""ET TROJAN Win32/Phorpiex Template 7 Active - Outbound Malicious Email Spam""

SID: 2044125

Revision: 3

Class Type: trojan-activity

Metadata: attack_target Client_Endpoint, created_at 2023_02_04, deployment Perimeter, malware_family Phorpiex, performance_impact Low, signature_severity Major, updated_at 2023_04_07

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: [25,26,465,587]

Flow: established,to_server

Contents:

  • Value: "Subject|3a 20|READ|20|OR|20|GO|20|TO|20|JAIL!"

  • Value: "I|20|sent|20|it|20|from|20|your|20|email"

  • Value: "removed|20|my|20|trojan"

  • Value: "YOUR|20|ILLEGAL|20|ACTIVITIES!"

Within:

PCRE:

Special Options:

source