Ruleset Update Summary - 2026/08/05 - v11250

Summary:

17 new OPEN, 40 new PRO (17 + 23)


Added rules:

Open:

  • 2071385 - ET MALWARE Shai-Hulud (Here We Go Again) NPM Malware Github Repository Creation (malware.rules)
  • 2071386 - ET MALWARE Shai-Hulud (Here We Go Again) NPM Malware RPC Ethereum Call (malware.rules)
  • 2071387 - ET EXPLOIT_KIT ZPHP Domain in DNS Lookup (laurelcloister .top) (exploit_kit.rules)
  • 2071388 - ET EXPLOIT_KIT ZPHP Domain in TLS SNI (laurelcloister .top) (exploit_kit.rules)
  • 2071389 - ET MALWARE Shai-Hulud (Here We Go Again) NPM Malware Github Commit Marker Search (malware.rules)
  • 2071390 - ET WEB_SPECIFIC_APPS Edimax formiNICbasic rootAPmac Parameter Command Injection Attempt (CVE-2026-9441) (web_specific_apps.rules)
  • 2071391 - ET WEB_SPECIFIC_APPS Edimax formAccept submit-url Parameter Command Injection Attempt (CVE-2026-9440) (web_specific_apps.rules)
  • 2071392 - ET WEB_SPECIFIC_APPS TP-Link Wan6to4TunnelCfgRpm.htm dnsserver1 Parameter Buffer Overflow Attempt (CVE-2026-9105) (web_specific_apps.rules)
  • 2071393 - ET WEB_SPECIFIC_APPS TP-Link WlanSecurityRpm.htm radiusSecret Parameter Buffer Overflow Attempt (web_specific_apps.rules)
  • 2071394 - ET WEB_SPECIFIC_APPS TP-Link WanStaticIpV6CfgRpm.htm ip Parameter Buffer Overflow Attempt (web_specific_apps.rules)
  • 2071395 - ET WEB_SPECIFIC_APPS TP-Link WanDynamicIpV6CfgRpm.htm gw Parameter Buffer Overflow Attempt (web_specific_apps.rules)
  • 2071396 - ET WEB_SPECIFIC_APPS TP-Link PPPoEv6CfgRpm.htm username Parameter Buffer Overflow Attempt (web_specific_apps.rules)
  • 2071397 - ET EXPLOIT_KIT Observed ClickFix Loader Inbound (exploit_kit.rules)
  • 2071398 - ET EXPLOIT_KIT ZPHP Domain in DNS Lookup (belfryledger .top) (exploit_kit.rules)
  • 2071399 - ET EXPLOIT_KIT ZPHP Domain in DNS Lookup (hornbeamcairn .top) (exploit_kit.rules)
  • 2071400 - ET EXPLOIT_KIT ZPHP Domain in TLS SNI (belfryledger .top) (exploit_kit.rules)
  • 2071401 - ET EXPLOIT_KIT ZPHP Domain in TLS SNI (hornbeamcairn .top) (exploit_kit.rules)

Pro:

  • 2868134 - ETPRO MALWARE UNK_SteadySplit V1 CnC Key Exchange Request (malware.rules)
  • 2868135 - ETPRO MALWARE UNK_SteadySplit V1 CnC Key Exchange Response (malware.rules)
  • 2868136 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - PING Outbound (malware.rules)
  • 2868137 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PING Outbound (malware.rules)
  • 2868138 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PING Outbound (malware.rules)
  • 2868139 - ETPRO MALWARE TA584 Win32/XWorm CnC Command - Ping Inbound (malware.rules)
  • 2868140 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - RD+ Outbound (malware.rules)
  • 2868141 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - RD- Inbound (malware.rules)
  • 2868142 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - sendfileto Inbound (malware.rules)
  • 2868143 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - sendPlugin Outbound (malware.rules)
  • 2868144 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - savePlugin Inbound (malware.rules)
  • 2868145 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - Informations Outbound (malware.rules)
  • 2868146 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - GetInformations Inbound (malware.rules)
  • 2868147 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - GetInformations Outbound (malware.rules)
  • 2868148 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PCShutdown Inbound (malware.rules)
  • 2868149 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - PING Outbound (malware.rules)
  • 2868150 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PING Outbound (malware.rules)
  • 2868151 - ETPRO MALWARE TA584 Win32/XWorm CnC Command - Ping Inbound (malware.rules)
  • 2868152 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - RD- Inbound (malware.rules)
  • 2868153 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - sendPlugin Outbound (malware.rules)
  • 2868154 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - Informations Outbound (malware.rules)
  • 2868155 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - GetInformations Inbound (malware.rules)
  • 2868156 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PCShutdown Inbound (malware.rules)