[Emerging-Sigs] Emerging Threats Daily Signature Changes
emerging@emergingthreats.net
emerging at emergingthreats.net
Fri Feb 8 17:00:09 EST 2008
[***] Results from Oinkmaster started Fri Feb 8 17:00:09 2008 [***]
[+++] Added rules: [+++]
2007825 - ET TROJAN Neonaby.com Related Trojan User-Agent (neonabyupdate) (bleeding-virus.rules)
2007826 - ET TROJAN Suspicious Useragent Used by Several trojans (API-Guide test program) (bleeding-virus.rules)
2007827 - ET TROJAN Suspicious User-Agent - Possible Trojan Downloader (ie) (bleeding-virus.rules)
2007828 - ET TROJAN LDPinch Checkin (2) (bleeding-virus.rules)
2007829 - ET TROJAN PWS-LDPinch Checkin (bleeding-virus.rules)
2007830 - ET MALWARE Maxthom/Myie2.com Related Spyware User Agent (MyIE2) (bleeding-malware.rules)
[///] Modified active rules: [///]
2406005 - ET RBN Known Russian Business Network Monitored Domains (1) (bleeding-rbn.rules)
2406006 - ET RBN Known Russian Business Network Monitored Domains (2) (bleeding-rbn.rules)
2406007 - ET RBN Known Russian Business Network Monitored Domains (3) (bleeding-rbn.rules)
2406008 - ET RBN Known Russian Business Network Monitored Domains (4) (bleeding-rbn.rules)
2406009 - ET RBN Known Russian Business Network Monitored Domains (5) (bleeding-rbn.rules)
2406010 - ET RBN Known Russian Business Network Monitored Domains (6) (bleeding-rbn.rules)
2406011 - ET RBN Known Russian Business Network Monitored Domains (7) (bleeding-rbn.rules)
2406012 - ET RBN Known Russian Business Network Monitored Domains (8) (bleeding-rbn.rules)
2406013 - ET RBN Known Russian Business Network Monitored Domains (9) (bleeding-rbn.rules)
2406014 - ET RBN Known Russian Business Network Monitored Domains (10) (bleeding-rbn.rules)
2406015 - ET RBN Known Russian Business Network Monitored Domains (11) (bleeding-rbn.rules)
2406016 - ET RBN Known Russian Business Network Monitored Domains (12) (bleeding-rbn.rules)
2406017 - ET RBN Known Russian Business Network Monitored Domains (13) (bleeding-rbn.rules)
2406018 - ET RBN Known Russian Business Network Monitored Domains (14) (bleeding-rbn.rules)
2406019 - ET RBN Known Russian Business Network Monitored Domains (15) (bleeding-rbn.rules)
2406020 - ET RBN Known Russian Business Network Monitored Domains (16) (bleeding-rbn.rules)
2406021 - ET RBN Known Russian Business Network Monitored Domains (17) (bleeding-rbn.rules)
2406022 - ET RBN Known Russian Business Network Monitored Domains (18) (bleeding-rbn.rules)
2406023 - ET RBN Known Russian Business Network Monitored Domains (19) (bleeding-rbn.rules)
2406024 - ET RBN Known Russian Business Network Monitored Domains (20) (bleeding-rbn.rules)
2406025 - ET RBN Known Russian Business Network Monitored Domains (21) (bleeding-rbn.rules)
2406026 - ET RBN Known Russian Business Network Monitored Domains (22) (bleeding-rbn.rules)
2406027 - ET RBN Known Russian Business Network Monitored Domains (23) (bleeding-rbn.rules)
2406028 - ET RBN Known Russian Business Network Monitored Domains (24) (bleeding-rbn.rules)
2406029 - ET RBN Known Russian Business Network Monitored Domains (25) (bleeding-rbn.rules)
2406030 - ET RBN Known Russian Business Network Monitored Domains (26) (bleeding-rbn.rules)
2406031 - ET RBN Known Russian Business Network Monitored Domains (27) (bleeding-rbn.rules)
2406032 - ET RBN Known Russian Business Network Monitored Domains (28) (bleeding-rbn.rules)
2406033 - ET RBN Known Russian Business Network Monitored Domains (29) (bleeding-rbn.rules)
2406034 - ET RBN Known Russian Business Network Monitored Domains (30) (bleeding-rbn.rules)
2407005 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) (bleeding-rbn-BLOCK.rules)
2407006 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) (bleeding-rbn-BLOCK.rules)
2407007 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) (bleeding-rbn-BLOCK.rules)
2407008 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) (bleeding-rbn-BLOCK.rules)
2407009 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) (bleeding-rbn-BLOCK.rules)
2407010 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) (bleeding-rbn-BLOCK.rules)
2407011 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) (bleeding-rbn-BLOCK.rules)
2407012 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) (bleeding-rbn-BLOCK.rules)
2407013 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) (bleeding-rbn-BLOCK.rules)
2407014 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) (bleeding-rbn-BLOCK.rules)
2407015 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) (bleeding-rbn-BLOCK.rules)
2407016 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) (bleeding-rbn-BLOCK.rules)
2407017 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) (bleeding-rbn-BLOCK.rules)
2407018 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) (bleeding-rbn-BLOCK.rules)
2407019 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) (bleeding-rbn-BLOCK.rules)
2407020 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) (bleeding-rbn-BLOCK.rules)
2407021 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) (bleeding-rbn-BLOCK.rules)
2407022 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) (bleeding-rbn-BLOCK.rules)
2407023 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) (bleeding-rbn-BLOCK.rules)
2407024 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) (bleeding-rbn-BLOCK.rules)
2407025 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) (bleeding-rbn-BLOCK.rules)
2407026 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) (bleeding-rbn-BLOCK.rules)
2407027 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) (bleeding-rbn-BLOCK.rules)
2407028 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) (bleeding-rbn-BLOCK.rules)
2407029 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) (bleeding-rbn-BLOCK.rules)
2407030 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) (bleeding-rbn-BLOCK.rules)
2407031 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) (bleeding-rbn-BLOCK.rules)
2407032 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) (bleeding-rbn-BLOCK.rules)
2407033 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) (bleeding-rbn-BLOCK.rules)
2407034 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) (bleeding-rbn-BLOCK.rules)
[+++] Added non-rule lines: [+++]
-> Added to bleeding-malware.rules (1):
#maxthon related, by matt jonkman
-> Added to bleeding-rbn-BLOCK.rules (2):
# VERSION 35
# Updated 2008-02-08 16:03:09
-> Added to bleeding-rbn.rules (2):
# VERSION 35
# Updated 2008-02-08 16:03:09
-> Added to bleeding-sid-msg.map (6):
2007825 || ET TROJAN Neonaby.com Related Trojan User-Agent (neonabyupdate)
2007826 || ET TROJAN Suspicious Useragent Used by Several trojans (API-Guide test program)
2007827 || ET TROJAN Suspicious User-Agent - Possible Trojan Downloader (ie)
2007828 || ET TROJAN LDPinch Checkin (2)
2007829 || ET TROJAN PWS-LDPinch Checkin
2007830 || ET MALWARE Maxthom/Myie2.com Related Spyware User Agent (MyIE2)
-> Added to bleeding-sid-msg.map.txt (6):
2007825 || ET TROJAN Neonaby.com Related Trojan User-Agent (neonabyupdate)
2007826 || ET TROJAN Suspicious Useragent Used by Several trojans (API-Guide test program)
2007827 || ET TROJAN Suspicious User-Agent - Possible Trojan Downloader (ie)
2007828 || ET TROJAN LDPinch Checkin (2)
2007829 || ET TROJAN PWS-LDPinch Checkin
2007830 || ET MALWARE Maxthom/Myie2.com Related Spyware User Agent (MyIE2)
-> Added to bleeding-virus.rules (3):
#matt jonkman, general downloader ua
#matt jonkman, new variant
#more pinch
[---] Removed non-rule lines: [---]
-> Removed from bleeding-attack_response.rules (1):
# $Id: bleeding-attack_response.rules $
-> Removed from bleeding-dos.rules (1):
# $Id: bleeding-dos.rules $
-> Removed from bleeding-exploit.rules (1):
# $Id: bleeding-exploit.rules $
-> Removed from bleeding-game.rules (1):
# $Id: bleeding-game.rules $
-> Removed from bleeding-inappropriate.rules (1):
# $Id: bleeding-inappropriate.rules $
-> Removed from bleeding-malware.rules (1):
# $Id: bleeding-malware.rules $
-> Removed from bleeding-p2p.rules (1):
# $Id: bleeding-p2p.rules $
-> Removed from bleeding-policy.rules (1):
# $Id: bleeding-policy.rules $
-> Removed from bleeding-rbn-BLOCK.rules (2):
# VERSION 34
# Updated 2008-02-07 14:51:58
-> Removed from bleeding-rbn.rules (2):
# VERSION 34
# Updated 2008-02-07 14:51:58
-> Removed from bleeding-scan.rules (1):
# $Id: bleeding-scan.rules $
-> Removed from bleeding-virus.rules (1):
# $Id: bleeding-virus.rules $
-> Removed from bleeding-voip.rules (1):
# $Id: bleeding-voip.rules $
-> Removed from bleeding-web.rules (1):
# $Id: bleeding-web.rules $
-> Removed from bleeding-web_sql_injection.rules (1):
# $Id: bleeding-web_sql_injection.rules $
-> Removed from bleeding.rules (1):
# $Id: bleeding.rules $
More information about the Emerging-sigs
mailing list