Ruleset Update Summary - 2026/07/24 - v11241

Summary:

16 new OPEN, 33 new PRO (16 + 17)


Added rules:

Open:

  • 2071277 - ET PHISHING HiStats Lookalike Domain in DNS Lookup (histats .top) (phishing.rules)
  • 2071278 - ET PHISHING HiStats Lookalike Domain in TLS SNI (histats .top) (phishing.rules)
  • 2071279 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (bouoher .lol) (exploit_kit.rules)
  • 2071280 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (marshalh .icu) (exploit_kit.rules)
  • 2071281 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (bouoher .lol) (exploit_kit.rules)
  • 2071282 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (marshalh .icu) (exploit_kit.rules)
  • 2071283 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (js-sec .seketafrica .org) (malware.rules)
  • 2071284 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (js-sec .seketafrica .org) (malware.rules)
  • 2071285 - ET INFO Adobe Coldfusion POST Request for RDS Services (info.rules)
  • 2071286 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (limbcre .cyou) (malware.rules)
  • 2071287 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (limbcre .cyou) in TLS SNI (malware.rules)
  • 2071288 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (wastwfulldashiwnjs .shop) (malware.rules)
  • 2071289 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (wastwfulldashiwnjs .shop) in TLS SNI (malware.rules)
  • 2071290 - ET HUNTING Generic Phish Landing Page 2026-07-24 (hunting.rules)
  • 2071291 - ET PHISHING CoGUI Landing Page 2026-07-24 (phishing.rules)
  • 2071292 - ET INFO Excessive Number of SMB Session Requests in a short time frame (info.rules)

Pro:

  • 2868051 - ETPRO WEB_SPECIFIC_APPS Adobe ColdFusion Server Side Request Forgery (CVE-2026-48332) (web_specific_apps.rules)
  • 2868052 - ETPRO WEB_SPECIFIC_APPS Adobe ColdFusion Cross Site Scripting Attempt (CVE-2026-48330) (web_specific_apps.rules)
  • 2868053 - ETPRO WEB_SPECIFIC_APPS Adobe Coldfusion Privilege Escalation Attempt M1 (CVE-2026-48328) (web_specific_apps.rules)
  • 2868054 - ETPRO WEB_SPECIFIC_APPS Adobe Coldfusion Privilege Escalation Attempt M2 (CVE-2026-48328) (web_specific_apps.rules)
  • 2868055 - ETPRO PHISHING CoGUI Config Fetch 2026-07-24 (phishing.rules)
  • 2868056 - ETPRO WEB_SPECIFIC_APPS Adobe Coldfusion Stored Cross Site Scripting Attempt (CVE-2026-48320) (web_specific_apps.rules)
  • 2868057 - ETPRO PHISHING CoGUI Response 2026-07-24 (phishing.rules)
  • 2868058 - ETPRO WEB_SPECIFIC_APPS Adobe ColdFusion SSRF/Arbitrary File Upload Attempt (CVE-2026-48318) (web_specific_apps.rules)
  • 2868059 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - PING Outbound (malware.rules)
  • 2868060 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PING Outbound (malware.rules)
  • 2868061 - ETPRO MALWARE TA584 Win32/XWorm CnC Command - Ping Inbound (malware.rules)
  • 2868062 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - RD- Inbound (malware.rules)
  • 2868063 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - sendPlugin Outbound (malware.rules)
  • 2868064 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - Informations Outbound (malware.rules)
  • 2868065 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - GetInformations Inbound (malware.rules)
  • 2868066 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PCShutdown Inbound (malware.rules)
  • 2868067 - ETPRO WEB_SPECIFIC_APPS Adobe Coldfusion Authentication Bypass Attempt (CVE-2026-48284) (web_specific_apps.rules)