
And bingo !
“CHM is a compiled HTML file that contains an embedded HTML file with JavaScript code to start the active infection process. "
Javascript, again.
Block it, and the install process fails.
NoScript FTW !
Cisco Talos has uncovered a credential-stealing trojan that lifts your login details from the Chrome browser, Microsoft's Outlook and instant messengers. Delivered through phishing emails, the Masslogger trojan’s latest variant is contained within a multi-volume RAR archive using the .chm file format and .r00 extensions, said …
I see malware deliveries every day, all of them are quarantined by the mail server if they contain any of the files listed. But the majority of malware attempts these days seems to be delivered via Excel files containing macros. They are quarantined and I delete them after checking the spam score and source.