번호 | 날짜 | ID | 시그니처 (Total Ruleset: 27,111개) |
11,211 | 2015/01/20 | 2013978 | ET CURRENT_EVENTS Lilupophilupop Injected Script Being Served to Client; |
11,210 | 2015/01/20 | 2013977 | ET TROJAN TDSS DNS Based Internet Connectivity Check; |
11,209 | 2015/01/20 | 2013976 | ET TROJAN Zeus POST Request to CnC - URL agnostic; [1,2] |
11,208 | 2015/01/20 | 2013975 | ET CURRENT_EVENTS Neosploit Java Exploit Kit request to /? plus hex 32; |
11,207 | 2015/01/20 | 2013974 | ET POLICY Suspicious Invalid HTTP Accept Header of ?; |
11,206 | 2015/01/20 | 2013972 | ET CURRENT_EVENTS Initial Blackhole Landing Loading... Wait Please; [1] |
11,205 | 2015/01/20 | 2013971 | ET INFO DYNAMIC_DNS Query for Suspicious .dyndns-at-home.com Domain; |
11,204 | 2015/01/20 | 2013970 | ET DNS Query for Suspicious .noip.cn Domain; |
11,203 | 2015/01/20 | 2013969 | ET INFO HTTP Request to a .noip.cn domain; |
11,202 | 2015/01/20 | 2013968 | ET MOBILE_MALWARE Android/KungFu Package Delete Command; [1] |
11,201 | 2015/01/20 | 2013967 | ET USER_AGENTS Suspicious User-Agent (adlib); [1] |
11,200 | 2015/01/20 | 2013966 | ET MOBILE_MALWARE Android/Ozotshielder.A Checkin; [1] |
11,199 | 2015/01/20 | 2013965 | ET MOBILE_MALWARE Android/SndApp.B Sending Device Information; [1] |
11,198 | 2015/01/20 | 2013964 | ET TROJAN Suspicious UA Mozilla / 4.0; |
11,197 | 2015/01/20 | 2013963 | ET TROJAN Win32.Sality User-Agent (Internet Explorer 5.01); |
11,196 | 2015/01/20 | 2013962 | ET DELETED Possible Exploit Kit Delivering Executable to Client; [1] |
11,195 | 2015/01/20 | 2013961 | ET DELETED Blackhole Exploit Kit Delivering Java Exploit to Client; [1] |
11,194 | 2015/01/20 | 2013960 | ET CURRENT_EVENTS Blackhole Exploit Kit Delivering PDF Exploit to Client; [1] |
11,193 | 2015/01/20 | 2013959 | ET TROJAN Win32.Sality User-Agent (DEBUT.TMP); |
11,192 | 2015/01/20 | 2013956 | ET TROJAN W32/SmartPops Adware Outbound Off-Port MSSQL Communication; |
11,191 | 2015/01/20 | 2013955 | ET CURRENT_EVENTS Jupiter Exploit Kit Landing Page with Malicious Java Applets; |
11,190 | 2015/01/20 | 2013954 | ET TROJAN Win32/Rimecud.A User-Agent (giftz); [1,2] |
11,189 | 2015/01/20 | 2013953 | ET TROJAN Win32/Rimecud.A User-Agent (counters); [1,2] |
11,188 | 2015/01/20 | 2013952 | ET TROJAN TR/Rimecud.aksa User-Agent (indy); [1,2] |
11,187 | 2015/01/20 | 2013951 | ET TROJAN Win32/Rimecud.A User-Agent (needit); [1,2] |
11,186 | 2015/01/20 | 2013950 | ET CURRENT_EVENTS Blackhole obfuscated Javascript padded charcodes 25; |
11,185 | 2015/01/20 | 2013949 | ET TROJAN PWS.TIBIA Checkin or Data Post 2; |
11,184 | 2015/01/20 | 2013948 | ET TROJAN PWS.TIBIA Checkin or Data Post; |
11,183 | 2015/01/20 | 2013947 | ET TROJAN FakeAV.EGZ Checkin 2; |
11,182 | 2015/01/20 | 2013946 | ET TROJAN FakeAV.EGZ Checkin 1; [1] |
11,181 | 2015/01/20 | 2013945 | ET WEB_SERVER Weevely PHP backdoor detected (exec() function used); [1] |
11,180 | 2015/01/20 | 2013944 | ET WEB_SERVER Weevely PHP backdoor detected (perl->system() function used); [1] |
11,179 | 2015/01/20 | 2013943 | ET WEB_SERVER Weevely PHP backdoor detected (pcntl_exec() function used); [1] |
11,178 | 2015/01/20 | 2013942 | ET WEB_SERVER Weevely PHP backdoor detected (python_eval() function used); [1] |
11,177 | 2015/01/20 | 2013941 | ET WEB_SERVER Weevely PHP backdoor detected (popen() function used); [1] |
11,176 | 2015/01/20 | 2013940 | ET WEB_SERVER Weevely PHP backdoor detected (proc_open() function used); [1] |
11,175 | 2015/01/20 | 2013939 | ET WEB_SERVER Weevely PHP backdoor detected (shell_exec() function used); [1] |
11,174 | 2015/01/20 | 2013938 | ET WEB_SERVER Weevely PHP backdoor detected (passthru() function used); [1] |
11,173 | 2015/01/20 | 2013937 | ET WEB_SERVER Weevely PHP backdoor detected (system() function used); [1] |
11,172 | 2015/01/20 | 2013936 | ET POLICY SSH banner detected on TCP 443 likely proxy evasion; |
11,171 | 2015/01/20 | 2013935 | ET TROJAN Win32.Zbot.chas/Unruy.H Covert DNS CnC Channel TXT Response; |
11,170 | 2015/01/20 | 2013934 | ET TROJAN Win32.Fareit.A/Pony Downloader Checkin; [1,2,3,4,5,6] |
11,169 | 2015/01/20 | 2013933 | ET POLICY HTTP traffic on port 443 (CONNECT); |
11,168 | 2015/01/20 | 2013932 | ET POLICY HTTP traffic on port 443 (TRACE); |
11,167 | 2015/01/20 | 2013931 | ET POLICY HTTP traffic on port 443 (DELETE); |
11,166 | 2015/01/20 | 2013930 | ET POLICY HTTP traffic on port 443 (PUT); |
11,165 | 2015/01/20 | 2013929 | ET POLICY HTTP traffic on port 443 (OPTIONS); |
11,164 | 2015/01/20 | 2013928 | ET POLICY HTTP traffic on port 443 (PROPFIND); |
11,163 | 2015/01/20 | 2013927 | ET POLICY HTTP traffic on port 443 (HEAD); |
11,162 | 2015/01/20 | 2013926 | ET POLICY HTTP traffic on port 443 (POST); |
< 311 312 313 314 315 316 317 318 319 320 > |