[Emerging-updates] Daily Ruleset Update Summary 2/14/2011

Matthew Jonkman jonkman at emergingthreatspro.com
Mon Feb 14 02:28:35 EST 2011


Quite a few updates in this tarball. A major RBN update adding some Anonops nets, some good sandnet sigs, and a number new Pro sigs.

[+++]          Added rules:          [+++]

 2012310 - ET TROJAN Si25f_302 User-Agent (trojan.rules)
 2012311 - ET TROJAN W32.SillyP2P Checkin (trojan.rules)
 2012312 - ET TROJAN Generic Trojan with /? and Indy Library User-Agent (trojan.rules)
 2801335 - ETPRO TROJAN Backdoor.Win32.Darkshell.A Checkin (trojan.rules)
 2801336 - ETPRO TROJAN Trojan.Win32.Ctfmon.A Checkin (trojan.rules)
 2801337 - ETPRO EXPLOIT Symantec Alert Management System Modem String Stack Buffer Overflow (exploit.rules)
 2801338 - ETPRO MALWARE RogueSoftware.Win32.McAVG2011 Checkin (malware.rules)
 2801339 - ETPRO ACTIVEX Oracle Document Capture EasyMail ActiveX Control Information Disclosure 1 (activex.rules)
 2801340 - ETPRO ACTIVEX Oracle Document Capture EasyMail ActiveX Control Information Disclosure 2 (activex.rules)
 2801341 - ETPRO TROJAN Trojan.Win32.PassStealer.ird Checkin (trojan.rules)
 2801342 - ETPRO TROJAN Trojan.Win32.Fakeinstaller.H Checkin (trojan.rules)
 2801343 - ETPRO TROJAN Backdoor.Win32.Paras.B Checkin (trojan.rules)
 2801344 - ETPRO EXPLOIT HP OpenView Performance Insight Server Backdoor Account Code Execution (exploit.rules)
 2801345 - ETPRO EXPLOIT HP OpenView Performance Insight Server Backdoor Account Code Execution (exploit.rules)
 2801346 - ETPRO EXPLOIT HP OpenView Performance Insight Server Backdoor Account Code Execution (exploit.rules)


----------------------------------------------------
Matthew Jonkman
Emergingthreats.net
Emerging Threats Pro
Open Information Security Foundation (OISF)
Phone 765-807-8630
Fax 312-264-0205
http://www.emergingthreatspro.com
http://www.openinfosecfoundation.org
----------------------------------------------------

PGP: http://www.jonkmans.com/mattjonkman.asc





More information about the Emerging-updates mailing list