[Emerging-updates] Live Commit Output

emerging@emergingthreats.net emerging at emergingthreats.net
Tue Nov 11 06:06:34 EST 2008


[***] Results from Oinkmaster started Tue Nov 11 06:06:34 2008 [***]

[+++]          Added rules:          [+++]

 2008740 - ET TROJAN Ligats/DR.Ilomo Agent Post (emerging-virus.rules)
 2008741 - ET CURRENT_EVENTS CVE-2008-2992 Adobe Reader PDF Exploit Related Malware Checkin (emerging.rules)
 2008742 - ET MALWARE Suspicious User Agent - Possible Admoke Admware (bdwinrun) (emerging-malware.rules)
 2008743 - ET MALWARE Suspicious User Agent - Possible Admoke Admware (bdwinrun) (emerging-malware.rules)
 2008744 - ET POLICY Possible External FreeGate DNS Query (emerging-policy.rules)
 2008745 - ET POLICY Possible External FreeGate DNS Query (emerging-policy.rules)
 2008746 - ET POLICY Possible External FreeGate DNS Query (emerging-policy.rules)
 2008747 - ET POLICY Possible External FreeGate DNS Query (emerging-policy.rules)
 2008748 - ET POLICY Possible External FreeGate DNS Query (emerging-policy.rules)
 2008749 - ET MALWARE Suspicious User-Agent (checkonline) (emerging-malware.rules)
 2406036 - ET RBN Known Russian Business Network Monitored Domains (37) (emerging-rbn.rules)
 2406037 - ET RBN Known Russian Business Network Monitored Domains (38) (emerging-rbn.rules)
 2406038 - ET RBN Known Russian Business Network Monitored Domains (39) (emerging-rbn.rules)
 2406039 - ET RBN Known Russian Business Network Monitored Domains (40) (emerging-rbn.rules)
 2406040 - ET RBN Known Russian Business Network Monitored Domains (41) (emerging-rbn.rules)
 2406041 - ET RBN Known Russian Business Network Monitored Domains (42) (emerging-rbn.rules)
 2406042 - ET RBN Known Russian Business Network Monitored Domains (43) (emerging-rbn.rules)
 2406043 - ET RBN Known Russian Business Network Monitored Domains (44) (emerging-rbn.rules)
 2406044 - ET RBN Known Russian Business Network Monitored Domains (45) (emerging-rbn.rules)
 2407036 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (37) (emerging-rbn-BLOCK.rules)
 2407037 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (38) (emerging-rbn-BLOCK.rules)
 2407038 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (39) (emerging-rbn-BLOCK.rules)
 2407039 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (40) (emerging-rbn-BLOCK.rules)
 2407040 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (41) (emerging-rbn-BLOCK.rules)
 2407041 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (42) (emerging-rbn-BLOCK.rules)
 2407042 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (43) (emerging-rbn-BLOCK.rules)
 2407043 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (44) (emerging-rbn-BLOCK.rules)
 2407044 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (45) (emerging-rbn-BLOCK.rules)


[///]     Modified active rules:     [///]

 2008735 - ET MALWARE Suspicious User Agent (FTP) (emerging-malware.rules)
 2008737 - ET CURRENT_EVENTS KernelBot/MS08-067 related Trojan Checkin (emerging.rules)
 2400000 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400001 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400002 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400003 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400004 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400005 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400006 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400007 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2400008 - ET DROP Spamhaus DROP Listed Traffic Inbound (emerging-drop.rules)
 2401000 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401001 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401002 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401003 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401004 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401005 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401006 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401007 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2401008 - ET DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (emerging-drop-BLOCK.rules)
 2402000 - ET DROP Dshield Block Listed Source (emerging-dshield.rules)
 2403000 - ET DROP Dshield Block Listed Source - BLOCKING (emerging-dshield-BLOCK.rules)
 2404000 - ET DROP Known Bot C&C Server Traffic (group 1)  (emerging-botcc.rules)
 2404001 - ET DROP Known Bot C&C Server Traffic (group 2)  (emerging-botcc.rules)
 2404002 - ET DROP Known Bot C&C Server Traffic (group 3)  (emerging-botcc.rules)
 2404003 - ET DROP Known Bot C&C Server Traffic (group 4)  (emerging-botcc.rules)
 2404004 - ET DROP Known Bot C&C Server Traffic (group 5)  (emerging-botcc.rules)
 2404005 - ET DROP Known Bot C&C Server Traffic (group 6)  (emerging-botcc.rules)
 2404006 - ET DROP Known Bot C&C Server Traffic (group 7)  (emerging-botcc.rules)
 2404007 - ET DROP Known Bot C&C Server Traffic (group 8)  (emerging-botcc.rules)
 2404008 - ET DROP Known Bot C&C Server Traffic (group 9)  (emerging-botcc.rules)
 2404009 - ET DROP Known Bot C&C Server Traffic (group 10)  (emerging-botcc.rules)
 2404010 - ET DROP Known Bot C&C Server Traffic (group 11)  (emerging-botcc.rules)
 2404011 - ET DROP Known Bot C&C Server Traffic (group 12)  (emerging-botcc.rules)
 2404012 - ET DROP Known Bot C&C Server Traffic (group 13)  (emerging-botcc.rules)
 2404013 - ET DROP Known Bot C&C Server Traffic (group 14)  (emerging-botcc.rules)
 2404014 - ET DROP Known Bot C&C Server Traffic (group 15)  (emerging-botcc.rules)
 2404015 - ET DROP Known Bot C&C Server Traffic (group 16)  (emerging-botcc.rules)
 2404016 - ET DROP Known Bot C&C Server Traffic (group 17)  (emerging-botcc.rules)
 2404017 - ET DROP Known Bot C&C Server Traffic (group 18)  (emerging-botcc.rules)
 2404018 - ET DROP Known Bot C&C Server Traffic (group 19)  (emerging-botcc.rules)
 2404019 - ET DROP Known Bot C&C Server Traffic (group 20)  (emerging-botcc.rules)
 2405000 - ET DROP Known Bot C&C Traffic (group 1) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405001 - ET DROP Known Bot C&C Traffic (group 2) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405002 - ET DROP Known Bot C&C Traffic (group 3) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405003 - ET DROP Known Bot C&C Traffic (group 4) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405004 - ET DROP Known Bot C&C Traffic (group 5) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405005 - ET DROP Known Bot C&C Traffic (group 6) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405006 - ET DROP Known Bot C&C Traffic (group 7) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405007 - ET DROP Known Bot C&C Traffic (group 8) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405008 - ET DROP Known Bot C&C Traffic (group 9) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405009 - ET DROP Known Bot C&C Traffic (group 10) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405010 - ET DROP Known Bot C&C Traffic (group 11) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405011 - ET DROP Known Bot C&C Traffic (group 12) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405012 - ET DROP Known Bot C&C Traffic (group 13) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405013 - ET DROP Known Bot C&C Traffic (group 14) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405014 - ET DROP Known Bot C&C Traffic (group 15) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405015 - ET DROP Known Bot C&C Traffic (group 16) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405016 - ET DROP Known Bot C&C Traffic (group 17) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405017 - ET DROP Known Bot C&C Traffic (group 18) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405018 - ET DROP Known Bot C&C Traffic (group 19) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2405019 - ET DROP Known Bot C&C Traffic (group 20) - BLOCKING SOURCE (emerging-botcc-BLOCK.rules)
 2406000 - ET RBN Known Russian Business Network Monitored Domains (1) (emerging-rbn.rules)
 2406001 - ET RBN Known Russian Business Network Monitored Domains (2) (emerging-rbn.rules)
 2406002 - ET RBN Known Russian Business Network Monitored Domains (3) (emerging-rbn.rules)
 2406003 - ET RBN Known Russian Business Network Monitored Domains (4) (emerging-rbn.rules)
 2406004 - ET RBN Known Russian Business Network Monitored Domains (5) (emerging-rbn.rules)
 2406005 - ET RBN Known Russian Business Network Monitored Domains (6) (emerging-rbn.rules)
 2406006 - ET RBN Known Russian Business Network Monitored Domains (7) (emerging-rbn.rules)
 2406007 - ET RBN Known Russian Business Network Monitored Domains (8) (emerging-rbn.rules)
 2406008 - ET RBN Known Russian Business Network Monitored Domains (9) (emerging-rbn.rules)
 2406009 - ET RBN Known Russian Business Network Monitored Domains (10) (emerging-rbn.rules)
 2406010 - ET RBN Known Russian Business Network Monitored Domains (11) (emerging-rbn.rules)
 2406011 - ET RBN Known Russian Business Network Monitored Domains (12) (emerging-rbn.rules)
 2406012 - ET RBN Known Russian Business Network Monitored Domains (13) (emerging-rbn.rules)
 2406013 - ET RBN Known Russian Business Network Monitored Domains (14) (emerging-rbn.rules)
 2406014 - ET RBN Known Russian Business Network Monitored Domains (15) (emerging-rbn.rules)
 2406015 - ET RBN Known Russian Business Network Monitored Domains (16) (emerging-rbn.rules)
 2406016 - ET RBN Known Russian Business Network Monitored Domains (17) (emerging-rbn.rules)
 2406017 - ET RBN Known Russian Business Network Monitored Domains (18) (emerging-rbn.rules)
 2406018 - ET RBN Known Russian Business Network Monitored Domains (19) (emerging-rbn.rules)
 2406019 - ET RBN Known Russian Business Network Monitored Domains (20) (emerging-rbn.rules)
 2406020 - ET RBN Known Russian Business Network Monitored Domains (21) (emerging-rbn.rules)
 2406021 - ET RBN Known Russian Business Network Monitored Domains (22) (emerging-rbn.rules)
 2406022 - ET RBN Known Russian Business Network Monitored Domains (23) (emerging-rbn.rules)
 2406023 - ET RBN Known Russian Business Network Monitored Domains (24) (emerging-rbn.rules)
 2406024 - ET RBN Known Russian Business Network Monitored Domains (25) (emerging-rbn.rules)
 2406025 - ET RBN Known Russian Business Network Monitored Domains (26) (emerging-rbn.rules)
 2406026 - ET RBN Known Russian Business Network Monitored Domains (27) (emerging-rbn.rules)
 2406027 - ET RBN Known Russian Business Network Monitored Domains (28) (emerging-rbn.rules)
 2406028 - ET RBN Known Russian Business Network Monitored Domains (29) (emerging-rbn.rules)
 2406029 - ET RBN Known Russian Business Network Monitored Domains (30) (emerging-rbn.rules)
 2406030 - ET RBN Known Russian Business Network Monitored Domains (31) (emerging-rbn.rules)
 2406031 - ET RBN Known Russian Business Network Monitored Domains (32) (emerging-rbn.rules)
 2406032 - ET RBN Known Russian Business Network Monitored Domains (33) (emerging-rbn.rules)
 2406033 - ET RBN Known Russian Business Network Monitored Domains (34) (emerging-rbn.rules)
 2406034 - ET RBN Known Russian Business Network Monitored Domains (35) (emerging-rbn.rules)
 2406035 - ET RBN Known Russian Business Network Monitored Domains (36) (emerging-rbn.rules)
 2407000 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1) (emerging-rbn-BLOCK.rules)
 2407001 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2) (emerging-rbn-BLOCK.rules)
 2407002 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3) (emerging-rbn-BLOCK.rules)
 2407003 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4) (emerging-rbn-BLOCK.rules)
 2407004 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5) (emerging-rbn-BLOCK.rules)
 2407005 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6) (emerging-rbn-BLOCK.rules)
 2407006 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7) (emerging-rbn-BLOCK.rules)
 2407007 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8) (emerging-rbn-BLOCK.rules)
 2407008 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9) (emerging-rbn-BLOCK.rules)
 2407009 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10) (emerging-rbn-BLOCK.rules)
 2407010 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11) (emerging-rbn-BLOCK.rules)
 2407011 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12) (emerging-rbn-BLOCK.rules)
 2407012 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13) (emerging-rbn-BLOCK.rules)
 2407013 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14) (emerging-rbn-BLOCK.rules)
 2407014 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15) (emerging-rbn-BLOCK.rules)
 2407015 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16) (emerging-rbn-BLOCK.rules)
 2407016 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17) (emerging-rbn-BLOCK.rules)
 2407017 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18) (emerging-rbn-BLOCK.rules)
 2407018 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19) (emerging-rbn-BLOCK.rules)
 2407019 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20) (emerging-rbn-BLOCK.rules)
 2407020 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21) (emerging-rbn-BLOCK.rules)
 2407021 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22) (emerging-rbn-BLOCK.rules)
 2407022 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23) (emerging-rbn-BLOCK.rules)
 2407023 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24) (emerging-rbn-BLOCK.rules)
 2407024 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25) (emerging-rbn-BLOCK.rules)
 2407025 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26) (emerging-rbn-BLOCK.rules)
 2407026 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27) (emerging-rbn-BLOCK.rules)
 2407027 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28) (emerging-rbn-BLOCK.rules)
 2407028 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29) (emerging-rbn-BLOCK.rules)
 2407029 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30) (emerging-rbn-BLOCK.rules)
 2407030 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31) (emerging-rbn-BLOCK.rules)
 2407031 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (32) (emerging-rbn-BLOCK.rules)
 2407032 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (33) (emerging-rbn-BLOCK.rules)
 2407033 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (34) (emerging-rbn-BLOCK.rules)
 2407034 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (35) (emerging-rbn-BLOCK.rules)
 2407035 - ET RBN Known Russian Business Network Monitored Domains - BLOCKING (36) (emerging-rbn-BLOCK.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to emerging-drop-BLOCK.rules (2):
        #  VERSION 1355
        #  Generated 2008-11-11 00:03:02 EDT

     -> Added to emerging-drop.rules (2):
        #  VERSION 1355
        #  Generated 2008-11-11 00:03:02 EDT

     -> Added to emerging-policy.rules (1):
        #by Sandro Reis

     -> Added to emerging-rbn-BLOCK.rules (2):
        #  VERSION 82
        #  Updated 2008-11-06 09:42:34

     -> Added to emerging-rbn.rules (2):
        #  VERSION 82
        #  Updated 2008-11-06 09:42:34

     -> Added to emerging-sid-msg.map (29):
        2008737 || ET CURRENT_EVENTS KernelBot/MS08-067 related Trojan Checkin
        2008740 || ET TROJAN Ligats/DR.Ilomo Agent Post
        2008741 || ET CURRENT_EVENTS CVE-2008-2992 Adobe Reader PDF Exploit Related Malware Checkin
        2008742 || ET MALWARE Suspicious User Agent - Possible Admoke Admware (bdwinrun)
        2008743 || ET MALWARE Suspicious User Agent - Possible Admoke Admware (bdwinrun)
        2008744 || ET POLICY Possible External FreeGate DNS Query
        2008745 || ET POLICY Possible External FreeGate DNS Query
        2008746 || ET POLICY Possible External FreeGate DNS Query
        2008747 || ET POLICY Possible External FreeGate DNS Query
        2008748 || ET POLICY Possible External FreeGate DNS Query
        2008749 || ET MALWARE Suspicious User-Agent (checkonline)
        2406036 || ET RBN Known Russian Business Network Monitored Domains (37) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406037 || ET RBN Known Russian Business Network Monitored Domains (38) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406038 || ET RBN Known Russian Business Network Monitored Domains (39) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406039 || ET RBN Known Russian Business Network Monitored Domains (40) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406040 || ET RBN Known Russian Business Network Monitored Domains (41) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406041 || ET RBN Known Russian Business Network Monitored Domains (42) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406042 || ET RBN Known Russian Business Network Monitored Domains (43) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406043 || ET RBN Known Russian Business Network Monitored Domains (44) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406044 || ET RBN Known Russian Business Network Monitored Domains (45) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407036 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (37) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407037 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (38) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407038 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (39) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407039 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (40) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407040 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (41) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407041 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (42) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407042 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (43) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407043 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (44) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407044 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (45) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork

     -> Added to emerging-sid-msg.map.txt (29):
        2008737 || ET CURRENT_EVENTS KernelBot/MS08-067 related Trojan Checkin
        2008740 || ET TROJAN Ligats/DR.Ilomo Agent Post
        2008741 || ET CURRENT_EVENTS CVE-2008-2992 Adobe Reader PDF Exploit Related Malware Checkin
        2008742 || ET MALWARE Suspicious User Agent - Possible Admoke Admware (bdwinrun)
        2008743 || ET MALWARE Suspicious User Agent - Possible Admoke Admware (bdwinrun)
        2008744 || ET POLICY Possible External FreeGate DNS Query
        2008745 || ET POLICY Possible External FreeGate DNS Query
        2008746 || ET POLICY Possible External FreeGate DNS Query
        2008747 || ET POLICY Possible External FreeGate DNS Query
        2008748 || ET POLICY Possible External FreeGate DNS Query
        2008749 || ET MALWARE Suspicious User-Agent (checkonline)
        2406036 || ET RBN Known Russian Business Network Monitored Domains (37) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406037 || ET RBN Known Russian Business Network Monitored Domains (38) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406038 || ET RBN Known Russian Business Network Monitored Domains (39) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406039 || ET RBN Known Russian Business Network Monitored Domains (40) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406040 || ET RBN Known Russian Business Network Monitored Domains (41) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406041 || ET RBN Known Russian Business Network Monitored Domains (42) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406042 || ET RBN Known Russian Business Network Monitored Domains (43) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406043 || ET RBN Known Russian Business Network Monitored Domains (44) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2406044 || ET RBN Known Russian Business Network Monitored Domains (45) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407036 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (37) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407037 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (38) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407038 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (39) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407039 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (40) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407040 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (41) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407041 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (42) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407042 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (43) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407043 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (44) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
        2407044 || ET RBN Known Russian Business Network Monitored Domains - BLOCKING (45) || url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork

     -> Added to emerging.rules (1):
        #many sources

[---]     Removed non-rule lines:    [---]

     -> Removed from emerging-drop-BLOCK.rules (2):
        #  VERSION 1348
        #  Generated 2008-11-04 00:03:02 EDT

     -> Removed from emerging-drop.rules (2):
        #  VERSION 1348
        #  Generated 2008-11-04 00:03:02 EDT

     -> Removed from emerging-rbn-BLOCK.rules (2):
        #  VERSION 81
        #  Updated 2008-10-27 09:14:06

     -> Removed from emerging-rbn.rules (2):
        #  VERSION 81
        #  Updated 2008-10-27 09:14:06

     -> Removed from emerging-sid-msg.map (1):
        2008737 || ET CURRENT_EVENTS KernelBot/MS08-67 related Trojan Checkin

     -> Removed from emerging-sid-msg.map.txt (1):
        2008737 || ET CURRENT_EVENTS KernelBot/MS08-67 related Trojan Checkin



More information about the Emerging-updates mailing list