Summary:
15 new OPEN, 20 new PRO (15 + 5)
Thanks @naumovax
Added rules:
Open:
- 2054500 - ET MALWARE Patchwork APT Victim Registration (malware.rules)
- 2054501 - ET MALWARE Patchwork APT CnC Activity (starget) (malware.rules)
- 2054502 - ET MALWARE Patchwork APT Host Details Exfil (malware.rules)
- 2054503 - ET MALWARE Patchwork APT CnC Activity (uuiddsd) (malware.rules)
- 2054504 - ET MALWARE Patchwork APT CnC Activity (umnome) (malware.rules)
- 2054505 - ET MALWARE Patchwork APT Malformed HTTP Request (malware.rules)
- 2054506 - ET MALWARE Patchwork APT Malformed HTTP Request CnC Response (malware.rules)
- 2054507 - ET MALWARE Patchwork CnC Domain in DNS Lookup (xinhuanet .nihaoucloud .org) (malware.rules)
- 2054508 - ET MALWARE Patchwork CnC Domain in DNS Lookup (centling .nihaoucloud .org) (malware.rules)
- 2054509 - ET MALWARE Patchwork CnC Domain in DNS Lookup (weibo .nihaoucloud .org) (malware.rules)
- 2054510 - ET MALWARE Patchwork CnC Domain in DNS Lookup (hengtian .nihaoucloud .org) (malware.rules)
- 2054511 - ET MALWARE Observed Patchwork Domain (xinhuanet .nihaoucloud .org in TLS SNI) (malware.rules)
- 2054512 - ET MALWARE Observed Patchwork Domain (centling .nihaoucloud .org in TLS SNI) (malware.rules)
- 2054513 - ET MALWARE Observed Patchwork Domain (weibo .nihaoucloud .org in TLS SNI) (malware.rules)
- 2054514 - ET MALWARE Observed Patchwork Domain (hengtian .nihaoucloud .org in TLS SNI) (malware.rules)
Pro:
- 2857626 - ETPRO MALWARE TA582 Domain in DNS Lookup (malware.rules)
- 2857627 - ETPRO MALWARE TA582 Domain in DNS Lookup (malware.rules)
- 2857628 - ETPRO MALWARE TA582 Domain in DNS Lookup (malware.rules)
- 2857629 - ETPRO MALWARE TA582 Domain in DNS Lookup (malware.rules)
- 2857630 - ETPRO MALWARE TA582 Domain in DNS Lookup (malware.rules)