[Snort-sigs] Emerging Threats Daily Signature Changes

emerging at ...3335... emerging at ...3335...
Tue Feb 5 17:00:09 EST 2008


[***] Results from Oinkmaster started Tue Feb  5 17:00:08 2008 [***]

[+++]          Added rules:          [+++]

 2007811 - ET TROJAN Metajuan trojan checkin (bleeding-virus.rules)
 2007812 - ET CURRENT_EVENTS Vulnerable Facebook ActiveX CLSID in Use (bleeding.rules)
 2007813 - ET CURRENT_EVENTS Vulnerable Yahoo MediaGrid ActiveX CLSID in Use (bleeding.rules)
 2007814 - ET CURRENT_EVENTS Vulnerable Yahoo DataGrid ActiveX CLSID in Use (bleeding.rules)
 2007815 - ET CURRENT_EVENTS Vulnerable Aurigma ImageUploader4 ActiveX CLSID in Use (bleeding.rules)
 2007816 - ET CURRENT_EVENTS Vulnerable Aurigma ImageUploader5 ActiveX CLSID in Use (bleeding.rules)


[///]     Modified active rules:     [///]

 2406005 - ET RBN Known Russian Business Network Monitored Domains (1) (bleeding-rbn.rules)
 2406006 - ET RBN Known Russian Business Network Monitored Domains (2) (bleeding-rbn.rules)
 2406007 - ET RBN Known Russian Business Network Monitored Domains (3) (bleeding-rbn.rules)
 2406008 - ET RBN Known Russian Business Network Monitored Domains (4) (bleeding-rbn.rules)
 2406009 - ET RBN Known Russian Business Network Monitored Domains (5) (bleeding-rbn.rules)
 2406010 - ET RBN Known Russian Business Network Monitored Domains (6) (bleeding-rbn.rules)
 2406011 - ET RBN Known Russian Business Network Monitored Domains (7) (bleeding-rbn.rules)
 2406012 - ET RBN Known Russian Business Network Monitored Domains (8) (bleeding-rbn.rules)
 2406013 - ET RBN Known Russian Business Network Monitored Domains (9) (bleeding-rbn.rules)
 2406014 - ET RBN Known Russian Business Network Monitored Domains (10) (bleeding-rbn.rules)
 2406015 - ET RBN Known Russian Business Network Monitored Domains (11) (bleeding-rbn.rules)
 2406016 - ET RBN Known Russian Business Network Monitored Domains (12) (bleeding-rbn.rules)
 2406017 - ET RBN Known Russian Business Network Monitored Domains (13) (bleeding-rbn.rules)
 2406018 - ET RBN Known Russian Business Network Monitored Domains (14) (bleeding-rbn.rules)
 2406019 - ET RBN Known Russian Business Network Monitored Domains (15) (bleeding-rbn.rules)
 2406020 - ET RBN Known Russian Business Network Monitored Domains (16) (bleeding-rbn.rules)
 2406021 - ET RBN Known Russian Business Network Monitored Domains (17) (bleeding-rbn.rules)
 2406022 - ET RBN Known Russian Business Network Monitored Domains (18) (bleeding-rbn.rules)
 2406023 - ET RBN Known Russian Business Network Monitored Domains (19) (bleeding-rbn.rules)
 2406024 - ET RBN Known Russian Business Network Monitored Domains (20) (bleeding-rbn.rules)
 2406025 - ET RBN Known Russian Business Network Monitored Domains (21) (bleeding-rbn.rules)
 2406026 - ET RBN Known Russian Business Network Monitored Domains (22) (bleeding-rbn.rules)
 2406027 - ET RBN Known Russian Business Network Monitored Domains (23) (bleeding-rbn.rules)
 2406028 - ET RBN Known Russian Business Network Monitored Domains (24) (bleeding-rbn.rules)
 2406029 - ET RBN Known Russian Business Network Monitored Domains (25) (bleeding-rbn.rules)
 2406030 - ET RBN Known Russian Business Network Monitored Domains (26) (bleeding-rbn.rules)
 2406031 - ET RBN Known Russian Business Network Monitored Domains (27) (bleeding-rbn.rules)
 2406032 - ET RBN Known Russian Business Network Monitored Domains (28) (bleeding-rbn.rules)
 2406033 - ET RBN Known Russian Business Network Monitored Domains (29) (bleeding-rbn.rules)
 2406034 - ET RBN Known Russian Business Network Monitored Domains (30) (bleeding-rbn.rules)
 2407005 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) (bleeding-rbn-BLOCK.rules)
 2407006 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) (bleeding-rbn-BLOCK.rules)
 2407007 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) (bleeding-rbn-BLOCK.rules)
 2407008 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) (bleeding-rbn-BLOCK.rules)
 2407009 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) (bleeding-rbn-BLOCK.rules)
 2407010 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) (bleeding-rbn-BLOCK.rules)
 2407011 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) (bleeding-rbn-BLOCK.rules)
 2407012 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) (bleeding-rbn-BLOCK.rules)
 2407013 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) (bleeding-rbn-BLOCK.rules)
 2407014 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) (bleeding-rbn-BLOCK.rules)
 2407015 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) (bleeding-rbn-BLOCK.rules)
 2407016 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) (bleeding-rbn-BLOCK.rules)
 2407017 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) (bleeding-rbn-BLOCK.rules)
 2407018 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) (bleeding-rbn-BLOCK.rules)
 2407019 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) (bleeding-rbn-BLOCK.rules)
 2407020 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) (bleeding-rbn-BLOCK.rules)
 2407021 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) (bleeding-rbn-BLOCK.rules)
 2407022 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) (bleeding-rbn-BLOCK.rules)
 2407023 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) (bleeding-rbn-BLOCK.rules)
 2407024 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) (bleeding-rbn-BLOCK.rules)
 2407025 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) (bleeding-rbn-BLOCK.rules)
 2407026 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) (bleeding-rbn-BLOCK.rules)
 2407027 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) (bleeding-rbn-BLOCK.rules)
 2407028 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) (bleeding-rbn-BLOCK.rules)
 2407029 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) (bleeding-rbn-BLOCK.rules)
 2407030 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) (bleeding-rbn-BLOCK.rules)
 2407031 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) (bleeding-rbn-BLOCK.rules)
 2407032 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) (bleeding-rbn-BLOCK.rules)
 2407033 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) (bleeding-rbn-BLOCK.rules)
 2407034 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) (bleeding-rbn-BLOCK.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to bleeding-rbn-BLOCK.rules (2):
        #  VERSION 31
        #  Updated 2008-02-05 12:45:26

     -> Added to bleeding-rbn.rules (2):
        #  VERSION 31
        #  Updated 2008-02-05 12:45:26

     -> Added to bleeding-sid-msg.map (6):
        2007811 || ET TROJAN Metajuan trojan checkin || url,www.symantec.com/security_response/writeup.jsp?docid=2007-030112-0714-99
        2007812 || ET CURRENT_EVENTS Vulnerable Facebook ActiveX CLSID in Use || url,isc.sans.org/diary.html?storyid=3929
        2007813 || ET CURRENT_EVENTS Vulnerable Yahoo MediaGrid ActiveX CLSID in Use || url,isc.sans.org/diary.html?storyid=3929
        2007814 || ET CURRENT_EVENTS Vulnerable Yahoo DataGrid ActiveX CLSID in Use || url,isc.sans.org/diary.html?storyid=3929
        2007815 || ET CURRENT_EVENTS Vulnerable Aurigma ImageUploader4 ActiveX CLSID in Use || url,isc.sans.org/diary.html?storyid=3929
        2007816 || ET CURRENT_EVENTS Vulnerable Aurigma ImageUploader5 ActiveX CLSID in Use || url,isc.sans.org/diary.html?storyid=3929

     -> Added to bleeding-sid-msg.map.txt (6):
        2007811 || ET TROJAN Metajuan trojan checkin || url,www.symantec.com/security_response/writeup.jsp?docid=2007-030112-0714-99
        2007812 || ET CURRENT_EVENTS Vulnerable Facebook ActiveX CLSID in Use || url,isc.sans.org/diary.html?storyid=3929
        2007813 || ET CURRENT_EVENTS Vulnerable Yahoo MediaGrid ActiveX CLSID in Use || url,isc.sans.org/diary.html?storyid=3929
        2007814 || ET CURRENT_EVENTS Vulnerable Yahoo DataGrid ActiveX CLSID in Use || url,isc.sans.org/diary.html?storyid=3929
        2007815 || ET CURRENT_EVENTS Vulnerable Aurigma ImageUploader4 ActiveX CLSID in Use || url,isc.sans.org/diary.html?storyid=3929
        2007816 || ET CURRENT_EVENTS Vulnerable Aurigma ImageUploader5 ActiveX CLSID in Use || url,isc.sans.org/diary.html?storyid=3929

     -> Added to bleeding-virus.rules (1):
        #by David Bianco

     -> Added to bleeding.rules (9):
        #by Matt Jonkman
        # re http://isc.sans.org/diary.html?storyid=3929
        # Will remove these sometime after patching looks complete
        #by Matt Jonkman
        # re http://isc.sans.org/diary.html?storyid=3929
        # Will remove these sometime after patching looks complete
        #by Matt Jonkman
        # re http://isc.sans.org/diary.html?storyid=3929
        # Will remove these sometime after patching looks complete

[---]     Removed non-rule lines:    [---]

     -> Removed from bleeding-rbn-BLOCK.rules (2):
        #  VERSION 30
        #  Updated 2008-02-03 17:58:24

     -> Removed from bleeding-rbn.rules (2):
        #  VERSION 30
        #  Updated 2008-02-03 17:58:24

     -> Removed from bleeding-sid-msg.map (2):
        2404017 || ET DROP Known Bot C&C Server Traffic (group 18)  || url,www.shadowserver.org
        2405017 || ET DROP Known Bot C&C Traffic (group 18) - BLOCKING SOURCE || url,www.shadowserver.org

     -> Removed from bleeding-sid-msg.map.txt (2):
        2404017 || ET DROP Known Bot C&C Server Traffic (group 18)  || url,www.shadowserver.org
        2405017 || ET DROP Known Bot C&C Traffic (group 18) - BLOCKING SOURCE || url,www.shadowserver.org





More information about the Snort-sigs mailing list