Return of the mass-mailing malware

I have not seen a mass mailer for ages. Before fake AVs, they were the one of the most commonly seen malware to pass through SophosLabs. Mass mailers can be hilarious at times, especially when the message body is a funny one. While trawling through spam messages, I had a whiff of nostalgia.

The spam came with a zip attachment and it is detected as W32/MyDoom-Gen and Mal/ZipMal-B. After quick 10 seconds unpacking and analysis <yes, I’m so smart ;)>, it is obvious that the spam was mass-mailed from an infected computer.

ahhhh, I missed you, mass mailers.