On Thu, 21 Apr 2016 08:33:01 -0500 Chip M. wrote: > Starting about two hours ago, about 40% of my real-time > honeypot spam is a new malware campaign. About a third are > hitting "BAYES_00", with about 10% of all having negative SA > scores. :( > > Full spample (with munged email addresses): > http://puffin.net/software/spam/samples/0040_mal_tgz.txt
Content-Type: application/octet-stream; name="0005500922.tgz" I wonder how common octet-stream is with legitimate .tgz files.