Permalink
Re: Spam Du Jour ? *.XLS [In reply to]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Yet Another Ninja schrieb:
> LOL
>
> investors news-76212.xls, et all
>
> no real challenge
>
jep , got 3 xls spams today

- --
Mit freundlichen Gruessen
Best Regards

Robert Schetterer

https://www.schetterer.org
Germany
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org

iD8DBQFGopH6fGH2AvR16oERAr7rAJ4vNizIo/EsmdJYGDiIGNsMFifqPwCfYSj6
U6jT3MLdWIbvV8Lmx0oEfg8=
=g5DS
-----END PGP SIGNATURE-----


stucki at mi

Jul 21, 2007, 4:55 PM

Post #3 of 6 (157 views)
Permalink
Re: Spam Du Jour ? *.XLS [In reply to]

On Sun, 22 Jul 2007, Robert Schetterer wrote:

> > investors news-76212.xls, et all
> >
> > no real challenge
> >
> jep , got 3 xls spams today

well, here too,

but I think soon we'll get the whole mix ...
a combinatoric explosion of envelope formats
and content variants, meaning
'any windows-showable-fileformat' *
'all the already known picture-tricks embedded'

Anybody working on generic detectors yet?
(I really would like to plug that (w)hole :-)

Something like amavis or clamav to first unpack
and then spamassassin to analyze it?

Stucki


d.hill at yournetplus

Jul 21, 2007, 6:14 PM

Post #4 of 6 (158 views)
Permalink
Re: Spam Du Jour ? *.XLS [In reply to]

On Sun, 22 Jul 2007 01:55:20 +0200
"Chr. v. Stuckrad" <stucki[at]mi.fu-berlin.de> wrote:
>On Sun, 22 Jul 2007, Robert Schetterer wrote:
>
>> > investors news-76212.xls, et all
>> >
>> > no real challenge
>> >
>> jep , got 3 xls spams today
>
>well, here too,
>
>but I think soon we'll get the whole mix ...
>a combinatoric explosion of envelope formats
>and content variants, meaning
> 'any windows-showable-fileformat' *
> 'all the already known picture-tricks embedded'
>
>Anybody working on generic detectors yet?
>(I really would like to plug that (w)hole :-)
>
>Something like amavis or clamav to first unpack
>and then spamassassin to analyze it?
>
>Stucki

You might also want to keep in mind if some versions of
Outlook are being
used to generate these spams, you could start seeing just
a winmail.dat
attachment. This would indicate a message was generated in
RTF (rich text
format). See:

http://en.wikipedia.org/wiki/TNEF

If that's the case, non Outlook users won't be able to
open the attachments
period. That is unless they have loaded the proper tools
to extract what's
inside.


robert at schetterer

Jul 22, 2007, 1:32 AM

Post #5 of 6 (150 views)
Permalink
Re: Spam Du Jour ? *.XLS [In reply to]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Chr. v. Stuckrad schrieb:
> On Sun, 22 Jul 2007, Robert Schetterer wrote:
>
>>> investors news-76212.xls, et all
>>>
>>> no real challenge
>>>
>> jep , got 3 xls spams today
>
> well, here too,
>
> but I think soon we'll get the whole mix ...
> a combinatoric explosion of envelope formats
> and content variants, meaning
> 'any windows-showable-fileformat' *
> 'all the already known picture-tricks embedded'
>
> Anybody working on generic detectors yet?
> (I really would like to plug that (w)hole :-)
>
> Something like amavis or clamav to first unpack
> and then spamassassin to analyze it?
>
> Stucki
>
Hi,

http://sanesecurity.co.uk/clamav/

catches it now

- --
Mit freundlichen Gruessen
Best Regards

Robert Schetterer

https://www.schetterer.org
Germany
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org

iD8DBQFGoxYdfGH2AvR16oERAo0KAJ96R9cru5KDqyc9nI9HYEgqYmEY/wCfX21o
UYG90NfajRyt8Ld2mg2UlzA=
=sB2r
-----END PGP SIGNATURE-----


stucki at mi

Jul 22, 2007, 7:42 AM

Post #6 of 6 (150 views)
Permalink
Re: Spam Du Jour ? *.XLS --> packed into zip now [In reply to]

On Sun, 22 Jul 2007, Robert Schetterer wrote:

> http://sanesecurity.co.uk/clamav/
>
> catches it now

As seen before, they react fast on news on this list :-)

Now I got the same 'XLS' *inside* a *.zip file!

Stucki

--
Christoph von Stuckrad * * |nickname |<stucki[at]mi.fu-berlin.de> \
Freie Universitaet Berlin |/_*|'stucki' |Tel(days):+49 30 838-75 459|
Mathematik & Informatik EDV |\ *|if online|Tel(else):+49 30 77 39 6600|
Takustr. 9 / 14195 Berlin * * |on IRCnet|Fax(alle):+49 30 838-75 454/

SpamAssassin users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact lists@gossamer-threads.com
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.