번호 | 날짜 | ID | 시그니처 (Total Ruleset: 27,111개) | 7,511 | 2015/01/20 | 2009824 | ET TROJAN Downloader.Win32.Delf followon POST Data PUSH Packet; [1,2] | 7,510 | 2015/01/20 | 2009823 | ET WEB_SERVER Attempt To Access MSSQL xp_enumdsn/xp_enumgroups/xp_ntsec_enumdomains Stored Procedure Via URI; [1,2,3,4] | 7,509 | 2015/01/20 | 2009822 | ET WEB_SERVER Attempt To Access MSSQL xp_readerrorlogs Stored Procedure Via URI to View Error Logs; [1,2,3] | 7,508 | 2015/01/20 | 2009820 | ET WEB_SERVER Attempt To Access MSSQL xp_enumerrorlogs Stored Procedure Via URI to View Error Logs; [1,2,3] | 7,507 | 2015/01/20 | 2009819 | ET WEB_SERVER Attempt To Access MSSQL xp_fileexist Stored Procedure Via URI to Locate Files On Disk; [1,2,3,4] | 7,506 | 2015/01/20 | 2009818 | ET WEB_SERVER Attempt To Access MSSQL xp_regread/xp_regwrite/xp_regdeletevalue/xp_regdeletekey Stored Procedure Via URI to Modify Registry; [1,2,3] | 7,505 | 2015/01/20 | 2009817 | ET WEB_SERVER Attempt To Access MSSQL sp_adduser Stored Procedure Via URI to Create New Database User; [1,2] | 7,504 | 2015/01/20 | 2009816 | ET WEB_SERVER Attempt To Access MSSQL xp_servicecontrol Stored Procedure Via URI; [1,2] | 7,503 | 2015/01/20 | 2009815 | ET WEB_SERVER Attempt To Access MSSQL xp_cmdshell Stored Procedure Via URI; [1,2,3] | 7,502 | 2015/01/20 | 2009814 | ET DELETED Downloader (Win32.Doneltart) Checkin - HTTP GET; [1] | 7,501 | 2015/01/20 | 2009813 | ET TROJAN Trojan.MyDNS DNSChanger - HTTP POST; [1] | 7,500 | 2015/01/20 | 2009812 | ET TROJAN AVKiller with Backdoor checkin; [1] | 7,499 | 2015/01/20 | 2009811 | ET TROJAN KillAV/Dropper/Mdrop/Hupigon - HTTP GET; [1] | 7,498 | 2015/01/20 | 2009810 | ET TROJAN Swizzor-based Downloader - Invalid User-Agent (Mozilla/4.0 (compatible MSIE 7.0 na .NET CLR 2.0.50727 .NET CLR 3.0.4506.2152 .NET CLR 3.5.30729)); [1,2] | 7,497 | 2015/01/20 | 2009809 | ET MALWARE Adware/Antivirus360 Config to client; [1] | 7,496 | 2015/01/20 | 2009808 | ET TROJAN Win32.Virut - GET; [1,2,3,4,5] | 7,495 | 2015/01/20 | 2009807 | ET MALWARE 2020search/PowerSearch Toolbar Adware/Spyware - GET; [1,2,3,4] | 7,494 | 2015/01/20 | 2009806 | ET TROJAN Poison Ivy RAT/Backdoor follow on POST Data PUSH Packet; [1,2,3] | 7,493 | 2015/01/20 | 2009805 | ET TROJAN Luder.B User-Agent (Mozilla/4.0 (SPGK)) - GET; [1,2,3] | 7,492 | 2015/01/20 | 2009804 | ET TROJAN Screenblaze SCR Related Backdoor - GET; [1,2,3,4,5] | 7,491 | 2015/01/20 | 2009803 | ET DELETED Downloader Generic - GET; [1] | 7,490 | 2015/01/20 | 2009801 | ET POLICY Carbonite.com Backup Software User-Agent (Carbonite Installer); [1] | 7,489 | 2015/01/20 | 2009800 | ET POLICY Carbonite.com Backup Software Leaking MAC Address; [1] | 7,488 | 2015/01/20 | 2009799 | ET WEB_SERVER PHP Attack Tool Morfeus F Scanner - M; [1,2] | 7,487 | 2015/01/20 | 2009798 | ET POLICY Carbonite Online Backup SSL Handshake; [1] | 7,486 | 2015/01/20 | 2009797 | ET DELETED Bifrose Response from victim; [1] | 7,485 | 2015/01/20 | 2009796 | ET MALWARE FakeAV Windows Protection Suite/ReleaseXP.exe User-Agent (Releasexp); [1] | 7,484 | 2015/01/20 | 2009795 | ET WEB_SPECIFIC_APPS Dog Pedigree Online Database managePerson.php personId Parameter SQL Injection; [1,2] | 7,483 | 2015/01/20 | 2009794 | ET WEB_SPECIFIC_APPS VidShare Pro listing_video.php catid Parameter SQL Injection; [1,2] | 7,482 | 2015/01/20 | 2009793 | ET WEB_SPECIFIC_APPS PHP Crawler footer.php footer_file Parameter Remote File Inclusion; [1,2] | 7,481 | 2015/01/20 | 2009792 | ET ACTIVEX Avax Vector avPreview.ocx ActiveX Control Buffer Overflow; [1,2,3] | 7,480 | 2015/01/20 | 2009791 | ET WEB_SPECIFIC_APPS GS Real Estate Portal email.php AgentID Parameter SQL Injection; [1,2,3,4] | 7,479 | 2015/01/20 | 2009790 | ET WEB_SPECIFIC_APPS beLive arch.php arch Parameter Local File Inclusion; [1,2,3] | 7,478 | 2015/01/20 | 2009789 | ET WEB_SPECIFIC_APPS TinyButStrong bs_us_examples_0view.php script Parameter Local File Inclusion; [1,2,3] | 7,477 | 2015/01/20 | 2009788 | ET WEB_SPECIFIC_APPS RSS-aggregator display.php path Parameter Remote File Inclusion; [1,2] | 7,476 | 2015/01/20 | 2009787 | ET WEB_SPECIFIC_APPS Community CMS view.php article_id Parameter SQL Injection; [1,2] | 7,475 | 2015/01/20 | 2009785 | ET MALWARE QVOD Related Spyware/Malware User-Agent (Qvod); [1,2,3] | 7,474 | 2015/01/20 | 2009783 | ET MALWARE RubyFortune Spyware Capabilities User-Agent (Microgaming Install Program) - GET; [1,2,3,4] | 7,473 | 2015/01/20 | 2009780 | ET WEB_SPECIFIC_APPS Joomla Full Path Disclosure -- content.php; [1,2] | 7,472 | 2015/01/20 | 2009779 | ET WEB_SPECIFIC_APPS Joomla Full Path Disclosure -- ldap.php; [1,2] | 7,471 | 2015/01/20 | 2009778 | ET WEB_SPECIFIC_APPS Joomla Full Path Disclosure -- php5x.php; [1,2] | 7,470 | 2015/01/20 | 2009776 | ET TROJAN Oficla Downloader Activity Observed; [1,2,3] | 7,469 | 2015/01/20 | 2009773 | ET WEB_SERVER Possible INSERT INTO SQL Injection In Cookie; [1,2,3,4] | 7,468 | 2015/01/20 | 2009772 | ET WEB_SERVER Possible DELETE FROM SQL Injection In Cookie; [1,2,3,4] | 7,467 | 2015/01/20 | 2009771 | ET WEB_SERVER Possible SELECT FROM SQL Injection In Cookie; [1,2,3,4] | 7,466 | 2015/01/20 | 2009770 | ET WEB_SERVER Possible UNION SELECT SQL Injection In Cookie; [1,2,3,4,5] | 7,465 | 2015/01/20 | 2009769 | ET SCAN SQL Power Injector SQL Injection User Agent Detected; [1,2,3] | 7,464 | 2015/01/20 | 2009768 | ET SCAN NBTStat Query Response to External Destination, Possible Windows Network Enumeration; [1,2] | 7,463 | 2015/01/20 | 2009767 | ET SCAN Multiple NBTStat Query Responses to External Destination, Possible Automated Windows Network Enumeration; [1,2] | 7,462 | 2015/01/20 | 2009766 | ET MALWARE IE Toolbar User-Agent (IEToolbar); [1] | < 391 392 393 394 395 396 397 398 399 400 > |
|