TMS zl Module IPS/IDS Signature Reference Guide RLX.10.2.2.94

ProCurve TMS zl Module IPS/IDS Signature
Reference Guide Version RLX.10.2.2.94
280
Signature ID: 2057
VIRUS OUTBOUND .diz file attachment
Threat Level: Information
Signature Description: This event indicates that an outgoing email message possibly containing a virus has been
detected. This rule generates an event when a filename extension commonly used by viruses is detected. This signature
generate log for .diz file attachment.
Signature ID: 2058
VIRUS OUTBOUND .bat file attachment
Threat Level: Information
Signature Description: This event indicates that an outgoing email message possibly containing a virus has been
detected. This rule generates an event when a filename extension commonly used by viruses is detected. This signature
generate log for .bat file attachment.
Signature ID: 2059
VIRUS OUTBOUND .ini file attachment
Threat Level: Information
Signature Description: Virus is a computer program that can copy itself and infect a computer without permission or
knowledge of the user. The team 'virus' is also commonly used, to refer to many different types of malware and adware
programs. This rule will trigger when attach '.ini' file then blocks the attachment. When a prohibited attachment has
been blocked, it will not deliver the attachment to the recipient but the message will still be delivered. The sender will
not receive any notification that the attachment has been removed.
Signature ID: 2060
VIRUS OUTBOUND .reg file attachment
Threat Level: Information
Signature Description: Virus is a computer program that can copy itself and infect a computer without permission or
knowledge of the user. The team 'virus' is also commonly used, to refer to many different types of malware and adware
programs. This rule will trigger when attach '.reg' file then blocks the attachment. When a prohibited attachment has
been blocked, it will not deliver the attachment to the recipient but the message will still be delivered. The sender will
not receive any notification that the attachment has been removed.
Signature ID: 2061
VIRUS OUTBOUND .chm file attachment
Threat Level: Information
Signature Description: This event indicates that an outgoing email message possibly containing a virus has been
detected. This rule generates an event when a filename extension commonly used by viruses is detected.
Signature ID: 2062
VIRUS OUTBOUND .hta file attachment
Threat Level: Information
Signature Description: Virus is a computer program that can copy itself and infect a computer without permission or
knowledge of the user. The team 'virus' is also commonly used, to refer to many different types of malware and adware
programs. This rule will trigger when attach '.hta' file then blocks the attachment. When a prohibited attachment has
been blocked, it will not deliver the attachment to the recipient but the message will still be delivered. The sender will
not receive any notification that the attachment has been removed.