Short Name |
POP3:EXT:DOT-386 |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
POP3 |
Keywords |
.386 e-mail attachment |
Release Date |
2004/08/04 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects e-mail attachments that have the extension .386 and were received through POP3. Because .386s ( Windows Enhanced Mode Driver) files contain executable code, this can indicate an incoming e-mail virus. Attackers can create malicious executables, tricking users into executing the file and infecting the system.
The impact on the target system is dependent on the instructions contained in the malicious .386 file.