# Ruleset Update Summary - 2025/03/11 - v10876

**URL:** <https://community.emergingthreats.net/t/ruleset-update-summary-2025-03-11-v10876/2509>\
**Category:** Ruleset Updates\
**Created:** [March 11, 2025, 11:06pm UTC](https://community.emergingthreats.net/t/ruleset-update-summary-2025-03-11-v10876/2509 "2025-03-11T23:06:36Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rulesbot](https://avatars.discourse-cdn.com/v4/letter/r/13edae/32.png) [@rulesbot](https://community.emergingthreats.net/u/rulesbot)\
**Post date:** [March 11, 2025, 11:06pm UTC](https://community.emergingthreats.net/t/ruleset-update-summary-2025-03-11-v10876/2509/1 "2025-03-11T23:06:36Z")

</div>

## Summary:

21 new OPEN, 26 new PRO (21 + 5)

* * *

## Added rules:

### Open:

- 2060779 - ET WEB\_SPECIFIC\_APPS DocsGPT Remote Code Execution Attempt (CVE-2025-0868) (web\_specific\_apps.rules)
- 2060780 - ET WEB\_SPECIFIC\_APPS Cockpit Authenticated Arbitrary PHP File Upload (web\_specific\_apps.rules)
- 2060781 - ET MALWARE Observed DNS Query to ClickFix Domain (booking-sup-lang-eng .com) (malware.rules)
- 2060782 - ET MALWARE Observed ClickFix Domain (booking-sup-lang-eng .com in TLS SNI) (malware.rules)
- 2060783 - ET WEB\_SPECIFIC\_APPS KLog Server Directory Traversal Attempt (CVE-2025-1035) (web\_specific\_apps.rules)
- 2060784 - ET INFO DYNAMIC\_DNS Query to a \*.iamnotwhoiam .net domain (info.rules)
- 2060785 - ET INFO DYNAMIC\_DNS HTTP Request to a \*.iamnotwhoiam .net domain (info.rules)
- 2060786 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (gentlbecomfort .world/Lofg) (malware.rules)
- 2060787 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (gentlbecomfort .world/Lofg) in TLS SNI (malware.rules)
- 2060788 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (joingeryjunc .top) (malware.rules)
- 2060789 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (joingeryjunc .top) in TLS SNI (malware.rules)
- 2060790 - ET EXPLOIT\_KIT LandUpdate808 Domain in DNS Lookup (srpkoa .com) (exploit\_kit.rules)
- 2060791 - ET EXPLOIT\_KIT LandUpdate808 Domain in TLS SNI (srpkoa .com) (exploit\_kit.rules)
- 2060792 - ET EXPLOIT\_KIT ZPHP Domain in DNS Lookup (rasin .shop) (exploit\_kit.rules)
- 2060793 - ET EXPLOIT\_KIT ZPHP Domain in DNS Lookup (kfzversicherungskosten .top) (exploit\_kit.rules)
- 2060794 - ET EXPLOIT\_KIT ZPHP Domain in TLS SNI (rasin .shop) (exploit\_kit.rules)
- 2060795 - ET EXPLOIT\_KIT ZPHP Domain in TLS SNI (kfzversicherungskosten .top) (exploit\_kit.rules)
- 2060796 - ET EXPLOIT\_KIT Malicious TA2726 TDS Domain in DNS Lookup (www .smartcn .cn) (exploit\_kit.rules)
- 2060797 - ET EXPLOIT\_KIT Malicious TA2726 TDS Domain in TLS SNI (www .smartcn .cn) (exploit\_kit.rules)
- 2060798 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (catalog .sjsailboats .com) (malware.rules)
- 2060799 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (catalog .sjsailboats .com) (malware.rules)

### Pro:

- 2860669 - ETPRO ATTACK\_RESPONSE Observed ClickFix Powershell Delivery Page Inbound (Large Image Evasion) (attack\_response.rules)
- 2860670 - ETPRO MALWARE Win32/zgRAT CnC Checkin (malware.rules)
- 2860671 - ETPRO MALWARE Win32/GetStream Stealer Victim Profile Exfil (malware.rules)
- 2860672 - ETPRO MALWARE Win32/GetStream Stealer CnC Response (malware.rules)
- 2860673 - ETPRO EXPLOIT Microsoft MapUrlToZone Security Feature Bypass (CVE-2025-21247) (exploit.rules)
