Summary:
9 new OPEN, 19 new PRO (9 + 10)
Added rules:
Open:
- 2071329 - ET WEB_SPECIFIC_APPS Veracore timeoutWarning PmSess1 Parameter SQL Injection Attempt (CVE-2025-25181) (web_specific_apps.rules)
- 2071336 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (phiplips .click) (exploit_kit.rules)
- 2071337 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (phiplips .click) (exploit_kit.rules)
- 2071338 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (app-api .starfoodmart .net) (malware.rules)
- 2071339 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (app-api .starfoodmart .net) (malware.rules)
- 2071340 - ET WEB_SPECIFIC_APPS Citrix Content Collaboration ShareFile Remote Code Execution (CVE-2023-24489) (web_specific_apps.rules)
- 2071341 - ET WEB_SPECIFIC_APPS Paessler PRTG Unauthenticated Local File Inclusion/Authentication Bypass Attempt (CVE-2018-19410) (web_specific_apps.rules)
- 2071342 - ET INFO Server Hello with Downgrade Request to TLS 1.2 (info.rules)
- 2071343 - ET INFO Server Hello with Downgrade Request to TLS 1.1 or Lower (info.rules)
Pro:
- 2868084 - ETPRO MOBILE_MALWARE Trojan-Spy.AndroidOS.Agent.ald Query (mobile_malware.rules)
- 2868085 - ETPRO MOBILE_MALWARE Trojan-Spy.AndroidOS.Agent.ald Query (mobile_malware.rules)
- 2868086 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - PING Outbound (malware.rules)
- 2868087 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PING Outbound (malware.rules)
- 2868088 - ETPRO MALWARE TA584 Win32/XWorm CnC Command - Ping Inbound (malware.rules)
- 2868089 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - RD- Inbound (malware.rules)
- 2868090 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - sendPlugin Outbound (malware.rules)
- 2868091 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - Informations Outbound (malware.rules)
- 2868092 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - GetInformations Inbound (malware.rules)
- 2868093 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PCShutdown Inbound (malware.rules)