Ruleset Update Summary - 2024/01/09 - v10502

Summary:

8 new OPEN, 10 new PRO (8 + 2)

Added rules:

Open:

  • 2049947 - ET MALWARE Suspected FalseFont Backdoor Activity M1 - (malware.rules)
  • 2049948 - ET MALWARE Suspected FalseFont Backdoor Activity M2 - (malware.rules)
  • 2049949 - ET MALWARE Lumma Stealer Related Domain in DNS Lookup (evokenumberpottruckere .fun) - (malware.rules)
  • 2049950 - ET MALWARE Observed Lumma Stealer Related Domain (evokenumberpottruckere .fun in TLS SNI) - (malware.rules)
  • 2049951 - ET MALWARE Lumma Stealer Related CnC Domain in DNS Lookup (goddirtybrilliancece .fun) - (malware.rules)
  • 2049952 - ET MALWARE Observed Lumma Stealer Related Domain (goddirtybrilliancece .fun in TLS SNI) - (malware.rules)
  • 2049953 - ET MALWARE Lumma Stealer Related CnC Domain in DNS Lookup (maskmusicalproplemanw .pw) - (malware.rules)
  • 2049954 - ET MALWARE Observed Lumma Stealer Related Domain (maskmusicalproplemanw .pw in TLS SNI) - (malware.rules)

Pro:

  • 2856121 - ETPRO MALWARE Win32/Unknown Bot CnC Activity (M3) - (malware.rules)
  • 2856122 - ETPRO MALWARE Win32/Unknown Bot CnC Response - (malware.rules)