Ruleset Update Summary - 2023/11/21 - v10470

Summary:

7 new OPEN, 9 new PRO (7 + 2)

Thanks Kevin, Ross


Added rules:

Open:

  • 2049274 - ET MALWARE WikiLoader Activity M3 (GET) (malware.rules)
  • 2049275 - ET MALWARE WikiLoader Activity M4 (Response) (malware.rules)
  • 2049276 - ET MALWARE TA404 Comebacker Related Activity (POST) (malware.rules)
  • 2049277 - ET WEB_SPECIFIC_APPS Tinycontrol LAN Controller v3 Authentication Bypass Attempt (web_specific_apps.rules)
  • 2049278 - ET WEB_SPECIFIC_APPS Tinycontrol LAN Controller v3 Request for lk3_settings.bin Backup File (web_specific_apps.rules)
  • 2049279 - ET WEB_SPECIFIC_APPS Tinycontrol LAN Controller v3 Denial of Service Attempt - EEPROM Reset (web_specific_apps.rules)
  • 2049280 - ET WEB_SPECIFIC_APPS Tinycontrol LAN Controller v3 Denial of Service Attempt - System Restart Request (web_specific_apps.rules)

Pro:

  • 2855840 - ETPRO MALWARE Win32/abc123 Stealer Payload Request (GET) (malware.rules)
  • 2855841 - ETPRO MALWARE Win32/abc123 Stealer Payload Inbound (malware.rules)