번호 | 날짜 | ID | 시그니처 (Total Ruleset: 27,111개) |
14,461 | 2015/01/20 | 2017356 | ET TROJAN PoisonIvy.gwx@123 Keepalive to CnC; [1] |
14,460 | 2015/01/20 | 2017355 | ET TROJAN PoisonIvy.key@123 Keepalive to CnC; [1] |
14,459 | 2015/01/20 | 2017354 | ET TROJAN PoisonIvy.happyyongzi Keepalive to CnC; [1] |
14,458 | 2015/01/20 | 2017353 | ET TROJAN PoisonIvy.suzuki Keepalive to CnC; [1] |
14,457 | 2015/01/20 | 2017352 | ET TROJAN PoisonIvy.keaidestone Keepalive to CnC; [1] |
14,456 | 2015/01/20 | 2017351 | ET TROJAN PoisonIvy.th3bug Keepalive to CnC; [1] |
14,455 | 2015/01/20 | 2017350 | ET TROJAN PoisonIvy.admin@388 Keepalive to CnC; [1] |
14,454 | 2015/01/20 | 2017349 | ET TROJAN Win32.Troj.Cidox Checkin; |
14,453 | 2015/01/20 | 2017348 | ET DELETED Trojan.Win32.VBKrypt.cugq Checkin; [1,2,3] |
14,452 | 2015/01/20 | 2017347 | ET TROJAN Trojan Related Lame Updater User-Agent; |
14,451 | 2015/01/20 | 2017346 | ET CURRENT_EVENTS Blackhole/Cool obfuscated plugindetect in charcodes w/o sep Jul 10 2013; |
14,450 | 2015/01/20 | 2017345 | ET SHELLCODE Possible UTF-16 u9090 NOP SLED; [1,2,3] |
14,449 | 2015/01/20 | 2017344 | ET TROJAN Proxychecker Lookup; [1] |
14,448 | 2015/01/20 | 2017343 | ET TROJAN W32/Spy.KeyLogger.OCI CnC Checkin; [1,2] |
14,447 | 2015/01/20 | 2017342 | ET INFO Iframe For IP Address Site; |
14,446 | 2015/01/20 | 2017341 | ET CURRENT_EVENTS Blackhole Exploit Kit Microsoft OpenType Font Exploit; |
14,445 | 2015/01/20 | 2017340 | ET CURRENT_EVENTS Blackhole Exploit Kit Shrift.php Microsoft OpenType Font Exploit Request; |
14,444 | 2015/01/20 | 2017337 | ET WEB_SERVER ATTACKER SQLi - SELECT and Schema Columns; |
14,443 | 2015/01/20 | 2017336 | ET INFO SUSPICIOUS Reassigned Eval Function 3; |
14,442 | 2015/01/20 | 2017335 | ET INFO SUSPICIOUS Reassigned Eval Function 2; |
14,441 | 2015/01/20 | 2017334 | ET INFO SUSPICIOUS Reassigned Eval Function 1; |
14,440 | 2015/01/20 | 2017333 | ET CURRENT_EVENTS Styx EK - /jvvn.html; |
14,439 | 2015/01/20 | 2017330 | ET WEB_SERVER SQLi - SELECT and sysobject; |
14,438 | 2015/01/20 | 2017329 | ET POLICY Pirate Browser Download; [1] |
14,437 | 2015/01/20 | 2017328 | ET CURRENT_EVENTS Unknown EK setSecurityManager hex August 14 2013; [1] |
14,436 | 2015/01/20 | 2017327 | ET WEB_SERVER Joomla Upload File Filter Bypass; |
14,435 | 2015/01/20 | 2017326 | ET TROJAN Yayih.A Checkin 3; [1] |
14,434 | 2015/01/20 | 2017325 | ET TROJAN Yayih.A Checkin 2; [1] |
14,433 | 2015/01/20 | 2017324 | ET CURRENT_EVENTS FlimKit obfuscated hex-encoded jnlp_embedded Aug 08 2013; |
14,432 | 2015/01/20 | 2017323 | ET CURRENT_EVENTS SUSPICIOUS IRC - NICK and -PC; |
14,431 | 2015/01/20 | 2017322 | ET CURRENT_EVENTS SUSPICIOUS IRC - NICK and Win; |
14,430 | 2015/01/20 | 2017321 | ET CURRENT_EVENTS SUSPICIOUS IRC - NICK and Possible Windows XP/7; |
14,429 | 2015/01/20 | 2017319 | ET CURRENT_EVENTS SUSPICIOUS IRC - NICK and 3 Letter Country Code; |
14,428 | 2015/01/20 | 2017318 | ET CURRENT_EVENTS SUSPICIOUS IRC - PRIVMSG *.(exe|tar|tgz|zip) download command; |
14,427 | 2015/01/20 | 2017317 | ET ATTACK_RESPONSE python shell spawn attempt; |
14,426 | 2015/01/20 | 2017315 | ET TROJAN DDoS.Win32.Agent.bay Covert Channel (VERSONEX and Mr.Black); |
14,425 | 2015/01/20 | 2017314 | ET TROJAN PRISM Backdoor; |
14,424 | 2015/01/20 | 2017313 | ET TROJAN China Chopper Command Struct; [1] |
14,423 | 2015/01/20 | 2017312 | ET TROJAN Win32/Pift DNS TXT CnC Lookup ppidn.net; [1] |
14,422 | 2015/01/20 | 2017311 | ET TROJAN Possible FortDisco Reporting Hacked Accounts; [1] |
14,421 | 2015/01/20 | 2017310 | ET CURRENT_EVENTS Possible FortDisco Wordpress Brute-force Site list download 10 wp-login.php; [1] |
14,420 | 2015/01/20 | 2017309 | ET TROJAN FortDisco Reporting Status; [1] |
14,419 | 2015/01/20 | 2017308 | ET TROJAN W32/PornoAsset.Ransomware CnC Checkin; [1,2,3] |
14,418 | 2015/01/20 | 2017307 | ET CURRENT_EVENTS 0f2490 Hacked Site Response (Outbound); |
14,417 | 2015/01/20 | 2017306 | ET CURRENT_EVENTS 0f2490 Hacked Site Response (Inbound); |
14,416 | 2015/01/20 | 2017305 | ET TROJAN Win32/Cridex Checkin; |
14,415 | 2015/01/20 | 2017303 | ET TROJAN ATTACKER IRCBot - PRIVMSG Response - Directory Listing *nix; |
14,414 | 2015/01/20 | 2017302 | ET CURRENT_EVENTS Fake Trojan Dropper purporting to be missing application - findloader; |
14,413 | 2015/01/20 | 2017301 | ET CURRENT_EVENTS Fake Trojan Dropper purporting to be missing application page landing; |
14,412 | 2015/01/20 | 2017300 | ET CURRENT_EVENTS Rawin -TDS - POST w/Java Version; |
< 251 252 253 254 255 256 257 258 259 260 > |