Rupert Gallagher skrev den 2023-02-07 11:15:
https://www.virustotal.com/gui/file/f4d587f60f2d34add9f77fcbd8c3c0df3ca51cfaecd9de85c45d25647eaac40bBoth SA and ClamAV passed it as legit. We should have a SA rule that says: "attached file with unknown data type".
or https://sanesecurity.com/foxhole-databases/