|
Addressing an FP: 2016950 - ET MALWARE Possible Win32/Hupigon ip.txt with a Non-Mozilla UA
|
|
0
|
240
|
October 2, 2023
|
|
Eternity Clipper
|
|
4
|
410
|
September 27, 2023
|
|
NStealer v2
|
|
3
|
494
|
September 25, 2023
|
|
Lumma Stealer Updates
|
|
2
|
556
|
September 15, 2023
|
|
Echida Botnet
|
|
3
|
394
|
September 11, 2023
|
|
JSCAPE MFT Binary Management Java Deserialization - CVE-2023-4528
|
|
0
|
324
|
September 8, 2023
|
|
SIG: ET MOBILE_MALWARE Android/InfamousChisel.InfoStealer APT28/SANDWORM Data Exfiltration
|
|
2
|
351
|
September 1, 2023
|
|
TheBoxClipper
|
|
2
|
461
|
August 30, 2023
|
|
RootTeam Stealer and overlap issues on Bandit Stealer rule detection
|
|
7
|
717
|
August 29, 2023
|
|
Mekotio
|
|
2
|
371
|
August 24, 2023
|
|
Parallax Rat
|
|
3
|
328
|
August 14, 2023
|
|
SIG: CloudFlare Tunnel DNS Query For argotunnel.com
|
|
2
|
242
|
August 14, 2023
|
|
DarkCloud
|
|
2
|
438
|
August 9, 2023
|
|
Phemedrone Stealer
|
|
1
|
272
|
August 7, 2023
|
|
Possible FP - JA3 Hash - [Abuse.ch] Possible Adware
|
|
1
|
367
|
August 1, 2023
|
|
PennyWise Stealer - Update on rules
|
|
2
|
432
|
July 28, 2023
|
|
Hydrochasma (Fast Reverse Proxy)
|
|
7
|
610
|
July 27, 2023
|
|
SIGNATURE: MalDoc/Gamaredon CnC: (ADMIN- prepend)
|
|
2
|
327
|
July 27, 2023
|
|
Lazarus APT Backdoor
|
|
5
|
715
|
July 27, 2023
|
|
Rockwell cve 2023-3595 and 2023-3596 signatures
|
|
0
|
676
|
July 20, 2023
|
|
Konni.APT
|
|
1
|
455
|
July 14, 2023
|
|
Possible FP: ET MALWARE Sourtoff Receiving Simda Payload
|
|
4
|
353
|
July 7, 2023
|
|
Mystic Stealer signature
|
|
6
|
691
|
June 28, 2023
|
|
StatusRecorder
|
|
1
|
383
|
June 27, 2023
|
|
ObserverStealer
|
|
5
|
594
|
June 23, 2023
|
|
GoodMorning Ransomware
|
|
7
|
482
|
June 23, 2023
|
|
FPs on new sig 2854494
|
|
2
|
348
|
June 20, 2023
|
|
SIG: MoveIt File Transfer WebShell Interaction
|
|
3
|
752
|
June 13, 2023
|
|
DynamicRAT
|
|
2
|
557
|
June 10, 2023
|
|
Gurcu stealer report outbound
|
|
7
|
434
|
May 30, 2023
|