[Emerging-updates] Daily Ruleset Update Summary 05/28/2014

Francis Trudeau ftrudeau at emergingthreats.net
Wed May 28 17:04:12 EDT 2014


 [***] Summary: [***]

 3 new Open signatures, 13 new Pro (3+10).  Zeus.BitcoinMiner, Various
AndroidOS, Necurs, OneLouder.

 Thanks:  Nathan Fowler, Kevin Ross, and Ryan Moon.

 [+++]          Added rules:          [+++]

 Open:

  2018504 - ET TROJAN W32/Zeus.BitcoinMiner Variant CnC Beacon
(trojan.rules)
  2018505 - ET CURRENT_EVENTS food.com compromise hostile JavaScript gate
(current_events.rules)
  2018506 - ET TROJAN Upatre Compromised Site hot-buys (trojan.rules)

 Pro:

  2808083 - ETPRO SNMP R7-2014-01 Brocade load balancer credential stealing
attempt (snmp.rules)
  2808084 - ETPRO SNMP R7-2014-02 Ubee cable modem credential stealing
attempt 1 (snmp.rules)
  2808085 - ETPRO SNMP R7-2014-02 Ubee cable modem credential stealing
attempt 2 (snmp.rules)
  2808086 - ETPRO SNMP R7-2014-03 Netopia/Motorola cable modem credential
stealing attempt (snmp.rules)
  2808087 - ETPRO MOBILE_MALWARE Backdoor.AndroidOS.Cynos.b Checkin
(mobile_malware.rules)
  2808088 - ETPRO MOBILE_MALWARE Backdoor.AndroidOS.Cynos.b Checkin 2
(mobile_malware.rules)
  2808089 - ETPRO MOBILE_MALWARE Backdoor.AndroidOS.Cynos.b Checkin 3
(mobile_malware.rules)
  2808090 - ETPRO TROJAN Win32/Necurs Checkin 4 (trojan.rules)
  2808091 - ETPRO MALWARE Win32/AdWare.SmartApps Checkin (malware.rules)
  2808092 - ETPRO TROJAN Win32/Tandfuy.B Checkin (trojan.rules)


 [+++]  Enabled and modified rules:   [+++]

  2018463 - ET TROJAN possible OneLouder header structure (trojan.rules)
  2018464 - ET TROJAN OneLouder EXE download possibly installing Zeus P2P
(trojan.rules)


 [///]     Modified active rules:     [///]

  2018496 - ET TROJAN Win32/Necurs Checkin (trojan.rules)
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.emergingthreats.net/pipermail/emerging-updates/attachments/20140528/559e0ec6/attachment.html>


More information about the Emerging-updates mailing list