Sophos has posted a blog entry about a fake security update of its software.

The spam include an EXE file pretending to be a rar (compressed) file. The filename is SOPHOS IDE scanner.rar according to the article.

When users run the file, it will attempt to install malware.

The blog entry include the text of what the body of the email looks like. The message is an altered version of a text from of a genuine Sophos download page.

Source: Sophos