[Esd-l] W32.Yaha.P@mm virus hidden in zip file

John D. Hardin jhardin at impsec.org
Mon Aug 25 16:38:21 PDT 2003

On Mon, 25 Aug 2003, Bob Pietruszka wrote:

> Does anyone know the proper syntax for trapping a file with .zip as the 
> last of two file extensions. I've tried modifying a line that's already in 
> there (*.[a-z][a-z][a-z0-9].exe to *.[a-z][a-z][a-z0-9].zip) but it didn't 
> seem to catch a double extension zip file. The file I got was 
> CURSOR03.cur.zip. 

Poisoning only applies to mangled extensions. You need to add "zip" to
the list of mangled extensions, and then your .zip rule will work.

'course, this will mangle the filenames on all .zip file attachments
you receive... Your choice. :)

