Sophos has posted a new blog entry a couple of days ago about a spam campaign which is about the war in Iran.

The author, SavioL, listed 25 subject lines about the campaign such as “The military operation in Iran has begun” and “US army is about 20 kilometers from Tegeran”.

The emails contain a link to a web page and the blog entry included a screen shot of the web page. The web page contains two .exe files. One is named form.exe and the other is iran_occupation.exe. They are detected as Troj/Tibs-UO.

SavioL also notes that there are some spelling errors on the emails.

Source: Sophos