A great week for rules! 16 new Open sigs, and 42 new Pro Subscriber rules! Not too shabby.
2805673 – ETPRO TROJAN Worm.Win32/Vobfus.GD Checkin (trojan.rules)
2805674 – ETPRO TROJAN Virus.Win32.Virut.a Proxy Registration (trojan.rules)
2805675 – ETPRO TROJAN Unknown Trojan Checkin (trojan.rules)
2805676 – ETPRO TROJAN Win32/FakeMSA.gen!A Checkin (trojan.rules)
2805677 – ETPRO TROJAN W32/VBNA.B!worm Checkin (trojan.rules)
2805678 – ETPRO TROJAN Worm.Win32/Vobfus.GD Checkin 2 (trojan.rules)
2805679 – ETPRO WEB_CLIENT Microsoft Internet Explorer Use-After-Free (web_client.rules)
2805680 – ETPRO WEB_CLIENT Microsoft Internet Explorer CTreePos Use After Free (web_client.rules)
2805681 – ETPRO WEB_CLIENT Microsoft Windows Explorer Briefcase Database File Integer Underflow (web_client.rules)
2805682 – ETPRO NETBIOS Microsoft Windows Explorer Briefcase Database File Integer Underflow (netbios.rules)
2805683 – ETPRO WEB_CLIENT Microsoft Windows Explorer Briefcase Integer Overflow (web_client.rules)
2805684 – ETPRO NETBIOS Microsoft Windows Explorer Briefcase Database Integer Overflow (netbios.rules)
2805685 – ETPRO WEB_CLIENT Microsoft .NET Framework Insecure Library Loading (web_client.rules)
2805686 – ETPRO NETBIOS Microsoft .NET Framework Insecure Library Loading – SMB ASCII (netbios.rules)
2805687 – ETPRO NETBIOS Microsoft .NET Framework Insecure Library Loading – SMB Unicode (netbios.rules)
2805688 – ETPRO NETBIOS Microsoft .NET Framework Insecure Library Loading – SMB-DS ASCII (netbios.rules)
2805689 – ETPRO NETBIOS Microsoft .NET Framework Insecure Library Loading – SMB-DS Unicode (netbios.rules)
2805690 – ETPRO WEB_CLIENT Microsoft .NET Proxy.pac file request (web_client.rules)
2805691 – ETPRO WEB_CLIENT Microsoft .NET framework sandboxes bypass via proxy auto configuration javascript file (web_client.rules)
2805694 – ETPRO TROJAN Variant.Strictor.9553 Checkin (trojan.rules)
2805695 – ETPRO TROJAN W32/Delfloader.B.gen!Eldorado Checkin 2 (trojan.rules)
2805696 – ETPRO TROJAN TR/Agent.1657856.1 Checkin (trojan.rules)
2805697 – ETPRO TROJAN Unknown Trojan Checkin (trojan.rules)
2805698 – ETPRO TROJAN
WORM_MEDBOT.AI Checkin (trojan.rules)
2805699 – ETPRO TROJAN W32/Dropper.P!tr Checkin (trojan.rules)
2805700 – ETPRO TROJAN Trojan.Win32.Agent2.fjpq Checkin (trojan.rules)
2805701 – ETPRO TROJAN Win32/Phintok.A Checkin 1 (trojan.rules)
2805702 – ETPRO TROJAN Win32/Phintok.A Checkin 2 (trojan.rules)
2805703 – ETPRO WEB_CLIENT Microsoft Excel corrupted file download invalid SerAuxErrBar BIFF record (web_client.rules)
2805704 – ETPRO TROJAN Win32/Alyak.C Checkin 1 (trojan.rules)
2805705 – ETPRO TROJAN Win32/Alyak.C Checkin 2 (trojan.rules)
2805706 – ETPRO TROJAN Win32/Alyak.C Checkin 3 (trojan.rules)
2805707 – ETPRO TROJAN
Backdoor.Win32.DarkMoon.BE Checkin 1 (trojan.rules)
2805708 – ETPRO TROJAN
Backdoor.Win32.DarkMoon.BE Checkin 2 (trojan.rules)
2805709 – ETPRO MALWARE Win32/InstallMate User-Agent (TixDll) (malware.rules)
2805710 – ETPRO TROJAN PSW.LdPinch.NCB Reporting via SMTP (trojan.rules)
2805711 – ETPRO TROJAN Unknown Trojan Checkin (trojan.rules)
2805712 – ETPRO TROJAN W32/Banker.ULW!tr Checkin (trojan.rules)
2805714 – ETPRO TROJAN Win32/Tinxy.A / Worm.Win32.Koobface Checkin (trojan.rules)
2805715 – ETPRO TROJAN Trojan.Win32.Agent.angq / Worm.Win32.Koobface Checkin (trojan.rules)
2805716 – ETPRO TROJAN Unknown Trojan Checkin (trojan.rules)
2805717 – ETPRO WEB_CLIENT Microsoft Internet Explorer CTreeNode Use After Free (web_client.rules)
[///] Modified active rules: [///]
2012102 – ET ACTIVEX Image Viewer CP Gold Image2PDF Buffer Overflow (activex.rules)
2012133 – ET ACTIVEX FathFTP 1.8 EnumFiles Method ActiveX Buffer Overflow (activex.rules)
2012134 – ET ACTIVEX SigPlus Pro 3.74 ActiveX LCDWriteString Method Remote Buffer Overflow (activex.rules)
2012145 – ET ACTIVEX Netcraft Toolbar Remote Code Execution (activex.rules)
2012146 – ET ACTIVEX ImageShack Toolbar Remote Code Execution (activex.rules)
2012147 – ET ACTIVEX Advanced File Vault Activex Heap Spray Attempt (activex.rules)
2012148 – ET ACTIVEX dBpowerAMP Audio Player 2 FileExists Method ActiveX Buffer Overflow (activex.rules)
2014730 – ET CURRENT_EVENTS Potential FAKEAV Download a-f0-9 x16 download (current_events.rules)
2015680 – ET CURRENT_EVENTS Blackhole Java applet with obfuscated URL Nov 09 2012 (current_events.rules)
2015739 – ET CURRENT_EVENTS pamdql applet with obfuscated URL (current_events.rules)
2015847 – ET CURRENT_EVENTS SofosFO/NeoSploit possible second stage landing page (current_events.rules)
2015872 – ET CURRENT_EVENTS Blackhole request for Payload (current_events.rules)
2015873 – ET CURRENT_EVENTS Cool Exploit Kit Requesting Payload (current_events.rules)
2804921 – ETPRO WEB_CLIENT Microsoft Excel file download – SET 1 (web_client.rules)
[---] Disabled and modified rules: [---]
2014599 – ET TROJAN Mac Flashback Checkin 3 (trojan.rules)
[---] Removed rules: [---]
2008766 – ET TROJAN Generic Downloader Checkin Url Detected (trojan.rules)
2014220 – ET CURRENT_EVENTS TDS Sutra Exploit Kit Redirect Received (current_events.rules)
2014521 – ET CURRENT_EVENTS Possible Blackhole Landing to 8 chr folder plus index.html (current_events.rules)
2803882 – ETPRO POLICY DynDNS IP Check Response (policy.rules)