Short Name |
POP3:EXT:DOT-WSH |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
POP3 |
Keywords |
.wsh e-mail attachment |
Release Date |
2004/07/28 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects e-mail attachments with the extension .wsh received through POP3. This can indicate an incoming e-mail virus. .WSHs (Windows Script Host Settings File) contain configuration parameters. Attackers can create malicious configurations, tricking the user into executing the file and infecting the system.
A tampered .wsh file can set undesired system values. Malware writers can exploit this vulnerability.