Summary:
30 new OPEN, 36 new PRO (30 + 6)
Added rules:
Open:
- 2071948 - ET INFO DYNAMIC_DNS Query to a *.ortodont-katalinic .com domain (info.rules)
- 2071949 - ET INFO DYNAMIC_DNS HTTP Request to a *.ortodont-katalinic .com domain (info.rules)
- 2071950 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (inviteaccessiblesaltw .shop) (malware.rules)
- 2071951 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (inviteaccessiblesaltw .shop) in TLS SNI (malware.rules)
- 2071952 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (memorialsurvivalthiewv .store) (malware.rules)
- 2071953 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (memorialsurvivalthiewv .store) in TLS SNI (malware.rules)
- 2071954 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (syncarpiajanapiom .fun) (malware.rules)
- 2071955 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (syncarpiajanapiom .fun) in TLS SNI (malware.rules)
- 2071956 - ET EXPLOIT D-Link udhcpd option 125, Suboption 1-3 Buffer Overflow Attempt (CVE-2026-86296) (exploit.rules)
- 2071957 - ET WEB_SPECIFIC_APPS Adobe Commerce & Magento StyleSmuggler Unauthenticated Remote Code Execution (CVE-2026-75650) (web_specific_apps.rules)
- 2071958 - ET MALWARE X-Panel Payload Inbound (malware.rules)
- 2071959 - ET MALWARE X-Panel CnC Activity (malware.rules)
- 2071960 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (falsifydisappearsoaeka .pw) (malware.rules)
- 2071961 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (falsifydisappearsoaeka .pw) in TLS SNI (malware.rules)
- 2071962 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (fitnescivilianquesw .pw) (malware.rules)
- 2071963 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (fitnescivilianquesw .pw) in TLS SNI (malware.rules)
- 2071964 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (setfupstore .icu) (malware.rules)
- 2071965 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (setfupstore .icu) in TLS SNI (malware.rules)
- 2071966 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (caapman .me) (exploit_kit.rules)
- 2071967 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (arernathy .sbs) (exploit_kit.rules)
- 2071968 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (schamserger .top) (exploit_kit.rules)
- 2071969 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (caapman .me) (exploit_kit.rules)
- 2071970 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (arernathy .sbs) (exploit_kit.rules)
- 2071971 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (schamserger .top) (exploit_kit.rules)
- 2071972 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (mesh .officialx-token .com) (malware.rules)
- 2071973 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (js-mini .thaiglobalshipping .com) (malware.rules)
- 2071974 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (ship-js .veecargoexpresscouriers .com) (malware.rules)
- 2071975 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (mesh .officialx-token .com) (malware.rules)
- 2071976 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (js-mini .thaiglobalshipping .com) (malware.rules)
- 2071977 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (ship-js .veecargoexpresscouriers .com) (malware.rules)
Pro:
- 2868490 - ETPRO INFO PGP Encrypted Message Request Outbound (info.rules)
- 2868491 - ETPRO INFO PGP Encrypted Message Request Inbound (info.rules)
- 2868492 - ETPRO INFO PGP Encrypted Message Response Outbound (info.rules)
- 2868493 - ETPRO INFO PGP Encrypted Message Response Inbound (info.rules)
- 2868494 - ETPRO EXPLOIT ISC DHCP Server Unauthenticated Root Remote Code Execution (exploit.rules)
- 2868495 - ETPRO EXPLOIT Microsoft Windows Kerberos Remote Code Execution (CVE-2026-69676) (exploit.rules)