[Emerging-Sigs] Daily Ruleset Update Summary 2019/04/19

Jason Williams jwilliams at emergingthreats.net
Fri Apr 19 13:57:53 HDT 2019


[***]            Summary:            [***]

28 new Pro. KuaiZip, Mobtes, CCCopyStealer, Various Phishing.

 [+++]          Added rules:          [+++]

 Pro:

  2835945 - ETPRO MOBILE_MALWARE Trojan.AndroidOS.Mobtes.e Checkin
(mobile_malware.rules)
  2835946 - ETPRO TROJAN CoinMiner Known Malicious Stratum Authline
(2019-04-19 1) (trojan.rules)
  2835947 - ETPRO TROJAN CoinMiner Known Malicious Stratum Authline
(2019-04-19 2) (trojan.rules)
  2835948 - ETPRO MALWARE KuaiZip Related Activity (malware.rules)
  2835949 - ETPRO TROJAN Observed Malicious SSL Cert (More_eggs CnC)
(trojan.rules)
  2835950 - ETPRO TROJAN CCCopyStealer Exfiltrating System Data
(trojan.rules)
  2835951 - ETPRO CURRENT_EVENTS Successful Banco do Brasil Phish
2019-04-19 (current_events.rules)
  2835952 - ETPRO CURRENT_EVENTS Successful BNP Paribas Phish 2019-04-19
(current_events.rules)
  2835953 - ETPRO CURRENT_EVENTS Successful Netflix Phish 2019-04-19
(current_events.rules)
  2835954 - ETPRO CURRENT_EVENTS Successful Generic Credit Card Information
Phish 2019-04-19 (current_events.rules)
  2835955 - ETPRO CURRENT_EVENTS Successful Wells Fargo Phish 2019-04-19
(current_events.rules)
  2835956 - ETPRO CURRENT_EVENTS Successful Generic Webmail Phish
2019-04-19 (current_events.rules)
  2835957 - ETPRO CURRENT_EVENTS Successful Generic Email Account
Verification Phish 2019-04-19 (current_events.rules)
  2835958 - ETPRO CURRENT_EVENTS Successful Spectrum Webmail Phish
2019-04-19 (current_events.rules)
  2835959 - ETPRO CURRENT_EVENTS Successful Banque Populaire Phish
2019-04-19 (current_events.rules)
  2835960 - ETPRO CURRENT_EVENTS Successful Navy Federal Credit Union Phish
2019-04-19 (current_events.rules)
  2835961 - ETPRO CURRENT_EVENTS Successful Navy Federal Credit Union Phish
2019-04-19 (current_events.rules)
  2835962 - ETPRO CURRENT_EVENTS Successful Microsoft Account Phish
2019-04-19 (current_events.rules)
  2835963 - ETPRO CURRENT_EVENTS Successful Microsoft Account Phish
2019-04-19 (current_events.rules)
  2835964 - ETPRO CURRENT_EVENTS Successful Banco do Brasil Phish
2019-04-19 (current_events.rules)
  2835965 - ETPRO CURRENT_EVENTS Successful Generic Credit Card Information
Phish 2019-04-19 (current_events.rules)
  2835966 - ETPRO CURRENT_EVENTS Successful Credit Agricole Phish
2019-04-19 (current_events.rules)
  2835967 - ETPRO CURRENT_EVENTS Successful Banco Bradesco Phish 2019-04-19
(current_events.rules)
  2835968 - ETPRO CURRENT_EVENTS Successful Bendigo Bank Phish 2019-04-19
(current_events.rules)
  2835969 - ETPRO CURRENT_EVENTS Successful CIBC Phish 2019-04-19
(current_events.rules)
  2835970 - ETPRO CURRENT_EVENTS Successful Generic Credit Card Information
Phish 2019-04-19 (current_events.rules)
  2835971 - ETPRO CURRENT_EVENTS Successful Paypal Phish 2019-04-19
(current_events.rules)
  2835972 - ETPRO CURRENT_EVENTS Successful Paypal Phish 2019-04-19
(current_events.rules)

 [///]     Modified active rules:     [///]

  2024771 - ET TROJAN [PTsecurity] Possible Cobalt Strike payload
(trojan.rules)
  2025005 - ET CURRENT_EVENTS Possible Successful Generic Phish Jan 14 2016
(current_events.rules)

 [---]         Disabled rules:        [---]

  2835753 - ETPRO TROJAN Win32.Floxif.H Checkin (trojan.rules)
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.emergingthreats.net/pipermail/emerging-sigs/attachments/20190419/b38d76bc/attachment.html>


More information about the Emerging-sigs mailing list