ET SCAN Zimbra Collaboration Global Address List Bulk Enumeration

7.0.35.0SID: 2071249Rev: 1Enabled8 views
History
Sourceet/open
Fileemerging-scan.rules
CreatedJuly 21, 2026
UpdatedJuly 21, 2026
Classificationattempted-recon
alert http any any -> [$HOME_NET,$SMTP_SERVERS] any (msg:"ET SCAN Zimbra Collaboration Global Address List Bulk Enumeration"; flow:established,to_server; http.uri; content:"/service/soap/BatchRequest"; fast_pattern; http.header_names; to_lowercase; content:"x-zimbra-csrf-token|0d 0a|"; http.request_body; content:"SearchGalRequest"; content:"urn:zimbraAccount"; distance:0; content:"name|3d 22|"; distance:0; pcre:"/^[a-z0-9]{2}/R"; content:"name|3d 22|"; distance:0; pcre:"/^[a-z0-9_-]{2,5}\x22/R"; content:"name|3d 22|"; distance:0; pcre:"/^[a-z0-9_-]{2,5}\x22/R"; content:"name|3d 22|"; distance:0; pcre:"/^[a-z0-9_-]{2,5}\x22/R"; http.method; content:"POST"; threshold:type threshold,seconds 10,count 20,track by_src; reference:url,www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits; classtype:attempted-recon; sid:2071249; rev:1; metadata:affected_product Zimbra, attack_target SMTP_Server, created_at 2026_07_21, deployment Perimeter, deployment Internal, confidence High, signature_severity Informational, updated_at 2026_07_21; target:dest_ip;)

Metadata

affected productZimbra
attack targetSMTP_Server
created at2026_07_21
deploymentInternal
confidenceHigh
signature severityInformational
updated at2026_07_21

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!