[Snort-sigs] Emerging Threats Daily Signature Changes

emerging at ...3335... emerging at ...3335...
Tue Apr 1 17:00:09 EDT 2008


[***] Results from Oinkmaster started Tue Apr  1 17:00:09 2008 [***]

[+++]          Added rules:          [+++]

 2008077 - ET CURRENT_EVENTS Possible Storm Worm April Fools Day EXE Request (foolsday.exe) (bleeding.rules)
 2008078 - ET CURRENT_EVENTS Possible Storm Worm April Fools Day EXE Request (funny.exe) (bleeding.rules)
 2008079 - ET CURRENT_EVENTS Possible Storm Worm April Fools Day EXE Request (kickme.exe) (bleeding.rules)


[///]     Modified active rules:     [///]

 2008073 - ET MALWARE Suspicious User-Agent (App4) (bleeding-malware.rules)


[---]         Disabled rules:        [---]

 2008064 - ET POLICY Nginx Server with no version string - Often Hostile Traffic (bleeding-policy.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to bleeding-sid-msg.map (5):
        2008077 || ET CURRENT_EVENTS Possible Storm Worm April Fools Day EXE Request (foolsday.exe)
        2008078 || ET CURRENT_EVENTS Possible Storm Worm April Fools Day EXE Request (funny.exe)
        2008079 || ET CURRENT_EVENTS Possible Storm Worm April Fools Day EXE Request (kickme.exe)
        2404020 || ET DROP Known Bot C&C Server Traffic (group 21)  || url,www.shadowserver.org
        2405020 || ET DROP Known Bot C&C Traffic (group 21) - BLOCKING SOURCE || url,www.shadowserver.org

     -> Added to bleeding-sid-msg.map.txt (5):
        2008077 || ET CURRENT_EVENTS Possible Storm Worm April Fools Day EXE Request (foolsday.exe)
        2008078 || ET CURRENT_EVENTS Possible Storm Worm April Fools Day EXE Request (funny.exe)
        2008079 || ET CURRENT_EVENTS Possible Storm Worm April Fools Day EXE Request (kickme.exe)
        2404020 || ET DROP Known Bot C&C Server Traffic (group 21)  || url,www.shadowserver.org
        2405020 || ET DROP Known Bot C&C Traffic (group 21) - BLOCKING SOURCE || url,www.shadowserver.org

     -> Added to bleeding.rules (2):
        #by matt jonkman
        #temporary for the current storm wave





More information about the Snort-sigs mailing list