Ruleset Update Summary - 2024/05/02 - v10588

Summary:

9 new OPEN, 10 new PRO (9 + 1)

Thanks @BugProve


Added rules:

Open:

  • 2052359 - ET EXPLOIT Selenium Server Grid Chrome 3.141.59 Remote Code Execution - Successful (exploit.rules)
  • 2052360 - ET INFO Selenium Server Grid Chrome 3.141.59 - Vulnerable Version Detected (info.rules)
  • 2052361 - ET MALWARE Suspected TA401/AridViper APT Micropsia Variant Related Activity (POST) (malware.rules)
  • 2052362 - ET WEB_SPECIFIC_APPS Zyxel Command Injection Attempt (CVE-2024-4474) M1 (web_specific_apps.rules)
  • 2052363 - ET WEB_SPECIFIC_APPS Zyxel Command Injection Attempt (CVE-2024-4474) M2 (web_specific_apps.rules)
  • 2052364 - ET WEB_SPECIFIC_APPS Zyxel Command Injection Attempt (CVE-2024-4474) M3 (web_specific_apps.rules)
  • 2052365 - ET WEB_SPECIFIC_APPS Zyxel Command Injection Attempt (CVE-2024-4474) M4 (web_specific_apps.rules)
  • 2052366 - ET WEB_SPECIFIC_APPS Zyxel Command Injection Attempt (CVE-2024-4474) M5 (web_specific_apps.rules)
  • 2052367 - ET WEB_SPECIFIC_APPS Zyxel Command Injection Attempt (CVE-2024-4474) M6 (web_specific_apps.rules)

Pro:

  • 2856827 - ETPRO MALWARE Win32/Golang Unknown Stealer Activity (GET) (malware.rules)

Disabled and modified rules:

  • 2002080 - ET ADWARE_PUP MySearch Products Spyware User-Agent (MySearch) (adware_pup.rules)
  • 2008782 - ET POLICY Possible Trojan File Download bad rar file header (not a valid rar file) (policy.rules)
  • 2810991 - ETPRO MALWARE SEDNIT CnC Beacon 1 (malware.rules)
  • 2813055 - ETPRO MOBILE_MALWARE RiskTool.AndroidOS.SMSreg.dw Checkin 3 (mobile_malware.rules)