CVE-2017-0199 – 0-day malware delivered by a multitude of different emails.

  1. All of ours are coming in malformed, so you don’t see an attachment, you see a boundary and base64 text. I had to run it through a converter to get the malware, to then run through virustotal.

    • I get that with lots of malware but not these. They have all arrived as proper rtf word docs. I have received about 150 that are seen by my spam filter as low spam so deliverable ( all to a couple of domains with a lax filter to get them easily) and about 2000 all in spam quarantine so far today. First seen approx. 10am and steadily continuing

