SMTP: Suspicious Mail Sender with Randomized Address

This signature detects SMTP messages that contains suspicious "from" header randomized. This kind of behavior is mostly observed when someone is trying to scan and send malicious traffic against a network security device using various traffic generators.

Short Name
SMTP:EXPLOIT:SUSPICIOUS-FROM
Severity
Major
Recommended
False
Recommended Action
None
Category
SMTP
Keywords
Address Mail Randomized Sender Suspicious with
Release Date
04/01/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?