[Snort-sigs] Emerging Threats Weekly Signature Changes

emerging at ...3335... emerging at ...3335...
Sat Oct 11 18:00:08 EDT 2008


[***] Results from Oinkmaster started Sat Oct 11 18:00:08 2008 [***]

[+++]          Added rules:          [+++]

 2008546 - ET TROJAN Downloader.vr Checkin part 1 of 2 (emerging-virus.rules)
 2008618 - ET DOS IAS Helper COM Component iashlpr.dll activex remote DOS (emerging-dos.rules)
 2008619 - ET EXPLOIT Novell ZENWorks for Desktops Remote Heap-Based Buffer Overflow (emerging-exploit.rules)
 2008620 - ET EXPLOIT Internet Information Service iisext.dll activex setpassword Insecure Method (emerging-exploit.rules)
 2008621 - ET EXPLOIT Internet Information Service adsiis.dll activex remote DOS (emerging-exploit.rules)
 2008622 - ET WEB Pritlog index.php filename File Disclosure (emerging-web.rules)
 2008623 - ET TROJAN Cinmus.Checkin 1 (emerging-virus.rules)
 2008624 - ET TROJAN Cinmus.Checkin 2 (emerging-virus.rules)
 2008625 - ET P2P Pando Client User-Agent Detected (Mozilla/4.0 (Windows\; U) Pando/1.xx) (emerging-p2p.rules)
 2008626 - ET TROJAN PlayMP3z.biz Related Spyware/Trojan Install Report (emerging-virus.rules)
 2008627 - ET SCAN Httprecon Web Server Fingerprint Scan (emerging-scan.rules)
 2008628 - ET SCAN WSFuzzer Web Application Fuzzing (emerging-scan.rules)
 2008629 - ET SCAN Wikto Backend Data Miner Scan (emerging-scan.rules)
 2008639 - ET TROJAN Tibs Trojan Downloader (emerging-virus.rules)
 2008640 - ET SCAN SIP erase_registrations/add registrations attempt (emerging-voip.rules)
 2008641 - ET SCAN sipscan probe (emerging-voip.rules)
 2008642 - ET TROJAN Keylogger PRO GOLD Post (emerging-virus.rules)
 2008643 - ET MALWARE Suspicious User-Agent Detected (Downloader1.2) (emerging-malware.rules)
 2008644 - ET TROJAN Spy-Net Trojan Connection (emerging-virus.rules)
 2008645 - ET TROJAN Spy-Net Trojan Connection (2) (emerging-virus.rules)
 2008646 - ET CURRENT_EVENTS Trojan resulting from Fake MS Updates Email Login to CnC (emerging.rules)
 2008647 - ET MALWARE Internet-antivirus.com Related Fake AV User-Agent Detected (Update Internet Antivirus) (emerging-malware.rules)
 2008648 - ET WEB_SPECIFIC trac q variable open redirect (emerging-web_sql_injection.rules)
 2008649 - ET WEB_SPECIFIC Realtor v_cat SQL Injection (emerging-web_sql_injection.rules)
 2008650 - ET WEB_SPECIFIC Autos catid SQL Injection (emerging-web_sql_injection.rules)
 2008651 - ET WEB_SPECIFIC JMweb MP3 src Multiple Local File Inclusion (emerging-web_sql_injection.rules)
 2008652 - ET WEB_SPECIFIC ScriptsEz Easy Image Downloader id File Disclosure (emerging-web_sql_injection.rules)
 2008653 - ET WEB_SPECIFIC Built2go Real Estate Listings event_id SQL Injection (emerging-web_sql_injection.rules)
 2406029 - ET RBN Known Russian Business Network Monitored Domains (30) (emerging-rbn.rules)
 2406030 - ET RBN Known Russian Business Network Monitored Domains (31) (emerging-rbn.rules)
 2406031 - ET RBN Known Russian Business Network Monitored Domains (32) (emerging-rbn.rules)
 2407029 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) (emerging-rbn-BLOCK.rules)
 2407030 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) (emerging-rbn-BLOCK.rules)
 2407031 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (32) (emerging-rbn-BLOCK.rules)


[///]     Modified active rules:     [///]

 2001980 - ET POLICY SSH Client Banner Detected on Unusual Port (emerging-policy.rules)
 2002916 - ET EXPLOIT RealVNC Authentication Bypass Attempt (emerging-exploit.rules)
 2003466 - ET WEB PHP Attack Tool Morfeus F Scanner (emerging-web.rules)
 2008415 - ET SCAN Cisco Torch IOS HTTP Scan (emerging-scan.rules)
 2008564 - ET MALWARE Suspicious User-Agent (Internet HTTP Request) (emerging-malware.rules)
 2400000 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400001 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400002 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400003 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400004 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400005 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400006 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400007 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2401000 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401001 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401002 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401003 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401004 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401005 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401006 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401007 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2402000 - ET DROP Dshield Block Listed Source (emerging-dshield.rules)
 2403000 - ET DROP Dshield Block Listed Source - BLOCKING (emerging-dshield-BLOCK.rules)
 2404000 - ET DROP Known Bot C&C Server Traffic (group 1)  (emerging-botcc.rules)
 2404001 - ET DROP Known Bot C&C Server Traffic (group 2)  (emerging-botcc.rules)
 2404002 - ET DROP Known Bot C&C Server Traffic (group 3)  (emerging-botcc.rules)
 2404003 - ET DROP Known Bot C&C Server Traffic (group 4)  (emerging-botcc.rules)
 2404004 - ET DROP Known Bot C&C Server Traffic (group 5)  (emerging-botcc.rules)
 2404005 - ET DROP Known Bot C&C Server Traffic (group 6)  (emerging-botcc.rules)
 2404006 - ET DROP Known Bot C&C Server Traffic (group 7)  (emerging-botcc.rules)
 2404007 - ET DROP Known Bot C&C Server Traffic (group 8)  (emerging-botcc.rules)
 2404008 - ET DROP Known Bot C&C Server Traffic (group 9)  (emerging-botcc.rules)
 2404009 - ET DROP Known Bot C&C Server Traffic (group 10)  (emerging-botcc.rules)
 2404010 - ET DROP Known Bot C&C Server Traffic (group 11)  (emerging-botcc.rules)
 2404011 - ET DROP Known Bot C&C Server Traffic (group 12)  (emerging-botcc.rules)
 2404012 - ET DROP Known Bot C&C Server Traffic (group 13)  (emerging-botcc.rules)
 2404013 - ET DROP Known Bot C&C Server Traffic (group 14)  (emerging-botcc.rules)
 2404014 - ET DROP Known Bot C&C Server Traffic (group 15)  (emerging-botcc.rules)
 2404015 - ET DROP Known Bot C&C Server Traffic (group 16)  (emerging-botcc.rules)
 2404016 - ET DROP Known Bot C&C Server Traffic (group 17)  (emerging-botcc.rules)
 2404017 - ET DROP Known Bot C&C Server Traffic (group 18)  (emerging-botcc.rules)
 2404018 - ET DROP Known Bot C&C Server Traffic (group 19)  (emerging-botcc.rules)
 2404019 - ET DROP Known Bot C&C Server Traffic (group 20)  (emerging-botcc.rules)
 2405000 - ET DROP Known Bot C&C Traffic (group 1) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405001 - ET DROP Known Bot C&C Traffic (group 2) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405002 - ET DROP Known Bot C&C Traffic (group 3) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405003 - ET DROP Known Bot C&C Traffic (group 4) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405004 - ET DROP Known Bot C&C Traffic (group 5) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405005 - ET DROP Known Bot C&C Traffic (group 6) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405006 - ET DROP Known Bot C&C Traffic (group 7) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405007 - ET DROP Known Bot C&C Traffic (group 8) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405008 - ET DROP Known Bot C&C Traffic (group 9) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405009 - ET DROP Known Bot C&C Traffic (group 10) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405010 - ET DROP Known Bot C&C Traffic (group 11) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405011 - ET DROP Known Bot C&C Traffic (group 12) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405012 - ET DROP Known Bot C&C Traffic (group 13) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405013 - ET DROP Known Bot C&C Traffic (group 14) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405014 - ET DROP Known Bot C&C Traffic (group 15) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405015 - ET DROP Known Bot C&C Traffic (group 16) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405016 - ET DROP Known Bot C&C Traffic (group 17) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405017 - ET DROP Known Bot C&C Traffic (group 18) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405018 - ET DROP Known Bot C&C Traffic (group 19) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405019 - ET DROP Known Bot C&C Traffic (group 20) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2406000 - ET RBN Known Russian Business Network Monitored Domains (1) (emerging-rbn.rules)
 2406001 - ET RBN Known Russian Business Network Monitored Domains (2) (emerging-rbn.rules)
 2406002 - ET RBN Known Russian Business Network Monitored Domains (3) (emerging-rbn.rules)
 2406003 - ET RBN Known Russian Business Network Monitored Domains (4) (emerging-rbn.rules)
 2406004 - ET RBN Known Russian Business Network Monitored Domains (5) (emerging-rbn.rules)
 2406005 - ET RBN Known Russian Business Network Monitored Domains (6) (emerging-rbn.rules)
 2406006 - ET RBN Known Russian Business Network Monitored Domains (7) (emerging-rbn.rules)
 2406007 - ET RBN Known Russian Business Network Monitored Domains (8) (emerging-rbn.rules)
 2406008 - ET RBN Known Russian Business Network Monitored Domains (9) (emerging-rbn.rules)
 2406009 - ET RBN Known Russian Business Network Monitored Domains (10) (emerging-rbn.rules)
 2406010 - ET RBN Known Russian Business Network Monitored Domains (11) (emerging-rbn.rules)
 2406011 - ET RBN Known Russian Business Network Monitored Domains (12) (emerging-rbn.rules)
 2406012 - ET RBN Known Russian Business Network Monitored Domains (13) (emerging-rbn.rules)
 2406013 - ET RBN Known Russian Business Network Monitored Domains (14) (emerging-rbn.rules)
 2406014 - ET RBN Known Russian Business Network Monitored Domains (15) (emerging-rbn.rules)
 2406015 - ET RBN Known Russian Business Network Monitored Domains (16) (emerging-rbn.rules)
 2406016 - ET RBN Known Russian Business Network Monitored Domains (17) (emerging-rbn.rules)
 2406017 - ET RBN Known Russian Business Network Monitored Domains (18) (emerging-rbn.rules)
 2406018 - ET RBN Known Russian Business Network Monitored Domains (19) (emerging-rbn.rules)
 2406019 - ET RBN Known Russian Business Network Monitored Domains (20) (emerging-rbn.rules)
 2406020 - ET RBN Known Russian Business Network Monitored Domains (21) (emerging-rbn.rules)
 2406021 - ET RBN Known Russian Business Network Monitored Domains (22) (emerging-rbn.rules)
 2406022 - ET RBN Known Russian Business Network Monitored Domains (23) (emerging-rbn.rules)
 2406023 - ET RBN Known Russian Business Network Monitored Domains (24) (emerging-rbn.rules)
 2406024 - ET RBN Known Russian Business Network Monitored Domains (25) (emerging-rbn.rules)
 2406025 - ET RBN Known Russian Business Network Monitored Domains (26) (emerging-rbn.rules)
 2406026 - ET RBN Known Russian Business Network Monitored Domains (27) (emerging-rbn.rules)
 2406027 - ET RBN Known Russian Business Network Monitored Domains (28) (emerging-rbn.rules)
 2406028 - ET RBN Known Russian Business Network Monitored Domains (29) (emerging-rbn.rules)
 2407000 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) (emerging-rbn-BLOCK.rules)
 2407001 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) (emerging-rbn-BLOCK.rules)
 2407002 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) (emerging-rbn-BLOCK.rules)
 2407003 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) (emerging-rbn-BLOCK.rules)
 2407004 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) (emerging-rbn-BLOCK.rules)
 2407005 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) (emerging-rbn-BLOCK.rules)
 2407006 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) (emerging-rbn-BLOCK.rules)
 2407007 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) (emerging-rbn-BLOCK.rules)
 2407008 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) (emerging-rbn-BLOCK.rules)
 2407009 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) (emerging-rbn-BLOCK.rules)
 2407010 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) (emerging-rbn-BLOCK.rules)
 2407011 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) (emerging-rbn-BLOCK.rules)
 2407012 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) (emerging-rbn-BLOCK.rules)
 2407013 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) (emerging-rbn-BLOCK.rules)
 2407014 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) (emerging-rbn-BLOCK.rules)
 2407015 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) (emerging-rbn-BLOCK.rules)
 2407016 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) (emerging-rbn-BLOCK.rules)
 2407017 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) (emerging-rbn-BLOCK.rules)
 2407018 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) (emerging-rbn-BLOCK.rules)
 2407019 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) (emerging-rbn-BLOCK.rules)
 2407020 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) (emerging-rbn-BLOCK.rules)
 2407021 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) (emerging-rbn-BLOCK.rules)
 2407022 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) (emerging-rbn-BLOCK.rules)
 2407023 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) (emerging-rbn-BLOCK.rules)
 2407024 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) (emerging-rbn-BLOCK.rules)
 2407025 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) (emerging-rbn-BLOCK.rules)
 2407026 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) (emerging-rbn-BLOCK.rules)
 2407027 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) (emerging-rbn-BLOCK.rules)
 2407028 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) (emerging-rbn-BLOCK.rules)


[---]         Removed rules:         [---]

 2008546 - ET CURRENT_EVENTS Unknown Downloader Checkin part 1 of 2 (emerging.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to emerging-dos.rules (1):
        #by Stillsecure (stillsecure.com)

     -> Added to emerging-drop-BLOCK.rules (2):
        #  VERSION 1323
        #  Generated 2008-10-11 00:03:02 EDT

     -> Added to emerging-drop.rules (2):
        #  VERSION 1323
        #  Generated 2008-10-11 00:03:02 EDT

     -> Added to emerging-exploit.rules (2):
        #by Stillsecure (stillsecure.com)
        #by Stillsecure (www.stillsecure.com)

     -> Added to emerging-p2p.rules (1):
        #by dxp

     -> Added to emerging-rbn-BLOCK.rules (2):
        #  VERSION 80
        #  Updated 2008-10-08 09:28:13

     -> Added to emerging-rbn.rules (2):
        #  VERSION 80
        #  Updated 2008-10-08 09:28:13

     -> Added to emerging-sid-msg.map (35):
        2002916 || ET EXPLOIT RealVNC Authentication Bypass Attempt || cve,2006-2369 || url,archives.neohapsis.com/archives/fulldisclosure/2006-05/0356.html || url,secunia.com/advisories/20107/
        2008546 || ET TROJAN Downloader.vr Checkin part 1 of 2
        2008618 || ET DOS IAS Helper COM Component iashlpr.dll activex remote DOS || url,securityreason.com/securityalert/4323 || cve,2008-2639 || url,www.securityfocus.com/archive/1/archive/1/496695/100/0/threaded
        2008619 || ET EXPLOIT Novell ZENWorks for Desktops Remote Heap-Based Buffer Overflow || url,securitytracker.com/alerts/2008/Sep/1020951.html || bugtraq,31435
        2008620 || ET EXPLOIT Internet Information Service iisext.dll activex setpassword Insecure Method || url,www.securityfocus.com/archive/1/archive/1/496694/100/0/threaded || cve,2008-4301
        2008621 || ET EXPLOIT Internet Information Service adsiis.dll activex remote DOS || url,securityreason.com/securityalert/4325 || cve,2008-4300
        2008622 || ET WEB Pritlog index.php filename File Disclosure || url,www.milw0rm.com/exploits/6613 || url,secunia.com/Advisories/31969/
        2008623 || ET TROJAN Cinmus.Checkin 1
        2008624 || ET TROJAN Cinmus.Checkin 2
        2008625 || ET P2P Pando Client User-Agent Detected (Mozilla/4.0 (Windows\; U) Pando/1.xx)
        2008626 || ET TROJAN PlayMP3z.biz Related Spyware/Trojan Install Report
        2008627 || ET SCAN Httprecon Web Server Fingerprint Scan || url,www.computec.ch/projekte/httprecon/
        2008628 || ET SCAN WSFuzzer Web Application Fuzzing || url,www.owasp.org/index.php/Category\:OWASP_WSFuzzer_Project
        2008629 || ET SCAN Wikto Backend Data Miner Scan || url,www.sensepost.com/research/wikto/WiktoDoc1-51.htm
        2008639 || ET TROJAN Tibs Trojan Downloader
        2008640 || ET SCAN SIP erase_registrations/add registrations attempt || url,www.hackingvoip.com/sec_tools.html
        2008641 || ET SCAN sipscan probe || url,www.hackingvoip.com/sec_tools.html
        2008642 || ET TROJAN Keylogger PRO GOLD Post
        2008643 || ET MALWARE Suspicious User-Agent Detected (Downloader1.2)
        2008644 || ET TROJAN Spy-Net Trojan Connection
        2008645 || ET TROJAN Spy-Net Trojan Connection (2)
        2008646 || ET CURRENT_EVENTS Trojan resulting from Fake MS Updates Email Login to CnC || url,isc.sans.org/diary.html?storyid=5159
        2008647 || ET MALWARE Internet-antivirus.com Related Fake AV User-Agent Detected (Update Internet Antivirus)
        2008648 || ET WEB_SPECIFIC trac q variable open redirect || url,cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2951
        2008649 || ET WEB_SPECIFIC Realtor v_cat SQL Injection || url,secunia.com/advisories/32149/ || url,www.milw0rm.com/exploits/6694
        2008650 || ET WEB_SPECIFIC Autos catid SQL Injection || url,secunia.com/advisories/32139/ || url,www.milw0rm.com/exploits/6696
        2008651 || ET WEB_SPECIFIC JMweb MP3 src Multiple Local File Inclusion || url,www.milw0rm.com/exploits/6669
        2008652 || ET WEB_SPECIFIC ScriptsEz Easy Image Downloader id File Disclosure || url,secunia.com/Advisories/32210/ || url,www.milw0rm.com/exploits/6715
        2008653 || ET WEB_SPECIFIC Built2go Real Estate Listings event_id SQL Injection || url,secunia.com/Advisories/32129/ || url,www.milw0rm.com/exploits/6697
        2406029 || ET RBN Known Russian Business Network Monitored Domains (30) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406030 || ET RBN Known Russian Business Network Monitored Domains (31) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406031 || ET RBN Known Russian Business Network Monitored Domains (32) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407029 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407030 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407031 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (32) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork

     -> Added to emerging-sid-msg.map.txt (35):
        2002916 || ET EXPLOIT RealVNC Authentication Bypass Attempt || cve,2006-2369 || url,archives.neohapsis.com/archives/fulldisclosure/2006-05/0356.html || url,secunia.com/advisories/20107/
        2008546 || ET TROJAN Downloader.vr Checkin part 1 of 2
        2008618 || ET DOS IAS Helper COM Component iashlpr.dll activex remote DOS || url,securityreason.com/securityalert/4323 || cve,2008-2639 || url,www.securityfocus.com/archive/1/archive/1/496695/100/0/threaded
        2008619 || ET EXPLOIT Novell ZENWorks for Desktops Remote Heap-Based Buffer Overflow || url,securitytracker.com/alerts/2008/Sep/1020951.html || bugtraq,31435
        2008620 || ET EXPLOIT Internet Information Service iisext.dll activex setpassword Insecure Method || url,www.securityfocus.com/archive/1/archive/1/496694/100/0/threaded || cve,2008-4301
        2008621 || ET EXPLOIT Internet Information Service adsiis.dll activex remote DOS || url,securityreason.com/securityalert/4325 || cve,2008-4300
        2008622 || ET WEB Pritlog index.php filename File Disclosure || url,www.milw0rm.com/exploits/6613 || url,secunia.com/Advisories/31969/
        2008623 || ET TROJAN Cinmus.Checkin 1
        2008624 || ET TROJAN Cinmus.Checkin 2
        2008625 || ET P2P Pando Client User-Agent Detected (Mozilla/4.0 (Windows\; U) Pando/1.xx)
        2008626 || ET TROJAN PlayMP3z.biz Related Spyware/Trojan Install Report
        2008627 || ET SCAN Httprecon Web Server Fingerprint Scan || url,www.computec.ch/projekte/httprecon/
        2008628 || ET SCAN WSFuzzer Web Application Fuzzing || url,www.owasp.org/index.php/Category\:OWASP_WSFuzzer_Project
        2008629 || ET SCAN Wikto Backend Data Miner Scan || url,www.sensepost.com/research/wikto/WiktoDoc1-51.htm
        2008639 || ET TROJAN Tibs Trojan Downloader
        2008640 || ET SCAN SIP erase_registrations/add registrations attempt || url,www.hackingvoip.com/sec_tools.html
        2008641 || ET SCAN sipscan probe || url,www.hackingvoip.com/sec_tools.html
        2008642 || ET TROJAN Keylogger PRO GOLD Post
        2008643 || ET MALWARE Suspicious User-Agent Detected (Downloader1.2)
        2008644 || ET TROJAN Spy-Net Trojan Connection
        2008645 || ET TROJAN Spy-Net Trojan Connection (2)
        2008646 || ET CURRENT_EVENTS Trojan resulting from Fake MS Updates Email Login to CnC || url,isc.sans.org/diary.html?storyid=5159
        2008647 || ET MALWARE Internet-antivirus.com Related Fake AV User-Agent Detected (Update Internet Antivirus)
        2008648 || ET WEB_SPECIFIC trac q variable open redirect || url,cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2951
        2008649 || ET WEB_SPECIFIC Realtor v_cat SQL Injection || url,secunia.com/advisories/32149/ || url,www.milw0rm.com/exploits/6694
        2008650 || ET WEB_SPECIFIC Autos catid SQL Injection || url,secunia.com/advisories/32139/ || url,www.milw0rm.com/exploits/6696
        2008651 || ET WEB_SPECIFIC JMweb MP3 src Multiple Local File Inclusion || url,www.milw0rm.com/exploits/6669
        2008652 || ET WEB_SPECIFIC ScriptsEz Easy Image Downloader id File Disclosure || url,secunia.com/Advisories/32210/ || url,www.milw0rm.com/exploits/6715
        2008653 || ET WEB_SPECIFIC Built2go Real Estate Listings event_id SQL Injection || url,secunia.com/Advisories/32129/ || url,www.milw0rm.com/exploits/6697
        2406029 || ET RBN Known Russian Business Network Monitored Domains (30) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406030 || ET RBN Known Russian Business Network Monitored Domains (31) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406031 || ET RBN Known Russian Business Network Monitored Domains (32) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407029 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407030 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407031 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (32) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork

     -> Added to emerging-virus.rules (5):
        #Sig by Daniel Clemens
        #ref: 13bce3215f758d69a6574f7018ed8c32
        #This one is lets the client know the server is connected and ready
        #by jeremy conway
        #ref: 61441e5fab0173480c05f876e5ebd07b

     -> Added to emerging-voip.rules (2):
        #by Kevin Ross
        #by Kevin Ross

     -> Added to emerging-web.rules (1):
        #by Stillsecure (stillsecure.com)

     -> Added to emerging-web_sql_injection.rules (1):
        #by Russ McRee

     -> Added to emerging.rules (1):
        # fake email for MS Updates results in a trojan that uses this fake UA

[---]     Removed non-rule lines:    [---]

     -> Removed from emerging-drop-BLOCK.rules (2):
        #  VERSION 1316
        #  Generated 2008-10-04 00:03:02 EDT

     -> Removed from emerging-drop.rules (2):
        #  VERSION 1316
        #  Generated 2008-10-04 00:03:02 EDT

     -> Removed from emerging-rbn-BLOCK.rules (2):
        #  VERSION 77
        #  Updated 2008-10-01 18:23:28

     -> Removed from emerging-rbn.rules (2):
        #  VERSION 77
        #  Updated 2008-10-01 18:23:28

     -> Removed from emerging-sid-msg.map (20):
        2002916 || ET EXPLOIT RealVNC Authentication Bypass Attempt || cve,2006-2369 || url,www.cl.cam.ac.uk/Research/DTG/attarchive/vnc/rfbproto.pdf || url,archives.neohapsis.com/archives/fulldisclosure/2006-05/0356.html || url,secunia.com/advisories/20107/
        2008546 || ET CURRENT_EVENTS Unknown Downloader Checkin part 1 of 2
        2500067 || ET COMPROMISED Known Compromised or Hostile Host Traffic (68) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500068 || ET COMPROMISED Known Compromised or Hostile Host Traffic (69) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500069 || ET COMPROMISED Known Compromised or Hostile Host Traffic (70) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500070 || ET COMPROMISED Known Compromised or Hostile Host Traffic (71) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500071 || ET COMPROMISED Known Compromised or Hostile Host Traffic (72) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500072 || ET COMPROMISED Known Compromised or Hostile Host Traffic (73) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500073 || ET COMPROMISED Known Compromised or Hostile Host Traffic (74) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500074 || ET COMPROMISED Known Compromised or Hostile Host Traffic (75) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500075 || ET COMPROMISED Known Compromised or Hostile Host Traffic (76) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510067 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (68) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510068 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (69) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510069 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (70) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510070 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (71) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510071 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (72) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510072 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (73) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510073 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (74) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510074 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (75) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510075 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (76) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts

     -> Removed from emerging-sid-msg.map.txt (20):
        2002916 || ET EXPLOIT RealVNC Authentication Bypass Attempt || cve,2006-2369 || url,www.cl.cam.ac.uk/Research/DTG/attarchive/vnc/rfbproto.pdf || url,archives.neohapsis.com/archives/fulldisclosure/2006-05/0356.html || url,secunia.com/advisories/20107/
        2008546 || ET CURRENT_EVENTS Unknown Downloader Checkin part 1 of 2
        2500067 || ET COMPROMISED Known Compromised or Hostile Host Traffic (68) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500068 || ET COMPROMISED Known Compromised or Hostile Host Traffic (69) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500069 || ET COMPROMISED Known Compromised or Hostile Host Traffic (70) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500070 || ET COMPROMISED Known Compromised or Hostile Host Traffic (71) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500071 || ET COMPROMISED Known Compromised or Hostile Host Traffic (72) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500072 || ET COMPROMISED Known Compromised or Hostile Host Traffic (73) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500073 || ET COMPROMISED Known Compromised or Hostile Host Traffic (74) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500074 || ET COMPROMISED Known Compromised or Hostile Host Traffic (75) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2500075 || ET COMPROMISED Known Compromised or Hostile Host Traffic (76) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510067 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (68) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510068 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (69) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510069 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (70) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510070 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (71) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510071 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (72) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510072 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (73) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510073 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (74) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510074 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (75) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts
        2510075 || ET COMPROMISED Known Compromised or Hostile Host Traffic - BLOCKING (76) || url,doc.emergingthreats.net/bin/view/Main/CompromisedHosts

     -> Removed from emerging.rules (1):
        #another unknown, soo to be IDd. Sig by Daniel Clemens





More information about the Snort-sigs mailing list