Ruleset Update Summary - 2024/09/11 - v10687

Summary:

6 new OPEN, 7 new PRO (6 + 1)


Added rules:

Open:

  • 2055818 - ET INFO DYNAMIC_DNS Query to a * .ltlegl .com Domain (info.rules)
  • 2055819 - ET INFO DYNAMIC_DNS HTTP Request to a * .ltlegl .com Domain (info.rules)
  • 2055820 - ET EXPLOIT_KIT CC Skimmer Domain in DNS Lookup (marketiqhub .com) (exploit_kit.rules)
  • 2055821 - ET EXPLOIT_KIT CC Skimmer Domain in TLS SNI (marketiqhub .com) (exploit_kit.rules)
  • 2055822 - ET EXPLOIT_KIT ZPHP Domain in DNS Lookup (simplymecosmetics .com) (exploit_kit.rules)
  • 2055823 - ET EXPLOIT_KIT ZPHP Domain in TLS SNI (simplymecosmetics .com) (exploit_kit.rules)

Pro:

  • 2858333 - ETPRO MALWARE Win32/zgRAT CnC Checkin (malware.rules)

Modified inactive rules:

  • 2038755 - ET MALWARE Observed DNS Query to Temporary File Hosting Domain (temp .sh) (malware.rules)