""ET SMTP EXE - ZIP file with .pif filename inside""

SID: 2018144

Revision: 1

Class Type: bad-unknown

Metadata: created_at 2014_02_15, updated_at 2014_02_15

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: any

Flow: established

Contents:

  • Value: "|0D 0A 0D 0A|UmFyI"

Within:

PCRE: "/^[A-Za-z0-9\/+\x0D\x0A]+?(LnBpZ|5waW|ucGlm)/R"

Special Options:

source