VIRUS: Possible ASProx Botnet Email Content

This signature detects potential ASProx (aka Kuluoz/DoFoil/Zortob) infection attempts being sent via SMTP. Because SMTP can be forwarded by legitimate remote mail servers, blocking on this signature can cause problems with your normal mail delivery, and we cannot "Recommend" a drop action. Use this signature with extreme caution and only on mail traffic you suspect to be invalid.

Short Name
VIRUS:SMTP:ASPROX
Severity
Major
Recommended
False
Recommended Action
None
Category
VIRUS
Keywords
ASProx Botnet Content Email Possible
Release Date
08/25/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?