Back to Rule

Rule History

SID: 2003041 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 7Jul 30, 2010, 12:00 PM

ET DELETED Win32.SMTP-Mailer SMTP Outbound

alert tcp $HOME_NET any -> $EXTERNAL_NET 25 (msg:"ET DELETED Win32.SMTP-Mailer SMTP Outbound"; flow:to_server,established; content:"Subject|3a 20 3a 20|ZOMBIE"; nocase; content:"X-Library|3a| Indy 9.00.10"; nocase; distance:0; reference:url,research.sunbelt-software.com/threatdisplay.aspx?name=Win32.SMTP-Mailer&threatid=48095; reference:url,www.hauri.net/virus/virusinfo_read.php?code=TRW3000774&start=1; classtype:trojan-activity; sid:2003041; rev:7; metadata:created_at 2010_07_30, signature_severity Unknown, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)

Jul 30, 2010, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

Oct 1, 2025, 9:34 PM

rules/emerging-deleted.rules