Full Disclosure mailing list archives

Odd My_Photo.zip in email


From: Ill will <xillwillx () gmail com>
Date: Fri, 13 Jan 2006 10:07:27 -0500

receiving an odd email with an attached zip file called "My_Photo.zip"
containing a .jpg and a .bat that only has execution code of "My
Photo.jpg" in it. the .jpg itself looks to be an encrypted vb dll with
just the .jpg extention changed .. but im just curious as to how this
virus planned on executing itself , ive seen the mydoom virus
spreading this way but included something like a .cpl file or a file
with a bunch of spaces to hide the extention of .pif etc .. not at
home right now to analyze but wondeirng if anyone came across this
--
- illwill
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: