Am 21.04.2016 um 17:07 schrieb RW:
On Thu, 21 Apr 2016 08:33:01 -0500
Chip M. wrote:

Starting about two hours ago, about 40% of my real-time
honeypot spam is a new malware campaign.  About a third are
hitting "BAYES_00", with about 10% of all having negative SA
scores. :(

Full spample (with munged email addresses):
        http://puffin.net/software/spam/samples/0040_mal_tgz.txt


Content-Type: application/octet-stream; name="0005500922.tgz"

I wonder how common  octet-stream is with legitimate  .tgz
files

sadly you need to expect "application/octet-stream" for nearly any filetype, learned the hard way by doing mime-checks on webservers

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to