[Snort-sigs] Emerging Threats Daily Signature Changes

emerging at ...3335... emerging at ...3335...
Fri Mar 7 17:00:09 EST 2008


[***] Results from Oinkmaster started Fri Mar  7 17:00:09 2008 [***]

[+++]          Added rules:          [+++]

 2007930 - ET TROJAN Delf/Hupigon C&C Channel Version Report (bleeding-virus.rules)
 2007931 - ET EXPLOIT IncrediMail IMMenuShellExt ActiveX Control Buffer Overflow Vulnerability (bleeding-exploit.rules)
 2007932 - ET EXPLOIT Symantec BackupExec Calendar Control (PVCalendar.ocx) BoF Vulnerability (bleeding-exploit.rules)
 2007933 - ET EXPLOIT Zilab Chat and Instant Messaging Heap Overflow Vulnerability (bleeding-exploit.rules)
 2007934 - ET EXPLOIT Zilab Chat and Instant Messaging User Info BoF Vulnerability (bleeding-exploit.rules)
 2007935 - ET MALWARE Geopia.com Fake Anti-Spyware/AV User Agent (fs3update) (bleeding-malware.rules)
 2007936 - ET WEB Netwin Webmail SurgeMail Mail Server Format String Vulnerability (bleeding-web.rules)
 2007937 - ET EXPLOIT Borland VisiBroker Smart Agent Heap Overflow (bleeding-exploit.rules)
 2007938 - ET MALWARE Geopia.com Fake Anti-Spyware/AV User Agent (fian3manager) (bleeding-malware.rules)
 2007939 - ET TROJAN Delf Checkin via HTTP (bleeding-virus.rules)
 2007940 - ET TROJAN Banker.li HTTP Checkin (bleeding-virus.rules)
 2406035 - ET RBN Known Russian Business Network Monitored Domains (31) (bleeding-rbn.rules)
 2407035 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) (bleeding-rbn-BLOCK.rules)


[///]     Modified active rules:     [///]

 2002383 - ET SCAN Potential FTP Brute-Force attempt (bleeding-scan.rules)
 2406005 - ET RBN Known Russian Business Network Monitored Domains (1) (bleeding-rbn.rules)
 2406006 - ET RBN Known Russian Business Network Monitored Domains (2) (bleeding-rbn.rules)
 2406007 - ET RBN Known Russian Business Network Monitored Domains (3) (bleeding-rbn.rules)
 2406008 - ET RBN Known Russian Business Network Monitored Domains (4) (bleeding-rbn.rules)
 2406009 - ET RBN Known Russian Business Network Monitored Domains (5) (bleeding-rbn.rules)
 2406010 - ET RBN Known Russian Business Network Monitored Domains (6) (bleeding-rbn.rules)
 2406011 - ET RBN Known Russian Business Network Monitored Domains (7) (bleeding-rbn.rules)
 2406012 - ET RBN Known Russian Business Network Monitored Domains (8) (bleeding-rbn.rules)
 2406013 - ET RBN Known Russian Business Network Monitored Domains (9) (bleeding-rbn.rules)
 2406014 - ET RBN Known Russian Business Network Monitored Domains (10) (bleeding-rbn.rules)
 2406015 - ET RBN Known Russian Business Network Monitored Domains (11) (bleeding-rbn.rules)
 2406016 - ET RBN Known Russian Business Network Monitored Domains (12) (bleeding-rbn.rules)
 2406017 - ET RBN Known Russian Business Network Monitored Domains (13) (bleeding-rbn.rules)
 2406018 - ET RBN Known Russian Business Network Monitored Domains (14) (bleeding-rbn.rules)
 2406019 - ET RBN Known Russian Business Network Monitored Domains (15) (bleeding-rbn.rules)
 2406020 - ET RBN Known Russian Business Network Monitored Domains (16) (bleeding-rbn.rules)
 2406021 - ET RBN Known Russian Business Network Monitored Domains (17) (bleeding-rbn.rules)
 2406022 - ET RBN Known Russian Business Network Monitored Domains (18) (bleeding-rbn.rules)
 2406023 - ET RBN Known Russian Business Network Monitored Domains (19) (bleeding-rbn.rules)
 2406024 - ET RBN Known Russian Business Network Monitored Domains (20) (bleeding-rbn.rules)
 2406025 - ET RBN Known Russian Business Network Monitored Domains (21) (bleeding-rbn.rules)
 2406026 - ET RBN Known Russian Business Network Monitored Domains (22) (bleeding-rbn.rules)
 2406027 - ET RBN Known Russian Business Network Monitored Domains (23) (bleeding-rbn.rules)
 2406028 - ET RBN Known Russian Business Network Monitored Domains (24) (bleeding-rbn.rules)
 2406029 - ET RBN Known Russian Business Network Monitored Domains (25) (bleeding-rbn.rules)
 2406030 - ET RBN Known Russian Business Network Monitored Domains (26) (bleeding-rbn.rules)
 2406031 - ET RBN Known Russian Business Network Monitored Domains (27) (bleeding-rbn.rules)
 2406032 - ET RBN Known Russian Business Network Monitored Domains (28) (bleeding-rbn.rules)
 2406033 - ET RBN Known Russian Business Network Monitored Domains (29) (bleeding-rbn.rules)
 2406034 - ET RBN Known Russian Business Network Monitored Domains (30) (bleeding-rbn.rules)
 2407005 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) (bleeding-rbn-BLOCK.rules)
 2407006 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) (bleeding-rbn-BLOCK.rules)
 2407007 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) (bleeding-rbn-BLOCK.rules)
 2407008 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) (bleeding-rbn-BLOCK.rules)
 2407009 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) (bleeding-rbn-BLOCK.rules)
 2407010 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) (bleeding-rbn-BLOCK.rules)
 2407011 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) (bleeding-rbn-BLOCK.rules)
 2407012 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) (bleeding-rbn-BLOCK.rules)
 2407013 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) (bleeding-rbn-BLOCK.rules)
 2407014 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) (bleeding-rbn-BLOCK.rules)
 2407015 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) (bleeding-rbn-BLOCK.rules)
 2407016 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) (bleeding-rbn-BLOCK.rules)
 2407017 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) (bleeding-rbn-BLOCK.rules)
 2407018 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) (bleeding-rbn-BLOCK.rules)
 2407019 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) (bleeding-rbn-BLOCK.rules)
 2407020 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) (bleeding-rbn-BLOCK.rules)
 2407021 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) (bleeding-rbn-BLOCK.rules)
 2407022 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) (bleeding-rbn-BLOCK.rules)
 2407023 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) (bleeding-rbn-BLOCK.rules)
 2407024 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) (bleeding-rbn-BLOCK.rules)
 2407025 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) (bleeding-rbn-BLOCK.rules)
 2407026 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) (bleeding-rbn-BLOCK.rules)
 2407027 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) (bleeding-rbn-BLOCK.rules)
 2407028 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) (bleeding-rbn-BLOCK.rules)
 2407029 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) (bleeding-rbn-BLOCK.rules)
 2407030 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) (bleeding-rbn-BLOCK.rules)
 2407031 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) (bleeding-rbn-BLOCK.rules)
 2407032 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) (bleeding-rbn-BLOCK.rules)
 2407033 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) (bleeding-rbn-BLOCK.rules)
 2407034 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) (bleeding-rbn-BLOCK.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to bleeding-attack_response.rules (1):
        # $Id: bleeding-attack_response.rules $

     -> Added to bleeding-dos.rules (1):
        # $Id: bleeding-dos.rules $

     -> Added to bleeding-exploit.rules (2):
        # $Id: bleeding-exploit.rules $
        #by Akash Mahajan of stillsecure

     -> Added to bleeding-game.rules (1):
        # $Id: bleeding-game.rules $

     -> Added to bleeding-inappropriate.rules (1):
        # $Id: bleeding-inappropriate.rules $

     -> Added to bleeding-malware.rules (1):
        # $Id: bleeding-malware.rules $

     -> Added to bleeding-p2p.rules (1):
        # $Id: bleeding-p2p.rules $

     -> Added to bleeding-policy.rules (1):
        # $Id: bleeding-policy.rules $

     -> Added to bleeding-rbn-BLOCK.rules (2):
        #  VERSION 37
        #  Updated 2008-03-06 19:56:19

     -> Added to bleeding-rbn.rules (2):
        #  VERSION 37
        #  Updated 2008-03-06 19:56:19

     -> Added to bleeding-scan.rules (1):
        # $Id: bleeding-scan.rules $

     -> Added to bleeding-sid-msg.map (13):
        2007930 || ET TROJAN Delf/Hupigon C&C Channel Version Report
        2007931 || ET EXPLOIT IncrediMail IMMenuShellExt ActiveX Control Buffer Overflow Vulnerability || cve,CVE-2007-1683 || bugtraq,23674 || url,www.milw0rm.com/exploits/3877
        2007932 || ET EXPLOIT Symantec BackupExec Calendar Control (PVCalendar.ocx) BoF Vulnerability || bugtraq,28008 || cve,CVE-2007-6017 || url,www.milw0rm.com/exploits/5205
        2007933 || ET EXPLOIT Zilab Chat and Instant Messaging Heap Overflow Vulnerability || bugtraq,27940 || url,aluigi.altervista.org/adv/zilabzcsx-adv.txt
        2007934 || ET EXPLOIT Zilab Chat and Instant Messaging User Info BoF Vulnerability || bugtraq,27940 || url,aluigi.altervista.org/adv/zilabzcsx-adv.txt
        2007935 || ET MALWARE Geopia.com Fake Anti-Spyware/AV User Agent (fs3update)
        2007936 || ET WEB Netwin Webmail SurgeMail Mail Server Format String Vulnerability || bugtraq,27990 || cve,CVE-2008-1055 || url,aluigi.altervista.org/adv/surgemailz-adv.txt
        2007937 || ET EXPLOIT Borland VisiBroker Smart Agent Heap Overflow || url,aluigi.altervista.org/adv/visibroken-adv.txt || bugtraq,28084
        2007938 || ET MALWARE Geopia.com Fake Anti-Spyware/AV User Agent (fian3manager)
        2007939 || ET TROJAN Delf Checkin via HTTP
        2007940 || ET TROJAN Banker.li HTTP Checkin
        2406035 || ET RBN Known Russian Business Network Monitored Domains (31) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407035 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork

     -> Added to bleeding-sid-msg.map.txt (13):
        2007930 || ET TROJAN Delf/Hupigon C&C Channel Version Report
        2007931 || ET EXPLOIT IncrediMail IMMenuShellExt ActiveX Control Buffer Overflow Vulnerability || cve,CVE-2007-1683 || bugtraq,23674 || url,www.milw0rm.com/exploits/3877
        2007932 || ET EXPLOIT Symantec BackupExec Calendar Control (PVCalendar.ocx) BoF Vulnerability || bugtraq,28008 || cve,CVE-2007-6017 || url,www.milw0rm.com/exploits/5205
        2007933 || ET EXPLOIT Zilab Chat and Instant Messaging Heap Overflow Vulnerability || bugtraq,27940 || url,aluigi.altervista.org/adv/zilabzcsx-adv.txt
        2007934 || ET EXPLOIT Zilab Chat and Instant Messaging User Info BoF Vulnerability || bugtraq,27940 || url,aluigi.altervista.org/adv/zilabzcsx-adv.txt
        2007935 || ET MALWARE Geopia.com Fake Anti-Spyware/AV User Agent (fs3update)
        2007936 || ET WEB Netwin Webmail SurgeMail Mail Server Format String Vulnerability || bugtraq,27990 || cve,CVE-2008-1055 || url,aluigi.altervista.org/adv/surgemailz-adv.txt
        2007937 || ET EXPLOIT Borland VisiBroker Smart Agent Heap Overflow || url,aluigi.altervista.org/adv/visibroken-adv.txt || bugtraq,28084
        2007938 || ET MALWARE Geopia.com Fake Anti-Spyware/AV User Agent (fian3manager)
        2007939 || ET TROJAN Delf Checkin via HTTP
        2007940 || ET TROJAN Banker.li HTTP Checkin
        2406035 || ET RBN Known Russian Business Network Monitored Domains (31) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407035 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork

     -> Added to bleeding-virus.rules (2):
        # $Id: bleeding-virus.rules $
        #Banker.ili by matt jonkman

     -> Added to bleeding-voip.rules (1):
        # $Id: bleeding-voip.rules $

     -> Added to bleeding-web.rules (1):
        # $Id: bleeding-web.rules $

     -> Added to bleeding-web_sql_injection.rules (1):
        # $Id: bleeding-web_sql_injection.rules $

     -> Added to bleeding.rules (1):
        # $Id: bleeding.rules $

[---]     Removed non-rule lines:    [---]

     -> Removed from bleeding-rbn-BLOCK.rules (2):
        #  VERSION 36
        #  Updated 2008-02-21 10:21:51

     -> Removed from bleeding-rbn.rules (2):
        #  VERSION 36
        #  Updated 2008-02-21 10:21:51





More information about the Snort-sigs mailing list