""ET TROJAN W32/SpyBanker Infection Confirmation Email 2""

SID: 2014762

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2012_05_17, updated_at 2012_05_17

Reference:

  • md5

  • f091e8ed0e8f4953ff10ce3bd06dbe54

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: 25

Flow: established,to_server

Contents:

  • Value: "From|3A 20 22|Infected|22|"

Within:

PCRE:

Special Options:

source