[Esd-l] ALERT: new .ZIP worm uses multiple obfuscation layers

I just got what is obviously a worm - meaningless body text and a Zip
file attachment.

The sanitizer DID NOT block it, because the Zip file contained only a
.htm file. That HTML page contained an apparently auto-executing
base-64 encoded .EXE.

The message itself had an HTML body part containing IFRAME code
intended to automatically open the Zip in an HTML-enabled mail client.
This part WAS defanged, but the Zip file attachment was visible to the
end user and thus the user could still self-infect.

You may want to add "*.html?" and "*.eml" and "*.msg" to your zipfile
poison list.

This is getting annoying. I *so* do not want to recurse into zip

