Ruleset Update Summary - 2023/06/16 - v10351

Summary:

9 new OPEN, 9 new PRO (9 + 0)

Thanks @kaspersky, @InQuest, @Threatlabz


Added rules:

Open:

  • 2046291 - ET MALWARE GreetingGhoul Stealer CnC Exfil (POST) (malware.rules)
  • 2046292 - ET PHISHING GreetingGhoul Stealer Crypto Landing Page (phishing.rules)
  • 2046293 - ET MALWARE Mystic Stealer Admin Panel 2023-06-16 (malware.rules)
  • 2046294 - ET MALWARE Mystic Stealer C2 Client Hello Packet (malware.rules)
  • 2046295 - ET MALWARE Mystic Stealer C2 Session Key Response Packet (malware.rules)
  • 2046296 - ET MALWARE LegionLoader CnC Domain (legions .win) in DNS Lookup (malware.rules)
  • 2046297 - ET MALWARE Observed LegionLoader Domain in TLS SNI (legions .win) (malware.rules)
  • 2046298 - ET MALWARE Legion Loader Activity Observed (LegionClient) (malware.rules)
  • 2046299 - ET MALWARE Zenlod System Information Retrieval (malware.rules)