[Snort-sigs] Bleedingsnort.com Daily Update

bleeding at ...2727... bleeding at ...2727...
Fri Jul 21 21:00:13 EDT 2006


[***] Results from Oinkmaster started Fri Jul 21 21:00:12 2006 [***]

[+++]          Added rules:          [+++]

 2003040 - BLEEDING-EDGE PCMesh Anonymous Proxy Traffic (bleeding-policy.rules)
 2003041 - BLEEDING-EDGE VIRUS Win32.SMTP-Mailer SMTP Outbound (bleeding-virus.rules)
 2003043 - BLEEDING-EDGE VIRUS Suspicious SMTP HELO Outbound (bleeding-virus.rules)
 2003044 - BLEEDING-EDGE VIRUS Suspicious SMTP EHLO Outbound (bleeding-virus.rules)


[///]     Modified active rules:     [///]

 2001972 - BLEEDING-EDGE Behavioral Unusually fast Terminal Server Traffic, Potential Scan or Infection (bleeding-scan.rules)
 2400000 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
 2400001 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
 2400002 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
 2400003 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
 2400004 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
 2401000 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
 2401001 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
 2401002 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
 2401003 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
 2401004 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to bleeding-sid-msg.map (4):
        2003040 || BLEEDING-EDGE PCMesh Anonymous Proxy Traffic
        2003041 || BLEEDING-EDGE VIRUS Win32.SMTP-Mailer SMTP Outbound || url,www.hauri.net/virus/virusinfo_read.php?code=TRW3000774&start=1
        2003043 || BLEEDING-EDGE VIRUS Suspicious SMTP HELO Outbound
        2003044 || BLEEDING-EDGE VIRUS Suspicious SMTP EHLO Outbound

     -> Added to bleeding-virus.rules (1):
        #by Russ McRee





More information about the Snort-sigs mailing list