번호 | 날짜 | ID | 시그니처 (Total Ruleset: 27,111개) |
15,061 | 2015/01/20 | 2017966 | ET DOS Likely NTP DDoS In Progress MON_LIST Response to Non-Ephemeral Port IMPL 0x03; [1,2] |
15,060 | 2015/01/20 | 2017965 | ET DOS Likely NTP DDoS In Progress MON_LIST Response to Non-Ephemeral Port IMPL 0x02; [1,2] |
15,059 | 2015/01/20 | 2017964 | ET TROJAN Kishop.A checkin; |
15,058 | 2015/01/20 | 2017963 | ET CURRENT_EVENTS Possible Neutrino/Fiesta SilverLight Exploit Jan 13 2014 DLL Naming Convention; |
15,057 | 2015/01/20 | 2017962 | ET TROJAN PE EXE or DLL Windows file download disguised as ASCII; |
15,056 | 2015/01/20 | 2017961 | ET DELETED PE EXE or DLL Windows file download disguised as ASCII - SET; |
15,055 | 2015/01/20 | 2017960 | ET POLICY Bitcoin Mining Server Stratum Protocol HTTP Header; [1] |
15,054 | 2015/01/20 | 2017959 | ET TROJAN W32/Mevade.Variant CnC POST; [1,2] |
15,053 | 2015/01/20 | 2017958 | ET CURRENT_EVENTS Possible Neutrino EK SilverLight Exploit Jan 11 2014; |
15,052 | 2015/01/20 | 2017957 | ET CURRENT_EVENTS GoonEK Landing Jan 10 2014; |
15,051 | 2015/01/20 | 2017956 | ET CURRENT_EVENTS Angler EK Landing Jan 10 2014 3; |
15,050 | 2015/01/20 | 2017955 | ET CURRENT_EVENTS Angler EK Landing Jan 10 2014 2; |
15,049 | 2015/01/20 | 2017954 | ET CURRENT_EVENTS Angler EK Landing Jan 10 2014 1; |
15,048 | 2015/01/20 | 2017953 | ET CURRENT_EVENTS Angler EK Landing Jan 10 2014; |
15,047 | 2015/01/20 | 2017952 | ET WEB_SERVER ATTACKER WebShell - PHP Offender - POST Command; |
15,046 | 2015/01/20 | 2017951 | ET WEB_SERVER ATTACKER WebShell - PHP Offender - Title; |
15,045 | 2015/01/20 | 2017950 | ET SCAN FOCA uri; [1] |
15,044 | 2015/01/20 | 2017949 | ET USER_AGENTS FOCA User-Agent; [1] |
15,043 | 2015/01/20 | 2017948 | ET TROJAN LDPinch Checkin Post; |
15,042 | 2015/01/20 | 2017947 | ET DELETED Possible Styx Kein Landing URI Struct; |
15,041 | 2015/01/20 | 2017946 | ET TROJAN Agent.BAAB Checkin; [1] |
15,040 | 2015/01/20 | 2017945 | ET MALWARE Adware.PUQD Checkin; [1] |
15,039 | 2015/01/20 | 2017944 | ET TROJAN Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 14; [1,2] |
15,038 | 2015/01/20 | 2017943 | ET TROJAN Zbot Variant SSL cert for erjentronem.ru; |
15,037 | 2015/01/20 | 2017942 | ET TROJAN Zbot Variant SSL cert for anlogtewron.ru; |
15,036 | 2015/01/20 | 2017941 | ET TROJAN Zbot Variant SSL cert for dewart.ru; |
15,035 | 2015/01/20 | 2017940 | ET TROJAN Zbot Variant SSL cert for whoismama.ru; |
15,034 | 2015/01/20 | 2017938 | ET TROJAN Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 13; [1,2] |
15,033 | 2015/01/20 | 2017937 | ET TROJAN Fake/Short Google Search Appliance UA Win32/Ranbyus and Others; [1] |
15,032 | 2015/01/20 | 2017936 | ET TROJAN Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 12; [1,2] |
15,031 | 2015/01/20 | 2017935 | ET TROJAN Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 12 SET; [1,2] |
15,030 | 2015/01/20 | 2017934 | ET TROJAN Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 11; [1,2] |
15,029 | 2015/01/20 | 2017933 | ET POLICY TraceMyIP IP lookup; |
15,028 | 2015/01/20 | 2017931 | ET CURRENT_EVENTS DRIVEBY Redirection - Injection - Modified Edwards Packer Script; |
15,027 | 2015/01/20 | 2017930 | ET TROJAN Trojan Generic - POST To gate.php with no referer; |
15,026 | 2015/01/20 | 2017929 | ET POLICY bridges.torproject.org over TLS with SNI; [1] |
15,025 | 2015/01/20 | 2017928 | ET POLICY check.torproject.org IP lookup/Tor Usage check over TLS with SNI; |
15,024 | 2015/01/20 | 2017927 | ET POLICY check.torproject.org IP lookup/Tor Usage check over HTTP; |
15,023 | 2015/01/20 | 2017926 | ET POLICY DNS lookup for check.torproject.org IP lookup/Tor Usage check; |
15,022 | 2015/01/20 | 2017925 | ET POLICY DNS lookup for bridges.torproject.org IP lookup/Tor Usage check; [1] |
15,021 | 2015/01/20 | 2017924 | ET EXPLOIT MMCS service (Big Endian); [1] |
15,020 | 2015/01/20 | 2017923 | ET EXPLOIT MMCS service (Little Endian); [1] |
15,019 | 2015/01/20 | 2017922 | ET TROJAN Win32.Morix.B checkin; |
15,018 | 2015/01/20 | 2017921 | ET DOS Possible NTP DDoS Multiple MON_LIST Seq 0 Response Spanning Multiple Packets IMPL 0x03; [1] |
15,017 | 2015/01/20 | 2017920 | ET DOS Possible NTP DDoS Multiple MON_LIST Seq 0 Response Spanning Multiple Packets IMPL 0x02; [1] |
15,016 | 2015/01/20 | 2017919 | ET DOS Possible NTP DDoS Inbound Frequent Un-Authed MON_LIST Requests IMPL 0x03; [1] |
15,015 | 2015/01/20 | 2017918 | ET DOS Possible NTP DDoS Inbound Frequent Un-Authed MON_LIST Requests IMPL 0x02; [1] |
15,014 | 2015/01/20 | 2017917 | ET TROJAN W32/Ferret DDOS Bot CnC Beacon 2; [1] |
15,013 | 2015/01/20 | 2017916 | ET TROJAN Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 10; [1,2] |
15,012 | 2015/01/20 | 2017915 | ET TROJAN Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 9; [1,2] |
< 241 242 243 244 245 246 247 248 249 250 > |