VIRUS: Double File Extension

This anomaly triggers when it detects an e-mail attachments that contains two file extensions. Attackers or viruses can send e-mail attachments that use two file extensions to disguise the actual file name and trick users into opening a malicious attachment.

Extended Description

Files with double extensions could contain virus or worm code, and are easier to fool users into opening than files with one normal executable extension.

Short Name
VIRUS:SMTP:DOUBLE-EXTENSION
Severity
Major
Recommended
True
Recommended Action
Drop
Category
VIRUS
Release Date
06/20/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?