HTTP: Data is Not JPEG
This anomaly is triggered if a mismatch is detected between the content type "image/jpeg" and the actual data. The JPEG data should start from the pattern "ff d8 ff." Recent malware Command and Control ("C&C") channels use encrypted data with "jpeg" file extensions, but they are not well-formed JPEG files and will be detected by this anomaly.
References
CVE: CVE-2019-5129
URL: http://www.obrador.com/essentialjpeg/headerinfo.htm http://labs.alienvault.com/labs/index.php/2013/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists/ http://www.arbornetworks.com/asert/wp-content/uploads/2014/06/ASERT-Threat-Intelligence-Brief-2014-07-Illuminating-Etumbot-APT.pdf
mx-19.3
vmx-19.3
vsrx-19.2
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vmx-19.4
mx-19.4
srxevo-25.4
vsrx-26.2
srx-26.2
srx-branch-26.2
vsrx3bsd-26.2
mx-12.3
srx-12.3
srx-branch-12.3
vsrx-12.3