alert smtp $HOME_NET any -> $EXTERNAL_NET any (
msg:"ET MALWARE Win32/Tofsee Malformed Spam Template String";
flow:to_server,established;
content:"receive|20|further|20|updates.Please"; fast_pattern;
byte_test:1,!=,0x20,0,string,hex,relative;
threshold:type threshold, count 5, seconds 120, track by_src;
classtype:command-and-control;
sid:2029774; rev:2;
metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, created_at 2020_03_31, malware_family Tofsee, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_03_31;
)