Ruleset Update Summary - 2024/06/04 - v10609

Summary:

6 new OPEN, 12 new PRO (6 + 6)


Added rules:

Open:

  • 2053230 - ET EXPLOIT_KIT ZPHP Domain in DNS Lookup (mamajekisrecording .com) (exploit_kit.rules)
  • 2053231 - ET EXPLOIT_KIT ZPHP Domain in TLS SNI (mamajekisrecording .com) (exploit_kit.rules)
  • 2053232 - ET EXPLOIT_KIT TA569 Keitaro TDS Domain in DNS Lookup (progressivewebappsdev .com) (exploit_kit.rules)
  • 2053233 - ET EXPLOIT_KIT TA569 Keitaro TDS Domain in TLS SNI (progressivewebappsdev .com) (exploit_kit.rules)
  • 2053234 - ET INFO DYNAMIC_DNS Query to a *.capnorthshore .org Domain (info.rules)
  • 2053235 - ET INFO DYNAMIC_DNS HTTP Request to a *.capnorthshore .org Domain (info.rules)

Pro:

  • 2857130 - ETPRO MALWARE TA582 Domain in DNS Lookup (malware.rules)
  • 2857131 - ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound (malware.rules)
  • 2857132 - ETPRO MALWARE Win32/XWorm V3 CnC Command - Informations Outbound (malware.rules)
  • 2857133 - ETPRO MALWARE Win32/XWorm V3 CnC Command - GetInformations Inbound (malware.rules)
  • 2857134 - ETPRO MALWARE Win32/XWorm V3 CnC Command - GetInformations Outbound (malware.rules)
  • 2857135 - ETPRO MALWARE Win32/XWorm V3 CnC Command - PCShutdown Inbound (malware.rules)