Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

FedEx email virus? not detected

today I received an email with a zipped file that pretends to be from FedEx.  I had prior knowledge of the "scam" and I'm pretty sure the attached zip is a virus; probably a "Windows OS" virus, but a virus.

Sophos for Mac did not detect any threats, I got no pop ups, nothing.  So I opened Sophos and had it scan the directory that the email is in.  It still did not find it.

Is there a procedure for sending in samples of "suspected" viruses??  (I realize that I need to delete the file and email, but was wondering if I could send it in so Sophos can add it to a database or something.)

thanks. 

:1000691


This thread was automatically locked due to age.
Parents
  • Hello leilani,

    the email transfer protocol is historically 7bit ASCII and although it has been extended to allow 8bit any content that is not plain text has to be encoded  or wrapped in some form. I'll spare you the details here. Suffice to say a mail message is kind of special container which will not be "unpacked" by the operating system or it extensions. Thus a stored email (whether a single item or in a mailbox) is neither "executable" nor an archive in the narrower sense.

    Mail does not "extract" and decode the attachments to their original form when storing email (in Library), other clients (like Eudora) do. Thus a scan of Documents/Eudora Folder/ would have detected it in the .zip archive in some of the subfolders. 

    What is the solution for this??

     Just delete the mail   

    Christian

    :1000717
Reply
  • Hello leilani,

    the email transfer protocol is historically 7bit ASCII and although it has been extended to allow 8bit any content that is not plain text has to be encoded  or wrapped in some form. I'll spare you the details here. Suffice to say a mail message is kind of special container which will not be "unpacked" by the operating system or it extensions. Thus a stored email (whether a single item or in a mailbox) is neither "executable" nor an archive in the narrower sense.

    Mail does not "extract" and decode the attachments to their original form when storing email (in Library), other clients (like Eudora) do. Thus a scan of Documents/Eudora Folder/ would have detected it in the .zip archive in some of the subfolders. 

    What is the solution for this??

     Just delete the mail   

    Christian

    :1000717
Children
No Data