Ruleset Update Summary - 2026/09/28 - v11299

Summary:

26 new OPEN, 35 new PRO (26 + 9)

Thanks @skocherhan, @500mk500


Added rules:

Open:

  • 2072265 - ET INFO DYNAMIC_DNS Query to a *.bizuit .com domain (info.rules)
  • 2072266 - ET INFO DYNAMIC_DNS HTTP Request to a *.bizuit .com domain (info.rules)
  • 2072267 - ET INFO DYNAMIC_DNS Query to a *.ambientcoffee .com domain (info.rules)
  • 2072268 - ET INFO DYNAMIC_DNS HTTP Request to a *.ambientcoffee .com domain (info.rules)
  • 2072269 - ET INFO DYNAMIC_DNS Query to a *.robertschulze .net domain (info.rules)
  • 2072270 - ET INFO DYNAMIC_DNS HTTP Request to a *.robertschulze .net domain (info.rules)
  • 2072271 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (aliengp .cyou) (malware.rules)
  • 2072272 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (aliengp .cyou) in TLS SNI (malware.rules)
  • 2072273 - ET WEB_SPECIFIC_APPS Rails Active Storage BMP Direct Upload (CVE-2026-66066) (web_specific_apps.rules)
  • 2072274 - ET INFO DYNAMIC_DNS Query to a *.hosteriafutaleufu .cl domain (info.rules)
  • 2072275 - ET INFO DYNAMIC_DNS HTTP Request to a *.hosteriafutaleufu .cl domain (info.rules)
  • 2072276 - ET INFO DYNAMIC_DNS Query to a *.ploteando .com domain (info.rules)
  • 2072277 - ET INFO DYNAMIC_DNS HTTP Request to a *.ploteando .com domain (info.rules)
  • 2072278 - ET INFO DYNAMIC_DNS Query to a *.techmaxasia .com domain (info.rules)
  • 2072279 - ET INFO DYNAMIC_DNS HTTP Request to a *.techmaxasia .com domain (info.rules)
  • 2072280 - ET INFO DYNAMIC_DNS Query to a *.cafemeridiano .com .br domain (info.rules)
  • 2072281 - ET INFO DYNAMIC_DNS HTTP Request to a *.cafemeridiano .com .br domain (info.rules)
  • 2072282 - ET INFO DYNAMIC_DNS Query to a *.happypc .ca domain (info.rules)
  • 2072283 - ET INFO DYNAMIC_DNS HTTP Request to a *.happypc .ca domain (info.rules)
  • 2072284 - ET MALWARE Zbtlink Router ENDLESSDOORS Shell Outbound (rctlbash) (malware.rules)
  • 2072285 - ET WEB_SPECIFIC_APPS Mirasvit Cache Warmer PHP Object Injection (CVE-2026-45247) (web_specific_apps.rules)
  • 2072286 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (ow-api .behzad .eu .org) (malware.rules)
  • 2072287 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (us-west .oceandentalcare .com) (malware.rules)
  • 2072288 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (ow-api .behzad .eu .org) (malware.rules)
  • 2072289 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (us-west .oceandentalcare .com) (malware.rules)
  • 2072290 - ET HUNTING Request for Image with Specific Byte Range In HTTP Header (hunting.rules)

Pro:

  • 2868709 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - PING Outbound (malware.rules)
  • 2868710 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PING Outbound (malware.rules)
  • 2868711 - ETPRO MALWARE TA584 Win32/XWorm CnC Command - Ping Inbound (malware.rules)
  • 2868712 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - RD- Inbound (malware.rules)
  • 2868713 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - sendPlugin Outbound (malware.rules)
  • 2868714 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - Informations Outbound (malware.rules)
  • 2868715 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - GetInformations Inbound (malware.rules)
  • 2868716 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PCShutdown Inbound (malware.rules)
  • 2868717 - ETPRO MALWARE Malicious Win32/NetSupport Rat CnC Checkin (malware.rules)