Create headers_suspicious_outdated_clients.yml #3084
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This rule is designed to identify mail clients that are either suspicious, and have historic abuse from spam, malware or targeted intrusions or are simply out of date with modern anticipated usage, conversely, this will also be used to help vulnerability teams identify out of date clients internally by adding in
type.outbound
with up to date versions of enterprise email clients, which will then enable them to run this rule and identify older versions of mail clients by negating the original content and using the following type of search:https://platform.sublime.security/messages/hunt?huntId=0198a96a-542e-79f9-8dda-e4a1f87b8574
Some examples include:
X-Mailer: Zimbra 5.0.16_GA_2921.RHEL4 (zclient/5.0.16_GA_2921.RHEL4)
This comes from the following source:https://www.discourse.net/2009/11/annals_of_phishing/
https://thebat.net/ is an email client that is fashioned as a 'security first' client.
The Bat! (v3–v4…)
Foxmail is developed by Tencent.
Foxmail 7.0.1.92[cn]
Note: Foxmail often appends the [cn] tag and GB2312 charset shows up alongside itSource
SupMailer is another popular Chinese Mail Client
Supmailer 42.0.1
Microsoft Express 6 is a now 15 year old mail client, still abused in spam.
Microsoft Outlook Express 6.00.2900.2180
Associated samples
Associated hunts
Screenshot (insights)