[Emerging-Sigs] Emerging Threats Weekly Signature Changes
emerging@emergingthreats.net
emerging at emergingthreats.net
Sat Apr 19 19:00:08 EDT 2008
[***] Results from Oinkmaster started Sat Apr 19 19:00:08 2008 [***]
[+++] Added rules: [+++]
2008130 - ET TROJAN Win32.Lydra.hj HTTP Checkin (bleeding-virus.rules)
2008131 - ET MALWARE Vaccinespy.com Fake AV Uaer Agent (GLOBALx) (bleeding-malware.rules)
2008132 - ET TROJAN Common Downloader Access Count Tracking URL (bleeding-virus.rules)
2008133 - ET TROJAN Common Downloader Install Count Tracking URL (bleeding-virus.rules)
2008134 - ET TROJAN Common Downloader Install Count Tracking URL (partner) (bleeding-virus.rules)
2008135 - ET MALWARE Soft-Show.cn Related Fake AV Install (bleeding-malware.rules)
2008136 - ET TROJAN Egspy Install Report via HTTP (bleeding-virus.rules)
2008137 - ET CURRENT_EVENTS Domain Related to Phishing GDI Exploits MS08-021 igloofamily.com (bleeding.rules)
2008138 - ET CURRENT_EVENTS Domain Related to Phishing GDI Exploits MS08-021 amrc.com.tw (bleeding.rules)
2008139 - ET CURRENT_EVENTS RhiFrem Trojan Activity - cmd (bleeding.rules)
2008140 - ET CURRENT_EVENTS RhiFrem Trojan Activity - log (bleeding.rules)
2008141 - ET MALWARE Win-touch.com Spyware User Agent (WinTouch) (bleeding-malware.rules)
2008142 - ET MALWARE Vapsup User-Agent (doshowmeanad loader v2.1) (bleeding-virus.rules)
2008143 - ET TROJAN Downloader Checkin Pattern Used by Several Trojans (bleeding-virus.rules)
2008144 - ET TROJAN Proxy.Corpes.j Infection Report (bleeding-virus.rules)
2008145 - ET MALWARE Speed-runner.com Fake Speed Test User-Agent (SRInstaller) (bleeding-malware.rules)
2008146 - ET MALWARE Speed-runner.com Fake Speed Test User-Agent (SpeedRunner) (bleeding-malware.rules)
2008147 - ET MALWARE Suspicious User-Agent (RBR) (bleeding-malware.rules)
2008148 - ET MALWARE Soft-Show.cn Related Fake AV Install Ad Pull (bleeding-malware.rules)
[///] Modified active rules: [///]
2005320 - ET MALWARE Suspicious User-Agent (MyAgent) (bleeding-malware.rules)
2008121 - ET CURRENT_EVENTS Bobax Spam Inbound (Unique Faked Message-Id) (bleeding.rules)
2008122 - ET CURRENT_EVENTS Bobax Spam Inbound (Unique Faked Message-Id) (bleeding.rules)
2008125 - ET CURRENT_EVENTS Bobax Spam Inbound (Unique Faked Message-ID and no brackets) (bleeding.rules)
2400000 - ET DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
2400001 - ET DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
2400002 - ET DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
2400003 - ET DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
2400004 - ET DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
2401000 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
2401001 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
2401002 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
2401003 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
2401004 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
2402000 - ET DROP Dshield Block Listed Source (bleeding-dshield.rules)
2403000 - ET DROP Dshield Block Listed Source - BLOCKING (bleeding-dshield-BLOCK.rules)
2404000 - ET DROP Known Bot C&C Server Traffic (group 1) (bleeding-botcc.rules)
2404001 - ET DROP Known Bot C&C Server Traffic (group 2) (bleeding-botcc.rules)
2404002 - ET DROP Known Bot C&C Server Traffic (group 3) (bleeding-botcc.rules)
2404003 - ET DROP Known Bot C&C Server Traffic (group 4) (bleeding-botcc.rules)
2404004 - ET DROP Known Bot C&C Server Traffic (group 5) (bleeding-botcc.rules)
2404005 - ET DROP Known Bot C&C Server Traffic (group 6) (bleeding-botcc.rules)
2404006 - ET DROP Known Bot C&C Server Traffic (group 7) (bleeding-botcc.rules)
2404007 - ET DROP Known Bot C&C Server Traffic (group 8) (bleeding-botcc.rules)
2404008 - ET DROP Known Bot C&C Server Traffic (group 9) (bleeding-botcc.rules)
2404009 - ET DROP Known Bot C&C Server Traffic (group 10) (bleeding-botcc.rules)
2404010 - ET DROP Known Bot C&C Server Traffic (group 11) (bleeding-botcc.rules)
2404011 - ET DROP Known Bot C&C Server Traffic (group 12) (bleeding-botcc.rules)
2404012 - ET DROP Known Bot C&C Server Traffic (group 13) (bleeding-botcc.rules)
2404013 - ET DROP Known Bot C&C Server Traffic (group 14) (bleeding-botcc.rules)
2404014 - ET DROP Known Bot C&C Server Traffic (group 15) (bleeding-botcc.rules)
2404015 - ET DROP Known Bot C&C Server Traffic (group 16) (bleeding-botcc.rules)
2405000 - ET DROP Known Bot C&C Traffic (group 1) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405001 - ET DROP Known Bot C&C Traffic (group 2) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405002 - ET DROP Known Bot C&C Traffic (group 3) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405003 - ET DROP Known Bot C&C Traffic (group 4) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405004 - ET DROP Known Bot C&C Traffic (group 5) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405005 - ET DROP Known Bot C&C Traffic (group 6) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405006 - ET DROP Known Bot C&C Traffic (group 7) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405007 - ET DROP Known Bot C&C Traffic (group 8) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405008 - ET DROP Known Bot C&C Traffic (group 9) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405009 - ET DROP Known Bot C&C Traffic (group 10) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405010 - ET DROP Known Bot C&C Traffic (group 11) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405011 - ET DROP Known Bot C&C Traffic (group 12) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405012 - ET DROP Known Bot C&C Traffic (group 13) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405013 - ET DROP Known Bot C&C Traffic (group 14) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405014 - ET DROP Known Bot C&C Traffic (group 15) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405015 - ET DROP Known Bot C&C Traffic (group 16) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2406005 - ET RBN Known Russian Business Network Monitored Domains (1) (bleeding-rbn.rules)
2406006 - ET RBN Known Russian Business Network Monitored Domains (2) (bleeding-rbn.rules)
2406007 - ET RBN Known Russian Business Network Monitored Domains (3) (bleeding-rbn.rules)
2406008 - ET RBN Known Russian Business Network Monitored Domains (4) (bleeding-rbn.rules)
2406009 - ET RBN Known Russian Business Network Monitored Domains (5) (bleeding-rbn.rules)
2406010 - ET RBN Known Russian Business Network Monitored Domains (6) (bleeding-rbn.rules)
2406011 - ET RBN Known Russian Business Network Monitored Domains (7) (bleeding-rbn.rules)
2406012 - ET RBN Known Russian Business Network Monitored Domains (8) (bleeding-rbn.rules)
2406013 - ET RBN Known Russian Business Network Monitored Domains (9) (bleeding-rbn.rules)
2406014 - ET RBN Known Russian Business Network Monitored Domains (10) (bleeding-rbn.rules)
2406015 - ET RBN Known Russian Business Network Monitored Domains (11) (bleeding-rbn.rules)
2406016 - ET RBN Known Russian Business Network Monitored Domains (12) (bleeding-rbn.rules)
2406017 - ET RBN Known Russian Business Network Monitored Domains (13) (bleeding-rbn.rules)
2406018 - ET RBN Known Russian Business Network Monitored Domains (14) (bleeding-rbn.rules)
2406019 - ET RBN Known Russian Business Network Monitored Domains (15) (bleeding-rbn.rules)
2406020 - ET RBN Known Russian Business Network Monitored Domains (16) (bleeding-rbn.rules)
2406021 - ET RBN Known Russian Business Network Monitored Domains (17) (bleeding-rbn.rules)
2406022 - ET RBN Known Russian Business Network Monitored Domains (18) (bleeding-rbn.rules)
2406023 - ET RBN Known Russian Business Network Monitored Domains (19) (bleeding-rbn.rules)
2406024 - ET RBN Known Russian Business Network Monitored Domains (20) (bleeding-rbn.rules)
2406025 - ET RBN Known Russian Business Network Monitored Domains (21) (bleeding-rbn.rules)
2406026 - ET RBN Known Russian Business Network Monitored Domains (22) (bleeding-rbn.rules)
2406027 - ET RBN Known Russian Business Network Monitored Domains (23) (bleeding-rbn.rules)
2406028 - ET RBN Known Russian Business Network Monitored Domains (24) (bleeding-rbn.rules)
2406029 - ET RBN Known Russian Business Network Monitored Domains (25) (bleeding-rbn.rules)
2406030 - ET RBN Known Russian Business Network Monitored Domains (26) (bleeding-rbn.rules)
2406031 - ET RBN Known Russian Business Network Monitored Domains (27) (bleeding-rbn.rules)
2406032 - ET RBN Known Russian Business Network Monitored Domains (28) (bleeding-rbn.rules)
2406033 - ET RBN Known Russian Business Network Monitored Domains (29) (bleeding-rbn.rules)
2406034 - ET RBN Known Russian Business Network Monitored Domains (30) (bleeding-rbn.rules)
2406035 - ET RBN Known Russian Business Network Monitored Domains (31) (bleeding-rbn.rules)
2406036 - ET RBN Known Russian Business Network Monitored Domains (32) (bleeding-rbn.rules)
2406037 - ET RBN Known Russian Business Network Monitored Domains (33) (bleeding-rbn.rules)
2407005 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) (bleeding-rbn-BLOCK.rules)
2407006 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) (bleeding-rbn-BLOCK.rules)
2407007 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) (bleeding-rbn-BLOCK.rules)
2407008 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) (bleeding-rbn-BLOCK.rules)
2407009 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) (bleeding-rbn-BLOCK.rules)
2407010 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) (bleeding-rbn-BLOCK.rules)
2407011 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) (bleeding-rbn-BLOCK.rules)
2407012 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) (bleeding-rbn-BLOCK.rules)
2407013 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) (bleeding-rbn-BLOCK.rules)
2407014 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) (bleeding-rbn-BLOCK.rules)
2407015 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) (bleeding-rbn-BLOCK.rules)
2407016 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) (bleeding-rbn-BLOCK.rules)
2407017 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) (bleeding-rbn-BLOCK.rules)
2407018 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) (bleeding-rbn-BLOCK.rules)
2407019 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) (bleeding-rbn-BLOCK.rules)
2407020 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) (bleeding-rbn-BLOCK.rules)
2407021 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) (bleeding-rbn-BLOCK.rules)
2407022 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) (bleeding-rbn-BLOCK.rules)
2407023 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) (bleeding-rbn-BLOCK.rules)
2407024 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) (bleeding-rbn-BLOCK.rules)
2407025 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) (bleeding-rbn-BLOCK.rules)
2407026 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) (bleeding-rbn-BLOCK.rules)
2407027 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) (bleeding-rbn-BLOCK.rules)
2407028 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) (bleeding-rbn-BLOCK.rules)
2407029 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) (bleeding-rbn-BLOCK.rules)
2407030 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) (bleeding-rbn-BLOCK.rules)
2407031 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) (bleeding-rbn-BLOCK.rules)
2407032 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) (bleeding-rbn-BLOCK.rules)
2407033 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) (bleeding-rbn-BLOCK.rules)
2407034 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) (bleeding-rbn-BLOCK.rules)
2407035 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) (bleeding-rbn-BLOCK.rules)
2407036 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (32) (bleeding-rbn-BLOCK.rules)
2407037 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (33) (bleeding-rbn-BLOCK.rules)
[---] Removed rules: [---]
2003212 - ET EXPLOIT Microsoft Office Data Structure Corruption (unpatched) (bleeding-exploit.rules)
2003643 - ET TROJAN Win32.Small.mi User-Agent Detected (MyAgent) (bleeding-virus.rules)
2404016 - ET DROP Known Bot C&C Server Traffic (group 17) (bleeding-botcc.rules)
2404017 - ET DROP Known Bot C&C Server Traffic (group 18) (bleeding-botcc.rules)
2404018 - ET DROP Known Bot C&C Server Traffic (group 19) (bleeding-botcc.rules)
2404019 - ET DROP Known Bot C&C Server Traffic (group 20) (bleeding-botcc.rules)
2404020 - ET DROP Known Bot C&C Server Traffic (group 21) (bleeding-botcc.rules)
2405016 - ET DROP Known Bot C&C Traffic (group 17) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405017 - ET DROP Known Bot C&C Traffic (group 18) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405018 - ET DROP Known Bot C&C Traffic (group 19) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405019 - ET DROP Known Bot C&C Traffic (group 20) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
2405020 - ET DROP Known Bot C&C Traffic (group 21) - BLOCKING SOURCE (bleeding-botcc-BLOCK.rules)
[+++] Added non-rule lines: [+++]
-> Added to bleeding-attack_response.rules (1):
# $Id: bleeding-attack_response.rules $
-> Added to bleeding-dos.rules (1):
# $Id: bleeding-dos.rules $
-> Added to bleeding-drop-BLOCK.rules (2):
# VERSION 1133
# Generated 2008-04-13 01:03:03 EDT
-> Added to bleeding-drop.rules (2):
# VERSION 1133
# Generated 2008-04-13 01:03:03 EDT
-> Added to bleeding-exploit.rules (1):
# $Id: bleeding-exploit.rules $
-> Added to bleeding-game.rules (1):
# $Id: bleeding-game.rules $
-> Added to bleeding-inappropriate.rules (1):
# $Id: bleeding-inappropriate.rules $
-> Added to bleeding-malware.rules (2):
# $Id: bleeding-malware.rules $
#matt jonkman
-> Added to bleeding-p2p.rules (1):
# $Id: bleeding-p2p.rules $
-> Added to bleeding-policy.rules (1):
# $Id: bleeding-policy.rules $
-> Added to bleeding-rbn-BLOCK.rules (2):
# VERSION 41
# Updated 2008-04-13 22:59:51
-> Added to bleeding-rbn.rules (2):
# VERSION 41
# Updated 2008-04-13 22:59:51
-> Added to bleeding-scan.rules (1):
# $Id: bleeding-scan.rules $
-> Added to bleeding-sid-msg.map (86):
2005320 || ET MALWARE Suspicious User-Agent (MyAgent)
2008130 || ET TROJAN Win32.Lydra.hj HTTP Checkin
2008131 || ET MALWARE Vaccinespy.com Fake AV Uaer Agent (GLOBALx)
2008132 || ET TROJAN Common Downloader Access Count Tracking URL
2008133 || ET TROJAN Common Downloader Install Count Tracking URL
2008134 || ET TROJAN Common Downloader Install Count Tracking URL (partner)
2008135 || ET MALWARE Soft-Show.cn Related Fake AV Install
2008136 || ET TROJAN Egspy Install Report via HTTP
2008137 || ET CURRENT_EVENTS Domain Related to Phishing GDI Exploits MS08-021 igloofamily.com || url,isc.sans.org/diary.html?storyid=4274
2008138 || ET CURRENT_EVENTS Domain Related to Phishing GDI Exploits MS08-021 amrc.com.tw || url,isc.sans.org/diary.html?storyid=4274
2008139 || ET CURRENT_EVENTS RhiFrem Trojan Activity - cmd || url,www.castlecops.com/U_S_Courts_phish792683.html
2008140 || ET CURRENT_EVENTS RhiFrem Trojan Activity - log || url,www.castlecops.com/U_S_Courts_phish792683.html
2008141 || ET MALWARE Win-touch.com Spyware User Agent (WinTouch)
2008142 || ET MALWARE Vapsup User-Agent (doshowmeanad loader v2.1)
2008143 || ET TROJAN Downloader Checkin Pattern Used by Several Trojans
2008144 || ET TROJAN Proxy.Corpes.j Infection Report
2008145 || ET MALWARE Speed-runner.com Fake Speed Test User-Agent (SRInstaller)
2008146 || ET MALWARE Speed-runner.com Fake Speed Test User-Agent (SpeedRunner)
2008147 || ET MALWARE Suspicious User-Agent (RBR)
2008148 || ET MALWARE Soft-Show.cn Related Fake AV Install Ad Pull
2406005 || ET RBN Known Russian Business Network Monitored Domains (1) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406006 || ET RBN Known Russian Business Network Monitored Domains (2) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406007 || ET RBN Known Russian Business Network Monitored Domains (3) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406008 || ET RBN Known Russian Business Network Monitored Domains (4) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406009 || ET RBN Known Russian Business Network Monitored Domains (5) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406010 || ET RBN Known Russian Business Network Monitored Domains (6) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406011 || ET RBN Known Russian Business Network Monitored Domains (7) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406012 || ET RBN Known Russian Business Network Monitored Domains (8) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406013 || ET RBN Known Russian Business Network Monitored Domains (9) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406014 || ET RBN Known Russian Business Network Monitored Domains (10) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406015 || ET RBN Known Russian Business Network Monitored Domains (11) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406016 || ET RBN Known Russian Business Network Monitored Domains (12) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406017 || ET RBN Known Russian Business Network Monitored Domains (13) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406018 || ET RBN Known Russian Business Network Monitored Domains (14) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406019 || ET RBN Known Russian Business Network Monitored Domains (15) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406020 || ET RBN Known Russian Business Network Monitored Domains (16) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406021 || ET RBN Known Russian Business Network Monitored Domains (17) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406022 || ET RBN Known Russian Business Network Monitored Domains (18) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406023 || ET RBN Known Russian Business Network Monitored Domains (19) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406024 || ET RBN Known Russian Business Network Monitored Domains (20) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406025 || ET RBN Known Russian Business Network Monitored Domains (21) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406026 || ET RBN Known Russian Business Network Monitored Domains (22) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406027 || ET RBN Known Russian Business Network Monitored Domains (23) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406028 || ET RBN Known Russian Business Network Monitored Domains (24) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406029 || ET RBN Known Russian Business Network Monitored Domains (25) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406030 || ET RBN Known Russian Business Network Monitored Domains (26) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406031 || ET RBN Known Russian Business Network Monitored Domains (27) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406032 || ET RBN Known Russian Business Network Monitored Domains (28) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406033 || ET RBN Known Russian Business Network Monitored Domains (29) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406034 || ET RBN Known Russian Business Network Monitored Domains (30) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406035 || ET RBN Known Russian Business Network Monitored Domains (31) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406036 || ET RBN Known Russian Business Network Monitored Domains (32) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406037 || ET RBN Known Russian Business Network Monitored Domains (33) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407005 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407006 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407007 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407008 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407009 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407010 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407011 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407012 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407013 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407014 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407015 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407016 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407017 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407018 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407019 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407020 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407021 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407022 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407023 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407024 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407025 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407026 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407027 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407028 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407029 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407030 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407031 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407032 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407033 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407034 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407035 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407036 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (32) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407037 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (33) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
-> Added to bleeding-sid-msg.map.txt (86):
2005320 || ET MALWARE Suspicious User-Agent (MyAgent)
2008130 || ET TROJAN Win32.Lydra.hj HTTP Checkin
2008131 || ET MALWARE Vaccinespy.com Fake AV Uaer Agent (GLOBALx)
2008132 || ET TROJAN Common Downloader Access Count Tracking URL
2008133 || ET TROJAN Common Downloader Install Count Tracking URL
2008134 || ET TROJAN Common Downloader Install Count Tracking URL (partner)
2008135 || ET MALWARE Soft-Show.cn Related Fake AV Install
2008136 || ET TROJAN Egspy Install Report via HTTP
2008137 || ET CURRENT_EVENTS Domain Related to Phishing GDI Exploits MS08-021 igloofamily.com || url,isc.sans.org/diary.html?storyid=4274
2008138 || ET CURRENT_EVENTS Domain Related to Phishing GDI Exploits MS08-021 amrc.com.tw || url,isc.sans.org/diary.html?storyid=4274
2008139 || ET CURRENT_EVENTS RhiFrem Trojan Activity - cmd || url,www.castlecops.com/U_S_Courts_phish792683.html
2008140 || ET CURRENT_EVENTS RhiFrem Trojan Activity - log || url,www.castlecops.com/U_S_Courts_phish792683.html
2008141 || ET MALWARE Win-touch.com Spyware User Agent (WinTouch)
2008142 || ET MALWARE Vapsup User-Agent (doshowmeanad loader v2.1)
2008143 || ET TROJAN Downloader Checkin Pattern Used by Several Trojans
2008144 || ET TROJAN Proxy.Corpes.j Infection Report
2008145 || ET MALWARE Speed-runner.com Fake Speed Test User-Agent (SRInstaller)
2008146 || ET MALWARE Speed-runner.com Fake Speed Test User-Agent (SpeedRunner)
2008147 || ET MALWARE Suspicious User-Agent (RBR)
2008148 || ET MALWARE Soft-Show.cn Related Fake AV Install Ad Pull
2406005 || ET RBN Known Russian Business Network Monitored Domains (1) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406006 || ET RBN Known Russian Business Network Monitored Domains (2) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406007 || ET RBN Known Russian Business Network Monitored Domains (3) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406008 || ET RBN Known Russian Business Network Monitored Domains (4) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406009 || ET RBN Known Russian Business Network Monitored Domains (5) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406010 || ET RBN Known Russian Business Network Monitored Domains (6) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406011 || ET RBN Known Russian Business Network Monitored Domains (7) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406012 || ET RBN Known Russian Business Network Monitored Domains (8) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406013 || ET RBN Known Russian Business Network Monitored Domains (9) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406014 || ET RBN Known Russian Business Network Monitored Domains (10) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406015 || ET RBN Known Russian Business Network Monitored Domains (11) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406016 || ET RBN Known Russian Business Network Monitored Domains (12) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406017 || ET RBN Known Russian Business Network Monitored Domains (13) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406018 || ET RBN Known Russian Business Network Monitored Domains (14) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406019 || ET RBN Known Russian Business Network Monitored Domains (15) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406020 || ET RBN Known Russian Business Network Monitored Domains (16) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406021 || ET RBN Known Russian Business Network Monitored Domains (17) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406022 || ET RBN Known Russian Business Network Monitored Domains (18) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406023 || ET RBN Known Russian Business Network Monitored Domains (19) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406024 || ET RBN Known Russian Business Network Monitored Domains (20) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406025 || ET RBN Known Russian Business Network Monitored Domains (21) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406026 || ET RBN Known Russian Business Network Monitored Domains (22) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406027 || ET RBN Known Russian Business Network Monitored Domains (23) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406028 || ET RBN Known Russian Business Network Monitored Domains (24) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406029 || ET RBN Known Russian Business Network Monitored Domains (25) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406030 || ET RBN Known Russian Business Network Monitored Domains (26) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406031 || ET RBN Known Russian Business Network Monitored Domains (27) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406032 || ET RBN Known Russian Business Network Monitored Domains (28) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406033 || ET RBN Known Russian Business Network Monitored Domains (29) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406034 || ET RBN Known Russian Business Network Monitored Domains (30) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406035 || ET RBN Known Russian Business Network Monitored Domains (31) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406036 || ET RBN Known Russian Business Network Monitored Domains (32) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2406037 || ET RBN Known Russian Business Network Monitored Domains (33) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407005 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407006 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407007 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407008 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407009 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407010 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407011 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407012 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407013 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407014 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407015 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407016 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407017 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407018 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407019 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407020 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407021 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407022 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407023 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407024 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407025 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407026 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407027 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407028 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407029 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407030 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407031 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407032 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407033 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407034 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407035 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407036 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (32) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
2407037 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (33) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
-> Added to bleeding-virus.rules (2):
# $Id: bleeding-virus.rules $
#by matt jonkman, Proxy.Corpes.j 0fe727c2779b6891697db8f768b6d34b
-> Added to bleeding-voip.rules (1):
# $Id: bleeding-voip.rules $
-> Added to bleeding-web.rules (1):
# $Id: bleeding-web.rules $
-> Added to bleeding-web_sql_injection.rules (1):
# $Id: bleeding-web_sql_injection.rules $
-> Added to bleeding.rules (3):
# $Id: bleeding.rules $
#by Joshua Gimer
#by Don Jackson of Secureworks. RE: US courts related phishes
[---] Removed non-rule lines: [---]
-> Removed from bleeding-drop-BLOCK.rules (2):
# VERSION 1131
# Generated 2008-04-11 01:03:02 EDT
-> Removed from bleeding-drop.rules (2):
# VERSION 1131
# Generated 2008-04-11 01:03:02 EDT
-> Removed from bleeding-exploit.rules (1):
#out for testing. Please report experiences
-> Removed from bleeding-rbn-BLOCK.rules (2):
# VERSION 40
# Updated 2008-03-25 00:13:20
-> Removed from bleeding-rbn.rules (2):
# VERSION 40
# Updated 2008-03-25 00:13:20
-> Removed from bleeding-sid-msg.map (79):
2003212 || ET EXPLOIT Microsoft Office Data Structure Corruption (unpatched)
2003643 || ET TROJAN Win32.Small.mi User-Agent Detected (MyAgent)
2005320 || ET MALWARE Opteron.info Spyware User-Agent (MyAgent)
2404016 || ET DROP Known Bot C&C Server Traffic (group 17) || url,www.shadowserver.org
2404017 || ET DROP Known Bot C&C Server Traffic (group 18) || url,www.shadowserver.org
2404018 || ET DROP Known Bot C&C Server Traffic (group 19) || url,www.shadowserver.org
2404019 || ET DROP Known Bot C&C Server Traffic (group 20) || url,www.shadowserver.org
2404020 || ET DROP Known Bot C&C Server Traffic (group 21) || url,www.shadowserver.org
2405016 || ET DROP Known Bot C&C Traffic (group 17) - BLOCKING SOURCE || url,www.shadowserver.org
2405017 || ET DROP Known Bot C&C Traffic (group 18) - BLOCKING SOURCE || url,www.shadowserver.org
2405018 || ET DROP Known Bot C&C Traffic (group 19) - BLOCKING SOURCE || url,www.shadowserver.org
2405019 || ET DROP Known Bot C&C Traffic (group 20) - BLOCKING SOURCE || url,www.shadowserver.org
2405020 || ET DROP Known Bot C&C Traffic (group 21) - BLOCKING SOURCE || url,www.shadowserver.org
2406005 || ET RBN Known Russian Business Network Monitored Domains (1) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406006 || ET RBN Known Russian Business Network Monitored Domains (2) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406007 || ET RBN Known Russian Business Network Monitored Domains (3) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406008 || ET RBN Known Russian Business Network Monitored Domains (4) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406009 || ET RBN Known Russian Business Network Monitored Domains (5) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406010 || ET RBN Known Russian Business Network Monitored Domains (6) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406011 || ET RBN Known Russian Business Network Monitored Domains (7) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406012 || ET RBN Known Russian Business Network Monitored Domains (8) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406013 || ET RBN Known Russian Business Network Monitored Domains (9) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406014 || ET RBN Known Russian Business Network Monitored Domains (10) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406015 || ET RBN Known Russian Business Network Monitored Domains (11) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406016 || ET RBN Known Russian Business Network Monitored Domains (12) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406017 || ET RBN Known Russian Business Network Monitored Domains (13) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406018 || ET RBN Known Russian Business Network Monitored Domains (14) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406019 || ET RBN Known Russian Business Network Monitored Domains (15) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406020 || ET RBN Known Russian Business Network Monitored Domains (16) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406021 || ET RBN Known Russian Business Network Monitored Domains (17) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406022 || ET RBN Known Russian Business Network Monitored Domains (18) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406023 || ET RBN Known Russian Business Network Monitored Domains (19) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406024 || ET RBN Known Russian Business Network Monitored Domains (20) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406025 || ET RBN Known Russian Business Network Monitored Domains (21) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406026 || ET RBN Known Russian Business Network Monitored Domains (22) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406027 || ET RBN Known Russian Business Network Monitored Domains (23) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406028 || ET RBN Known Russian Business Network Monitored Domains (24) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406029 || ET RBN Known Russian Business Network Monitored Domains (25) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406030 || ET RBN Known Russian Business Network Monitored Domains (26) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406031 || ET RBN Known Russian Business Network Monitored Domains (27) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406032 || ET RBN Known Russian Business Network Monitored Domains (28) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406033 || ET RBN Known Russian Business Network Monitored Domains (29) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406034 || ET RBN Known Russian Business Network Monitored Domains (30) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406035 || ET RBN Known Russian Business Network Monitored Domains (31) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406036 || ET RBN Known Russian Business Network Monitored Domains (32) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406037 || ET RBN Known Russian Business Network Monitored Domains (33) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407005 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407006 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407007 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407008 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407009 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407010 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407011 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407012 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407013 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407014 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407015 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407016 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407017 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407018 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407019 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407020 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407021 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407022 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407023 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407024 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407025 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407026 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407027 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407028 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407029 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407030 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407031 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407032 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407033 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407034 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407035 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407036 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (32) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407037 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (33) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
-> Removed from bleeding-sid-msg.map.txt (79):
2003212 || ET EXPLOIT Microsoft Office Data Structure Corruption (unpatched)
2003643 || ET TROJAN Win32.Small.mi User-Agent Detected (MyAgent)
2005320 || ET MALWARE Opteron.info Spyware User-Agent (MyAgent)
2404016 || ET DROP Known Bot C&C Server Traffic (group 17) || url,www.shadowserver.org
2404017 || ET DROP Known Bot C&C Server Traffic (group 18) || url,www.shadowserver.org
2404018 || ET DROP Known Bot C&C Server Traffic (group 19) || url,www.shadowserver.org
2404019 || ET DROP Known Bot C&C Server Traffic (group 20) || url,www.shadowserver.org
2404020 || ET DROP Known Bot C&C Server Traffic (group 21) || url,www.shadowserver.org
2405016 || ET DROP Known Bot C&C Traffic (group 17) - BLOCKING SOURCE || url,www.shadowserver.org
2405017 || ET DROP Known Bot C&C Traffic (group 18) - BLOCKING SOURCE || url,www.shadowserver.org
2405018 || ET DROP Known Bot C&C Traffic (group 19) - BLOCKING SOURCE || url,www.shadowserver.org
2405019 || ET DROP Known Bot C&C Traffic (group 20) - BLOCKING SOURCE || url,www.shadowserver.org
2405020 || ET DROP Known Bot C&C Traffic (group 21) - BLOCKING SOURCE || url,www.shadowserver.org
2406005 || ET RBN Known Russian Business Network Monitored Domains (1) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406006 || ET RBN Known Russian Business Network Monitored Domains (2) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406007 || ET RBN Known Russian Business Network Monitored Domains (3) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406008 || ET RBN Known Russian Business Network Monitored Domains (4) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406009 || ET RBN Known Russian Business Network Monitored Domains (5) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406010 || ET RBN Known Russian Business Network Monitored Domains (6) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406011 || ET RBN Known Russian Business Network Monitored Domains (7) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406012 || ET RBN Known Russian Business Network Monitored Domains (8) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406013 || ET RBN Known Russian Business Network Monitored Domains (9) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406014 || ET RBN Known Russian Business Network Monitored Domains (10) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406015 || ET RBN Known Russian Business Network Monitored Domains (11) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406016 || ET RBN Known Russian Business Network Monitored Domains (12) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406017 || ET RBN Known Russian Business Network Monitored Domains (13) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406018 || ET RBN Known Russian Business Network Monitored Domains (14) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406019 || ET RBN Known Russian Business Network Monitored Domains (15) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406020 || ET RBN Known Russian Business Network Monitored Domains (16) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406021 || ET RBN Known Russian Business Network Monitored Domains (17) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406022 || ET RBN Known Russian Business Network Monitored Domains (18) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406023 || ET RBN Known Russian Business Network Monitored Domains (19) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406024 || ET RBN Known Russian Business Network Monitored Domains (20) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406025 || ET RBN Known Russian Business Network Monitored Domains (21) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406026 || ET RBN Known Russian Business Network Monitored Domains (22) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406027 || ET RBN Known Russian Business Network Monitored Domains (23) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406028 || ET RBN Known Russian Business Network Monitored Domains (24) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406029 || ET RBN Known Russian Business Network Monitored Domains (25) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406030 || ET RBN Known Russian Business Network Monitored Domains (26) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406031 || ET RBN Known Russian Business Network Monitored Domains (27) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406032 || ET RBN Known Russian Business Network Monitored Domains (28) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406033 || ET RBN Known Russian Business Network Monitored Domains (29) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406034 || ET RBN Known Russian Business Network Monitored Domains (30) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406035 || ET RBN Known Russian Business Network Monitored Domains (31) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406036 || ET RBN Known Russian Business Network Monitored Domains (32) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2406037 || ET RBN Known Russian Business Network Monitored Domains (33) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407005 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407006 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407007 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407008 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407009 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407010 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407011 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407012 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407013 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407014 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407015 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407016 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407017 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407018 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407019 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407020 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407021 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407022 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407023 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407024 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407025 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407026 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407027 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407028 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407029 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407030 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407031 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407032 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407033 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407034 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407035 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407036 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (32) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
2407037 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (33) || url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
-> Removed from bleeding-virus.rules (1):
#UA used by trojan small.mi, sent in from castlecops research
More information about the Emerging-sigs
mailing list