[Snort-sigs] Emerging Threats Weekly Signature Changes

emerging at ...3335... emerging at ...3335...
Sat Oct 4 18:00:08 EDT 2008


[***] Results from Oinkmaster started Sat Oct  4 18:00:08 2008 [***]

[+++]          Added rules:          [+++]

 2008593 - ET TROJAN Ultimate Defender Fake AV Checkin (emerging-virus.rules)
 2008594 - ET MALWARE ezday.co.kr Related Spyware User-Agent Detected (Ezshop) (emerging-malware.rules)
 2008595 - ET P2P SoulSeek P2P Server Connection (emerging-p2p.rules)
 2008596 - ET SCAN Brute Force Exploit Detector HTTP Buffer Overflow Detection (emerging-scan.rules)
 2008597 - ET SCAN Cisco Torch SNMP Scan (emerging-scan.rules)
 2008598 - ET SCAN Sipsak SIP scan (emerging-scan.rules)
 2008599 - ET CURRENT_EVENTS Asprox Cookie SQL Injection Attempt (emerging.rules)
 2008600 - ET MALWARE Suspicious User-Agent Detected (Windows+NT) (emerging-malware.rules)
 2008601 - ET TROJAN Visual Shock Keylogger Reporting to Controller (emerging-virus.rules)
 2008602 - ET TROJAN Visual Shock Keylogger Reporting Idle to Controller (emerging-virus.rules)
 2008603 - ET MALWARE Suspicious User-Agent Detected (RLMultySocket) (emerging-malware.rules)
 2008604 - ET TROJAN Gamethief/PSW.Magania Checkin (emerging-virus.rules)
 2008605 - ET SCAN Stompy Web Application Session Scan (emerging-scan.rules)
 2008606 - ET SCAN Enumiax Inter-Asterisk Exchange Protocol Username Scan (emerging-scan.rules)
 2008607 - ET EXPLOIT Chilkat IMAP ActiveX File Execution and IE DoS (emerging-exploit.rules)
 2008608 - ET MALWARE WinFixer Trojan Related User-Agent Detected (ElectroSun NetInstaller) (emerging-malware.rules)
 2008609 - ET SCAN Sivus VOIP Vulnerability Scanner SIP Scan (emerging-scan.rules)
 2008610 - ET SCAN Sivus VOIP Vulnerability Scanner SIP Components Scan (emerging-scan.rules)
 2008611 - ET P2P SoulSeek P2P Login Response (emerging-p2p.rules)
 2008612 - ET EXPLOIT Autodesk Design Review DWF Viewer ActiveX Control SaveAs Insecure Method (emerging-exploit.rules)
 2008613 - ET EXPLOIT GdPicture Pro ActiveX control SaveAsPDF Insecure Method (emerging-exploit.rules)
 2008614 - ET WEB_SQL_INJECTION PHP-Lance show.php catid SQL Injection (emerging-web_sql_injection.rules)
 2008615 - ET WEB_SQL_INJECTION Real Estate Manager realestate-index.php cat_id SQL Injection (emerging-web_sql_injection.rules)
 2008616 - ET WEB_SQL_INJECTION Pilot Online Training Solution news_read.php id SQL Injection (emerging-web_sql_injection.rules)
 2008617 - ET SCAN Wikto Scan (emerging-scan.rules)
 2406021 - ET RBN Known Russian Business Network Monitored Domains (22) (emerging-rbn.rules)
 2406022 - ET RBN Known Russian Business Network Monitored Domains (23) (emerging-rbn.rules)
 2406023 - ET RBN Known Russian Business Network Monitored Domains (24) (emerging-rbn.rules)
 2406024 - ET RBN Known Russian Business Network Monitored Domains (25) (emerging-rbn.rules)
 2406025 - ET RBN Known Russian Business Network Monitored Domains (26) (emerging-rbn.rules)
 2406026 - ET RBN Known Russian Business Network Monitored Domains (27) (emerging-rbn.rules)
 2406027 - ET RBN Known Russian Business Network Monitored Domains (28) (emerging-rbn.rules)
 2406028 - ET RBN Known Russian Business Network Monitored Domains (29) (emerging-rbn.rules)
 2407021 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) (emerging-rbn-BLOCK.rules)
 2407022 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) (emerging-rbn-BLOCK.rules)
 2407023 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) (emerging-rbn-BLOCK.rules)
 2407024 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) (emerging-rbn-BLOCK.rules)
 2407025 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) (emerging-rbn-BLOCK.rules)
 2407026 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) (emerging-rbn-BLOCK.rules)
 2407027 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) (emerging-rbn-BLOCK.rules)
 2407028 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) (emerging-rbn-BLOCK.rules)


[///]     Modified active rules:     [///]

 2007922 - ET TROJAN Backdoor.Win32.VB.brg C&C Checkin (emerging-virus.rules)
 2007979 - ET TROJAN Backdoor.Win32.VB.brg C&C Reporting Version (emerging-virus.rules)
 2008334 - ET TROJAN Beizhu/Womble/Vipdataend Checking in with Controller (emerging-virus.rules)
 2008335 - ET TROJAN Beizhu/Womble/Vipdataend Controller Keepalive (emerging-virus.rules)
 2008493 - ET TROJAN Pushdo Checkin (emerging-virus.rules)
 2008508 - ET CURRENT_EVENTS Internal User may have Visited an ASPROX Infected Site (emerging.rules)
 2008587 - ET TROJAN TroDjan 2.0 Infection Report (emerging-virus.rules)
 2400000 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400001 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400002 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400003 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400004 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400005 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400006 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400007 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2401000 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401001 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401002 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401003 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401004 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401005 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401006 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401007 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2402000 - ET DROP Dshield Block Listed Source (emerging-dshield.rules)
 2403000 - ET DROP Dshield Block Listed Source - BLOCKING (emerging-dshield-BLOCK.rules)
 2404000 - ET DROP Known Bot C&C Server Traffic (group 1)  (emerging-botcc.rules)
 2404001 - ET DROP Known Bot C&C Server Traffic (group 2)  (emerging-botcc.rules)
 2404002 - ET DROP Known Bot C&C Server Traffic (group 3)  (emerging-botcc.rules)
 2404003 - ET DROP Known Bot C&C Server Traffic (group 4)  (emerging-botcc.rules)
 2404004 - ET DROP Known Bot C&C Server Traffic (group 5)  (emerging-botcc.rules)
 2404005 - ET DROP Known Bot C&C Server Traffic (group 6)  (emerging-botcc.rules)
 2404006 - ET DROP Known Bot C&C Server Traffic (group 7)  (emerging-botcc.rules)
 2404007 - ET DROP Known Bot C&C Server Traffic (group 8)  (emerging-botcc.rules)
 2404008 - ET DROP Known Bot C&C Server Traffic (group 9)  (emerging-botcc.rules)
 2404009 - ET DROP Known Bot C&C Server Traffic (group 10)  (emerging-botcc.rules)
 2404010 - ET DROP Known Bot C&C Server Traffic (group 11)  (emerging-botcc.rules)
 2404011 - ET DROP Known Bot C&C Server Traffic (group 12)  (emerging-botcc.rules)
 2404012 - ET DROP Known Bot C&C Server Traffic (group 13)  (emerging-botcc.rules)
 2404013 - ET DROP Known Bot C&C Server Traffic (group 14)  (emerging-botcc.rules)
 2404014 - ET DROP Known Bot C&C Server Traffic (group 15)  (emerging-botcc.rules)
 2404015 - ET DROP Known Bot C&C Server Traffic (group 16)  (emerging-botcc.rules)
 2404016 - ET DROP Known Bot C&C Server Traffic (group 17)  (emerging-botcc.rules)
 2404017 - ET DROP Known Bot C&C Server Traffic (group 18)  (emerging-botcc.rules)
 2404018 - ET DROP Known Bot C&C Server Traffic (group 19)  (emerging-botcc.rules)
 2404019 - ET DROP Known Bot C&C Server Traffic (group 20)  (emerging-botcc.rules)
 2405000 - ET DROP Known Bot C&C Traffic (group 1) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405001 - ET DROP Known Bot C&C Traffic (group 2) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405002 - ET DROP Known Bot C&C Traffic (group 3) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405003 - ET DROP Known Bot C&C Traffic (group 4) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405004 - ET DROP Known Bot C&C Traffic (group 5) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405005 - ET DROP Known Bot C&C Traffic (group 6) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405006 - ET DROP Known Bot C&C Traffic (group 7) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405007 - ET DROP Known Bot C&C Traffic (group 8) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405008 - ET DROP Known Bot C&C Traffic (group 9) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405009 - ET DROP Known Bot C&C Traffic (group 10) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405010 - ET DROP Known Bot C&C Traffic (group 11) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405011 - ET DROP Known Bot C&C Traffic (group 12) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405012 - ET DROP Known Bot C&C Traffic (group 13) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405013 - ET DROP Known Bot C&C Traffic (group 14) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405014 - ET DROP Known Bot C&C Traffic (group 15) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405015 - ET DROP Known Bot C&C Traffic (group 16) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405016 - ET DROP Known Bot C&C Traffic (group 17) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405017 - ET DROP Known Bot C&C Traffic (group 18) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405018 - ET DROP Known Bot C&C Traffic (group 19) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405019 - ET DROP Known Bot C&C Traffic (group 20) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2406000 - ET RBN Known Russian Business Network Monitored Domains (1) (emerging-rbn.rules)
 2406001 - ET RBN Known Russian Business Network Monitored Domains (2) (emerging-rbn.rules)
 2406002 - ET RBN Known Russian Business Network Monitored Domains (3) (emerging-rbn.rules)
 2406003 - ET RBN Known Russian Business Network Monitored Domains (4) (emerging-rbn.rules)
 2406004 - ET RBN Known Russian Business Network Monitored Domains (5) (emerging-rbn.rules)
 2406005 - ET RBN Known Russian Business Network Monitored Domains (6) (emerging-rbn.rules)
 2406006 - ET RBN Known Russian Business Network Monitored Domains (7) (emerging-rbn.rules)
 2406007 - ET RBN Known Russian Business Network Monitored Domains (8) (emerging-rbn.rules)
 2406008 - ET RBN Known Russian Business Network Monitored Domains (9) (emerging-rbn.rules)
 2406009 - ET RBN Known Russian Business Network Monitored Domains (10) (emerging-rbn.rules)
 2406010 - ET RBN Known Russian Business Network Monitored Domains (11) (emerging-rbn.rules)
 2406011 - ET RBN Known Russian Business Network Monitored Domains (12) (emerging-rbn.rules)
 2406012 - ET RBN Known Russian Business Network Monitored Domains (13) (emerging-rbn.rules)
 2406013 - ET RBN Known Russian Business Network Monitored Domains (14) (emerging-rbn.rules)
 2406014 - ET RBN Known Russian Business Network Monitored Domains (15) (emerging-rbn.rules)
 2406015 - ET RBN Known Russian Business Network Monitored Domains (16) (emerging-rbn.rules)
 2406016 - ET RBN Known Russian Business Network Monitored Domains (17) (emerging-rbn.rules)
 2406017 - ET RBN Known Russian Business Network Monitored Domains (18) (emerging-rbn.rules)
 2406018 - ET RBN Known Russian Business Network Monitored Domains (19) (emerging-rbn.rules)
 2406019 - ET RBN Known Russian Business Network Monitored Domains (20) (emerging-rbn.rules)
 2406020 - ET RBN Known Russian Business Network Monitored Domains (21) (emerging-rbn.rules)
 2407000 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) (emerging-rbn-BLOCK.rules)
 2407001 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) (emerging-rbn-BLOCK.rules)
 2407002 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) (emerging-rbn-BLOCK.rules)
 2407003 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) (emerging-rbn-BLOCK.rules)
 2407004 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) (emerging-rbn-BLOCK.rules)
 2407005 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) (emerging-rbn-BLOCK.rules)
 2407006 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) (emerging-rbn-BLOCK.rules)
 2407007 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) (emerging-rbn-BLOCK.rules)
 2407008 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) (emerging-rbn-BLOCK.rules)
 2407009 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) (emerging-rbn-BLOCK.rules)
 2407010 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) (emerging-rbn-BLOCK.rules)
 2407011 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) (emerging-rbn-BLOCK.rules)
 2407012 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) (emerging-rbn-BLOCK.rules)
 2407013 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) (emerging-rbn-BLOCK.rules)
 2407014 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) (emerging-rbn-BLOCK.rules)
 2407015 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) (emerging-rbn-BLOCK.rules)
 2407016 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) (emerging-rbn-BLOCK.rules)
 2407017 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) (emerging-rbn-BLOCK.rules)
 2407018 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) (emerging-rbn-BLOCK.rules)
 2407019 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) (emerging-rbn-BLOCK.rules)
 2407020 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) (emerging-rbn-BLOCK.rules)


[---]         Removed rules:         [---]

 2404020 - ET DROP Known Bot C&C Server Traffic (group 21)  (emerging-botcc.rules)
 2405020 - ET DROP Known Bot C&C Traffic (group 21) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to emerging-drop-BLOCK.rules (2):
        #  VERSION 1316
        #  Generated 2008-10-04 00:03:02 EDT

     -> Added to emerging-drop.rules (2):
        #  VERSION 1316
        #  Generated 2008-10-04 00:03:02 EDT

     -> Added to emerging-exploit.rules (3):
        #by Stillsecure
        #by Stillsecure
        #by Stillsecure

     -> Added to emerging-p2p.rules (1):
        #christopher Campesi

     -> Added to emerging-rbn-BLOCK.rules (2):
        #  VERSION 77
        #  Updated 2008-10-01 18:23:28

     -> Added to emerging-rbn.rules (2):
        #  VERSION 77
        #  Updated 2008-10-01 18:23:28

     -> Added to emerging-sid-msg.map (43):
        2008334 || ET TROJAN Beizhu/Womble/Vipdataend Checking in with Controller
        2008493 || ET TROJAN Pushdo Checkin
        2008593 || ET TROJAN Ultimate Defender Fake AV Checkin
        2008594 || ET MALWARE ezday.co.kr Related Spyware User-Agent Detected (Ezshop)
        2008595 || ET P2P SoulSeek P2P Server Connection || url,www.slsknet.org
        2008596 || ET SCAN Brute Force Exploit Detector HTTP Buffer Overflow Detection || url,www.snake-basket.de/bed.html
        2008597 || ET SCAN Cisco Torch SNMP Scan || url,www.securiteam.com/tools/5EP0F1FEUA.html || url,www.hackingexposedcisco.com/?link=tools
        2008598 || ET SCAN Sipsak SIP scan || url,sipsak.org/
        2008599 || ET CURRENT_EVENTS Asprox Cookie SQL Injection Attempt || url,isc.sans.org/diary.html?n&storyid=5092
        2008600 || ET MALWARE Suspicious User-Agent Detected (Windows+NT)
        2008601 || ET TROJAN Visual Shock Keylogger Reporting to Controller || url,research.sunbelt-software.com/threatdisplay.aspx?threatid=42573
        2008602 || ET TROJAN Visual Shock Keylogger Reporting Idle to Controller || url,research.sunbelt-software.com/threatdisplay.aspx?threatid=42573
        2008603 || ET MALWARE Suspicious User-Agent Detected (RLMultySocket)
        2008604 || ET TROJAN Gamethief/PSW.Magania Checkin
        2008605 || ET SCAN Stompy Web Application Session Scan || url,www.darknet.org.uk/2007/03/stompy-the-web-application-session-analyzer-tool/
        2008606 || ET SCAN Enumiax Inter-Asterisk Exchange Protocol Username Scan || url,sourceforge.net/projects/enumiax/
        2008607 || ET EXPLOIT Chilkat IMAP ActiveX File Execution and IE DoS || url,www.milw0rm.com/exploits/6600
        2008608 || ET MALWARE WinFixer Trojan Related User-Agent Detected (ElectroSun NetInstaller)
        2008609 || ET SCAN Sivus VOIP Vulnerability Scanner SIP Scan || url,www.vopsecurity.org/ || url,www.security-database.com/toolswatch/SiVus-VoIP-Security-Scanner-1-09.html
        2008610 || ET SCAN Sivus VOIP Vulnerability Scanner SIP Components Scan || url,www.vopsecurity.org/ || url,www.security-database.com/toolswatch/SiVus-VoIP-Security-Scanner-1-09.html
        2008611 || ET P2P SoulSeek P2P Login Response || url,www.slsknet.org
        2008612 || ET EXPLOIT Autodesk Design Review DWF Viewer ActiveX Control SaveAs Insecure Method || url,secunia.com/Advisories/31989/ || url,retrogod.altervista.org/9sg_autodesk_revit_arch_2009_exploit.html
        2008613 || ET EXPLOIT GdPicture Pro ActiveX control SaveAsPDF Insecure Method || url,milw0rm.com/exploits/6638 || url,secunia.com/Advisories/31966/
        2008614 || ET WEB_SQL_INJECTION PHP-Lance show.php catid SQL Injection || url,www.milw0rm.com/exploits/6605 || url,secunia.com/Advisories/32027/
        2008615 || ET WEB_SQL_INJECTION Real Estate Manager realestate-index.php cat_id SQL Injection || url,www.milw0rm.com/exploits/6599 || url,secunia.com/Advisories/32049/
        2008616 || ET WEB_SQL_INJECTION Pilot Online Training Solution news_read.php id SQL Injection || url,www.milw0rm.com/exploits/6613 || url,secunia.com/Advisories/31969/
        2008617 || ET SCAN Wikto Scan || url,www.sensepost.com/research/wikto/WiktoDoc1-51.htm
        2406021 || ET RBN Known Russian Business Network Monitored Domains (22) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406022 || ET RBN Known Russian Business Network Monitored Domains (23) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406023 || ET RBN Known Russian Business Network Monitored Domains (24) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406024 || ET RBN Known Russian Business Network Monitored Domains (25) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406025 || ET RBN Known Russian Business Network Monitored Domains (26) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406026 || ET RBN Known Russian Business Network Monitored Domains (27) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406027 || ET RBN Known Russian Business Network Monitored Domains (28) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406028 || ET RBN Known Russian Business Network Monitored Domains (29) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407021 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407022 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407023 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407024 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407025 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407026 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407027 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407028 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork

     -> Added to emerging-sid-msg.map.txt (43):
        2008334 || ET TROJAN Beizhu/Womble/Vipdataend Checking in with Controller
        2008493 || ET TROJAN Pushdo Checkin
        2008593 || ET TROJAN Ultimate Defender Fake AV Checkin
        2008594 || ET MALWARE ezday.co.kr Related Spyware User-Agent Detected (Ezshop)
        2008595 || ET P2P SoulSeek P2P Server Connection || url,www.slsknet.org
        2008596 || ET SCAN Brute Force Exploit Detector HTTP Buffer Overflow Detection || url,www.snake-basket.de/bed.html
        2008597 || ET SCAN Cisco Torch SNMP Scan || url,www.securiteam.com/tools/5EP0F1FEUA.html || url,www.hackingexposedcisco.com/?link=tools
        2008598 || ET SCAN Sipsak SIP scan || url,sipsak.org/
        2008599 || ET CURRENT_EVENTS Asprox Cookie SQL Injection Attempt || url,isc.sans.org/diary.html?n&storyid=5092
        2008600 || ET MALWARE Suspicious User-Agent Detected (Windows+NT)
        2008601 || ET TROJAN Visual Shock Keylogger Reporting to Controller || url,research.sunbelt-software.com/threatdisplay.aspx?threatid=42573
        2008602 || ET TROJAN Visual Shock Keylogger Reporting Idle to Controller || url,research.sunbelt-software.com/threatdisplay.aspx?threatid=42573
        2008603 || ET MALWARE Suspicious User-Agent Detected (RLMultySocket)
        2008604 || ET TROJAN Gamethief/PSW.Magania Checkin
        2008605 || ET SCAN Stompy Web Application Session Scan || url,www.darknet.org.uk/2007/03/stompy-the-web-application-session-analyzer-tool/
        2008606 || ET SCAN Enumiax Inter-Asterisk Exchange Protocol Username Scan || url,sourceforge.net/projects/enumiax/
        2008607 || ET EXPLOIT Chilkat IMAP ActiveX File Execution and IE DoS || url,www.milw0rm.com/exploits/6600
        2008608 || ET MALWARE WinFixer Trojan Related User-Agent Detected (ElectroSun NetInstaller)
        2008609 || ET SCAN Sivus VOIP Vulnerability Scanner SIP Scan || url,www.vopsecurity.org/ || url,www.security-database.com/toolswatch/SiVus-VoIP-Security-Scanner-1-09.html
        2008610 || ET SCAN Sivus VOIP Vulnerability Scanner SIP Components Scan || url,www.vopsecurity.org/ || url,www.security-database.com/toolswatch/SiVus-VoIP-Security-Scanner-1-09.html
        2008611 || ET P2P SoulSeek P2P Login Response || url,www.slsknet.org
        2008612 || ET EXPLOIT Autodesk Design Review DWF Viewer ActiveX Control SaveAs Insecure Method || url,secunia.com/Advisories/31989/ || url,retrogod.altervista.org/9sg_autodesk_revit_arch_2009_exploit.html
        2008613 || ET EXPLOIT GdPicture Pro ActiveX control SaveAsPDF Insecure Method || url,milw0rm.com/exploits/6638 || url,secunia.com/Advisories/31966/
        2008614 || ET WEB_SQL_INJECTION PHP-Lance show.php catid SQL Injection || url,www.milw0rm.com/exploits/6605 || url,secunia.com/Advisories/32027/
        2008615 || ET WEB_SQL_INJECTION Real Estate Manager realestate-index.php cat_id SQL Injection || url,www.milw0rm.com/exploits/6599 || url,secunia.com/Advisories/32049/
        2008616 || ET WEB_SQL_INJECTION Pilot Online Training Solution news_read.php id SQL Injection || url,www.milw0rm.com/exploits/6613 || url,secunia.com/Advisories/31969/
        2008617 || ET SCAN Wikto Scan || url,www.sensepost.com/research/wikto/WiktoDoc1-51.htm
        2406021 || ET RBN Known Russian Business Network Monitored Domains (22) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406022 || ET RBN Known Russian Business Network Monitored Domains (23) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406023 || ET RBN Known Russian Business Network Monitored Domains (24) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406024 || ET RBN Known Russian Business Network Monitored Domains (25) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406025 || ET RBN Known Russian Business Network Monitored Domains (26) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406026 || ET RBN Known Russian Business Network Monitored Domains (27) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406027 || ET RBN Known Russian Business Network Monitored Domains (28) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406028 || ET RBN Known Russian Business Network Monitored Domains (29) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407021 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407022 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407023 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407024 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407025 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407026 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407027 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407028 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork

     -> Added to emerging-virus.rules (1):
        # ref: 4e224c80f62c1b3dc74d295d0633e699

     -> Added to emerging-web_sql_injection.rules (3):
        #by Stillsecure
        #by Stillsecure
        #by Stillsecure

     -> Added to emerging.rules (1):
        #matt jonkman

[---]     Removed non-rule lines:    [---]

     -> Removed from emerging-drop-BLOCK.rules (2):
        #  VERSION 1309
        #  Generated 2008-09-27 00:03:02 EDT

     -> Removed from emerging-drop.rules (2):
        #  VERSION 1309
        #  Generated 2008-09-27 00:03:02 EDT

     -> Removed from emerging-rbn-BLOCK.rules (2):
        #  VERSION 63
        #  Updated 2008-09-25 09:04:53

     -> Removed from emerging-rbn.rules (2):
        #  VERSION 63
        #  Updated 2008-09-25 09:04:53

     -> Removed from emerging-sid-msg.map (14):
        2008334 || ET TROJAN Beizhu/Womble/Vipdataend Checking with Controller
        2008493 || ET TROJAN Cutwail/W32.Small.avu Dropper
        2404020 || ET DROP Known Bot C&C Server Traffic (group 21)  || url,www.shadowserver.org
        2405020 || ET DROP Known Bot C&C Traffic (group 21) - BLOCKING SOURCE || url,www.shadowserver.org
        2500076 || ET COMPROMISED Known Compromised or Hostile Host Traffic (77) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500077 || ET COMPROMISED Known Compromised or Hostile Host Traffic (78) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500078 || ET COMPROMISED Known Compromised or Hostile Host Traffic (79) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500079 || ET COMPROMISED Known Compromised or Hostile Host Traffic (80) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500080 || ET COMPROMISED Known Compromised or Hostile Host Traffic (81) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510076 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (77) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510077 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (78) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510078 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (79) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510079 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (80) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510080 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (81) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts

     -> Removed from emerging-sid-msg.map.txt (14):
        2008334 || ET TROJAN Beizhu/Womble/Vipdataend Checking with Controller
        2008493 || ET TROJAN Cutwail/W32.Small.avu Dropper
        2404020 || ET DROP Known Bot C&C Server Traffic (group 21)  || url,www.shadowserver.org
        2405020 || ET DROP Known Bot C&C Traffic (group 21) - BLOCKING SOURCE || url,www.shadowserver.org
        2500076 || ET COMPROMISED Known Compromised or Hostile Host Traffic (77) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500077 || ET COMPROMISED Known Compromised or Hostile Host Traffic (78) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500078 || ET COMPROMISED Known Compromised or Hostile Host Traffic (79) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500079 || ET COMPROMISED Known Compromised or Hostile Host Traffic (80) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500080 || ET COMPROMISED Known Compromised or Hostile Host Traffic (81) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510076 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (77) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510077 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (78) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510078 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (79) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510079 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (80) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510080 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (81) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts





More information about the Snort-sigs mailing list