MALWARE-TOOLS --
MALWARE-TOOLS Zimbra Collaboration Suite data stealer outbound connection attempt
This rule looks for malicious outbound connection attempts from the local network to an external network which may contain stolen sensitive information from Zimbra webmail users.
This rule will alert when a malicious outbound connection has been detected in the network. This may be related to some data stealer software affecting a vulnerable Zimbra webmail server
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Command and Control::Application Layer Protocol
Vulnerability::Severity::Medium
Vulnerability::Severity::Critical
Vulnerability::Severity::High
N/A
Not Applicable
CVE-2025-27915 |
Loading description
|