""ET TROJAN SpamBanker message""

SID: 2019937

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2014_12_15, updated_at 2014_12_15

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: [25,587]

Flow: to_server,established

Contents:

  • Value: "NEGOCIO_ONLINE|2e|"

  • Value: "|0d 0a|Content-Disposition|3a| attachment"

  • Value: "filename|3d|"

Within:

PCRE: "/^[\x22\x27]NEGOCIO_ONLINE(.(?:zip|exe))[\x27\x22]\x0d\x0a/Ri"

Special Options:

  • nocase

  • nocase

source