In Symantec Messaging Gateway (SMG), administrators may occasionally observe the static-virus-attack-backup verdict in the message audit logs. This article explains the technical behavior behind this verdict and why it occurs on established SMTP connections.
The static-virus-attack-backup verdict is a hidden policy that occurs during the following sequence of events:
static-virus-attack-backup verdict. This acts as a secondary protective measure, identifying these messages as originating from an IP already flagged by the Virus Attack feature, despite the connection itself continuing to be processed.This verdict is distinct from the static-virus-attack verdict, which is applied when a new connection is attempted from an IP that is already known to be in the penalty box.
This behavior is Working as Designed.
The static-virus-attack-backup verdict indicates that the SMG is successfully identifying and tagging traffic from a known malicious source that was already connected before the penalty was applied. No configuration changes are required to "fix" this verdict, as it is fulfilling its purpose as a security safety net.
The action taken for messages which receive this verdict cannot be modified: