[Emerging-Sigs] Emerging Threats Daily Signature Changes

emerging@emergingthreats.net emerging at emergingthreats.net
Tue May 13 17:00:09 EDT 2008


[***] Results from Oinkmaster started Tue May 13 17:00:09 2008 [***]

[+++]          Added rules:          [+++]

 2008209 - ET MALWARE Suspicious User-Agent (SERVER2_03) (emerging-malware.rules)
 2008210 - ET MALWARE Suspicious Misspelled Mozilla User-Agent (Mozila) (emerging-malware.rules)
 2008211 - ET MALWARE Suspicious User-Agent (WinProxy) (emerging-malware.rules)
 2008212 - ET TROJAN Optix Pro Trojan/Keylogger Reporting Installation via Email (emerging-virus.rules)
 2008213 - ET TROJAN LDPinch Checkin (9) (emerging-virus.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to emerging-sid-msg.map (5):
        2008209 || ET MALWARE Suspicious User-Agent (SERVER2_03)
        2008210 || ET MALWARE Suspicious Misspelled Mozilla User-Agent (Mozila)
        2008211 || ET MALWARE Suspicious User-Agent (WinProxy)
        2008212 || ET TROJAN Optix Pro Trojan/Keylogger Reporting Installation via Email || url,en.wikipedia.org/wiki/Optix_Pro
        2008213 || ET TROJAN LDPinch Checkin (9)

     -> Added to emerging-sid-msg.map.txt (5):
        2008209 || ET MALWARE Suspicious User-Agent (SERVER2_03)
        2008210 || ET MALWARE Suspicious Misspelled Mozilla User-Agent (Mozila)
        2008211 || ET MALWARE Suspicious User-Agent (WinProxy)
        2008212 || ET TROJAN Optix Pro Trojan/Keylogger Reporting Installation via Email || url,en.wikipedia.org/wiki/Optix_Pro
        2008213 || ET TROJAN LDPinch Checkin (9)

     -> Added to emerging-virus.rules (1):
        #matt jonkman, re 9fcea128aeff455ff8f6c9558dd150fd



More information about the Emerging-sigs mailing list