SMTP: HTML "data:" URL Scheme
This signature detects an e-mail containing a HTML document containing parameters using the "data:" URL scheme. This scheme is defined in RFC2397 and is a legitimate usage of HTML. However, attackers can use the scheme to first embed malware in a Web page, then bypass specific filters that normally detect such a delivery.
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3