Skip to content

Create headers_suspicious_outdated_clients.yml #3084

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

brycampbell
Copy link
Member

This rule is designed to identify mail clients that are either suspicious, and have historic abuse from spam, malware or targeted intrusions or are simply out of date with modern anticipated usage, conversely, this will also be used to help vulnerability teams identify out of date clients internally by adding in type.outbound with up to date versions of enterprise email clients, which will then enable them to run this rule and identify older versions of mail clients by negating the original content and using the following type of search:

https://platform.sublime.security/messages/hunt?huntId=0198a96a-542e-79f9-8dda-e4a1f87b8574

Some examples include:
X-Mailer: Zimbra 5.0.16_GA_2921.RHEL4 (zclient/5.0.16_GA_2921.RHEL4) This comes from the following source:
https://www.discourse.net/2009/11/annals_of_phishing/

https://thebat.net/ is an email client that is fashioned as a 'security first' client.
The Bat! (v3–v4…)

Foxmail is developed by Tencent.
Foxmail 7.0.1.92[cn] Note: Foxmail often appends the [cn] tag and GB2312 charset shows up alongside it

Source

SupMailer is another popular Chinese Mail Client

Supmailer 42.0.1

Microsoft Express 6 is a now 15 year old mail client, still abused in spam.

Microsoft Outlook Express 6.00.2900.2180

Associated samples

Associated hunts

Screenshot (insights)

@brycampbell brycampbell requested a review from a team as a code owner August 14, 2025 16:30
@brycampbell brycampbell added the review-needed Indicates that a PR is waiting for review label Aug 14, 2025
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Aug 14, 2025
@brycampbell brycampbell removed the review-needed Indicates that a PR is waiting for review label Aug 14, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
in-test-rules PR is in our testing suite to collect telemetry
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant