[Emerging-Sigs] Emerging Threats Daily Signature Changes

emerging@emergingthreats.net emerging at emergingthreats.net
Tue Jul 1 16:00:08 EDT 2008


[***] Results from Oinkmaster started Tue Jul  1 16:00:08 2008 [***]

[+++]          Added rules:          [+++]

 2008359 - ET TROJAN Unnamed - kuaiche.com related (emerging.rules)
 2008360 - ET TROJAN Steam Steal0r (emerging-virus.rules)
 2008361 - ET MALWARE Suspicious User-Agent (Accessing) (emerging-malware.rules)
 2008362 - ET SCAN bsqlbf Brute Force SQL Injection (emerging-scan.rules)


[///]     Modified active rules:     [///]

 2003636 - ET VIRUS Sality Virus User Agent Detected (KUKU) (emerging-virus.rules)
 2008077 - ET CURRENT_EVENTS Possible Storm Worm EXE Request (winner.exe) (emerging.rules)
 2008288 - ET CURRENT_EVENTS Possible Storm Worm URL Request (mylove.exe) (emerging.rules)
 2406005 - ET RBN Known Russian Business Network Monitored Domains (1) (emerging-rbn.rules)
 2406006 - ET RBN Known Russian Business Network Monitored Domains (2) (emerging-rbn.rules)
 2406007 - ET RBN Known Russian Business Network Monitored Domains (3) (emerging-rbn.rules)
 2406008 - ET RBN Known Russian Business Network Monitored Domains (4) (emerging-rbn.rules)
 2406009 - ET RBN Known Russian Business Network Monitored Domains (5) (emerging-rbn.rules)
 2406010 - ET RBN Known Russian Business Network Monitored Domains (6) (emerging-rbn.rules)
 2406011 - ET RBN Known Russian Business Network Monitored Domains (7) (emerging-rbn.rules)
 2406012 - ET RBN Known Russian Business Network Monitored Domains (8) (emerging-rbn.rules)
 2406013 - ET RBN Known Russian Business Network Monitored Domains (9) (emerging-rbn.rules)
 2406014 - ET RBN Known Russian Business Network Monitored Domains (10) (emerging-rbn.rules)
 2406015 - ET RBN Known Russian Business Network Monitored Domains (11) (emerging-rbn.rules)
 2406016 - ET RBN Known Russian Business Network Monitored Domains (12) (emerging-rbn.rules)
 2406017 - ET RBN Known Russian Business Network Monitored Domains (13) (emerging-rbn.rules)
 2406018 - ET RBN Known Russian Business Network Monitored Domains (14) (emerging-rbn.rules)
 2406019 - ET RBN Known Russian Business Network Monitored Domains (15) (emerging-rbn.rules)
 2406020 - ET RBN Known Russian Business Network Monitored Domains (16) (emerging-rbn.rules)
 2406021 - ET RBN Known Russian Business Network Monitored Domains (17) (emerging-rbn.rules)
 2406022 - ET RBN Known Russian Business Network Monitored Domains (18) (emerging-rbn.rules)
 2406023 - ET RBN Known Russian Business Network Monitored Domains (19) (emerging-rbn.rules)
 2406024 - ET RBN Known Russian Business Network Monitored Domains (20) (emerging-rbn.rules)
 2406025 - ET RBN Known Russian Business Network Monitored Domains (21) (emerging-rbn.rules)
 2406026 - ET RBN Known Russian Business Network Monitored Domains (22) (emerging-rbn.rules)
 2406027 - ET RBN Known Russian Business Network Monitored Domains (23) (emerging-rbn.rules)
 2406028 - ET RBN Known Russian Business Network Monitored Domains (24) (emerging-rbn.rules)
 2406029 - ET RBN Known Russian Business Network Monitored Domains (25) (emerging-rbn.rules)
 2406030 - ET RBN Known Russian Business Network Monitored Domains (26) (emerging-rbn.rules)
 2406031 - ET RBN Known Russian Business Network Monitored Domains (27) (emerging-rbn.rules)
 2406032 - ET RBN Known Russian Business Network Monitored Domains (28) (emerging-rbn.rules)
 2406033 - ET RBN Known Russian Business Network Monitored Domains (29) (emerging-rbn.rules)
 2406034 - ET RBN Known Russian Business Network Monitored Domains (30) (emerging-rbn.rules)
 2406035 - ET RBN Known Russian Business Network Monitored Domains (31) (emerging-rbn.rules)
 2406036 - ET RBN Known Russian Business Network Monitored Domains (32) (emerging-rbn.rules)
 2406037 - ET RBN Known Russian Business Network Monitored Domains (33) (emerging-rbn.rules)
 2406038 - ET RBN Known Russian Business Network Monitored Domains (34) (emerging-rbn.rules)
 2407005 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) (emerging-rbn-BLOCK.rules)
 2407006 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) (emerging-rbn-BLOCK.rules)
 2407007 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) (emerging-rbn-BLOCK.rules)
 2407008 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) (emerging-rbn-BLOCK.rules)
 2407009 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) (emerging-rbn-BLOCK.rules)
 2407010 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) (emerging-rbn-BLOCK.rules)
 2407011 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) (emerging-rbn-BLOCK.rules)
 2407012 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) (emerging-rbn-BLOCK.rules)
 2407013 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) (emerging-rbn-BLOCK.rules)
 2407014 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) (emerging-rbn-BLOCK.rules)
 2407015 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) (emerging-rbn-BLOCK.rules)
 2407016 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) (emerging-rbn-BLOCK.rules)
 2407017 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) (emerging-rbn-BLOCK.rules)
 2407018 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) (emerging-rbn-BLOCK.rules)
 2407019 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) (emerging-rbn-BLOCK.rules)
 2407020 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) (emerging-rbn-BLOCK.rules)
 2407021 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) (emerging-rbn-BLOCK.rules)
 2407022 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) (emerging-rbn-BLOCK.rules)
 2407023 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) (emerging-rbn-BLOCK.rules)
 2407024 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) (emerging-rbn-BLOCK.rules)
 2407025 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) (emerging-rbn-BLOCK.rules)
 2407026 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) (emerging-rbn-BLOCK.rules)
 2407027 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) (emerging-rbn-BLOCK.rules)
 2407028 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) (emerging-rbn-BLOCK.rules)
 2407029 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) (emerging-rbn-BLOCK.rules)
 2407030 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) (emerging-rbn-BLOCK.rules)
 2407031 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) (emerging-rbn-BLOCK.rules)
 2407032 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) (emerging-rbn-BLOCK.rules)
 2407033 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) (emerging-rbn-BLOCK.rules)
 2407034 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) (emerging-rbn-BLOCK.rules)
 2407035 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) (emerging-rbn-BLOCK.rules)
 2407036 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (32) (emerging-rbn-BLOCK.rules)
 2407037 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (33) (emerging-rbn-BLOCK.rules)
 2407038 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (34) (emerging-rbn-BLOCK.rules)


[///]    Modified inactive rules:    [///]

 2000560 - ET POLICY HTTP CONNECT Tunnel Attempt Inbound (emerging-policy.rules)
 2008330 - ET POLICY HTTP CONNECT Tunnel Attempt Outbound (emerging-policy.rules)


[---]         Removed rules:         [---]

 2406003 - ET RBN Known Russian Business Network Traffic - Known Trojan C&Cs (emerging-rbn.rules)
 2407003 - ET RBN Known Russian Business Network Traffic - Known Trojan C&Cs - BLOCKING (emerging-rbn-BLOCK.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to emerging-malware.rules (1):
        #re f39d0a669ad98b95370a4f525d7d79ec, by Marcus at unsober

     -> Added to emerging-rbn-BLOCK.rules (2):
        #  VERSION 57
        #  Updated 2008-07-01 12:14:45

     -> Added to emerging-rbn.rules (2):
        #  VERSION 57
        #  Updated 2008-07-01 12:14:45

     -> Added to emerging-scan.rules (1):
        #by Michael Sconzo of ERCOT

     -> Added to emerging-sid-msg.map (9):
        2000560 || ET POLICY HTTP CONNECT Tunnel Attempt Inbound
        2003636 || ET VIRUS Sality Virus User Agent Detected (KUKU)
        2008077 || ET CURRENT_EVENTS Possible Storm Worm EXE Request (winner.exe) || url,www.sudosecure.net/archives/119
        2008288 || ET CURRENT_EVENTS Possible Storm Worm URL Request (mylove.exe)
        2008330 || ET POLICY HTTP CONNECT Tunnel Attempt Outbound
        2008359 || ET TROJAN Unnamed - kuaiche.com related
        2008360 || ET TROJAN Steam Steal0r
        2008361 || ET MALWARE Suspicious User-Agent (Accessing)
        2008362 || ET SCAN bsqlbf Brute Force SQL Injection || url,code.google.com/p/bsqlbf-v2/

     -> Added to emerging-sid-msg.map.txt (9):
        2000560 || ET POLICY HTTP CONNECT Tunnel Attempt Inbound
        2003636 || ET VIRUS Sality Virus User Agent Detected (KUKU)
        2008077 || ET CURRENT_EVENTS Possible Storm Worm EXE Request (winner.exe) || url,www.sudosecure.net/archives/119
        2008288 || ET CURRENT_EVENTS Possible Storm Worm URL Request (mylove.exe)
        2008330 || ET POLICY HTTP CONNECT Tunnel Attempt Outbound
        2008359 || ET TROJAN Unnamed - kuaiche.com related
        2008360 || ET TROJAN Steam Steal0r
        2008361 || ET MALWARE Suspicious User-Agent (Accessing)
        2008362 || ET SCAN bsqlbf Brute Force SQL Injection || url,code.google.com/p/bsqlbf-v2/

     -> Added to emerging-virus.rules (1):
        #ref: b957da5c0bc6f21341795a6ead9eddd9

     -> Added to emerging.rules (1):
        #by Pedro Marinho, re 58816f781154bda381fdcb1e3fab7bdd

[---]     Removed non-rule lines:    [---]

     -> Removed from emerging-rbn-BLOCK.rules (3):
        #Anserin/Torpig/Sinowal hosts
        #  VERSION 56
        #  Updated 2008-06-25 23:53:20

     -> Removed from emerging-rbn.rules (3):
        #Anserin/Torpig/Sinowal hosts
        #  VERSION 56
        #  Updated 2008-06-25 23:53:20

     -> Removed from emerging-sid-msg.map (7):
        2000560 || ET HTTP CONNECT Tunnel Attempt Inbound
        2003636 || ET VIRUS Sality Virus User Agent Detected (KUKU v3.09)
        2008077 || ET CURRENT_EVENTS Possible Storm Worm EXE Request (beijing.exe) || url,www.sudosecure.net/archives/119
        2008288 || ET CURRENT_EVENTS Possible Storm Worm URL Request (video.exe)
        2008330 || ET HTTP CONNECT Tunnel Attempt Outbound
        2406003 || ET RBN Known Russian Business Network Traffic - Known Trojan C&Cs || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407003 || ET RBN Known Russian Business Network Traffic - Known Trojan C&Cs - BLOCKING || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork

     -> Removed from emerging-sid-msg.map.txt (7):
        2000560 || ET HTTP CONNECT Tunnel Attempt Inbound
        2003636 || ET VIRUS Sality Virus User Agent Detected (KUKU v3.09)
        2008077 || ET CURRENT_EVENTS Possible Storm Worm EXE Request (beijing.exe) || url,www.sudosecure.net/archives/119
        2008288 || ET CURRENT_EVENTS Possible Storm Worm URL Request (video.exe)
        2008330 || ET HTTP CONNECT Tunnel Attempt Outbound
        2406003 || ET RBN Known Russian Business Network Traffic - Known Trojan C&Cs || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407003 || ET RBN Known Russian Business Network Traffic - Known Trojan C&Cs - BLOCKING || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork

     -> Removed from emerging.rules (1):
        #Jack Pepper



More information about the Emerging-sigs mailing list