AplusWebMaster
Topic Starter
FYI…
- http://www.f-secure.com/weblog/archives/ar…7.html#00001239
July 28, 2007 - "First spam was just text. Spam filters adapted to block that. Then spammers started to use html. Spam filters adapted to block that. Then spammers started to use images. Spam filters adapted to block that. Then spammers started to use PDF attachments. Spam filters are adapting for that right now. And now spammers are starting to use Office files. Like this case in point. You get an email with just a zip. No subject field, no text content… The ZIP contains a single Excel spreadsheet file… and when opened in Excel…it's just stock spam. Such spam gets through filters better…and people probably pay more attention to them, too. Of course, opening unknown XLS files is always risky as there might be malicious code embedded. However, in this case it was just spam…"
(Screenshots available at the URL above.)

- http://preview.tinyurl.com/2f3zfh
July 24, 2007 (Avert Labs blog) - "…A worrying thing is that people may get complacent about Excel spam if it continues. Macro-based exploits are currently making a come back. Imagine what might happen if both the spam presentation and an exploit is combined. A person might open the spreadsheet and think that it was a pump and dump spam, in the meantime a payload would have been dropped."
.
- http://www.f-secure.com/weblog/archives/ar…7.html#00001239
July 28, 2007 - "First spam was just text. Spam filters adapted to block that. Then spammers started to use html. Spam filters adapted to block that. Then spammers started to use images. Spam filters adapted to block that. Then spammers started to use PDF attachments. Spam filters are adapting for that right now. And now spammers are starting to use Office files. Like this case in point. You get an email with just a zip. No subject field, no text content… The ZIP contains a single Excel spreadsheet file… and when opened in Excel…it's just stock spam. Such spam gets through filters better…and people probably pay more attention to them, too. Of course, opening unknown XLS files is always risky as there might be malicious code embedded. However, in this case it was just spam…"
(Screenshots available at the URL above.)
- http://preview.tinyurl.com/2f3zfh
July 24, 2007 (Avert Labs blog) - "…A worrying thing is that people may get complacent about Excel spam if it continues. Macro-based exploits are currently making a come back. Imagine what might happen if both the spam presentation and an exploit is combined. A person might open the spreadsheet and think that it was a pump and dump spam, in the meantime a payload would have been dropped."
.