Sourcefire VRT Rules Update

Date: 2008-07-01

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2.6.

The format of the file is:

sid - Message (rule group)

New rules:
13866 <-> SPYWARE-PUT Trackware adclicker-fc.gen.a runtime detection - popup ads (spyware-put.rules)
13867 <-> SPYWARE-PUT Trackware adclicker-fc.gen.a runtime detection (spyware-put.rules)
13868 <-> SPYWARE-PUT Adware antispywaremaster runtime detection - start fake scanning (spyware-put.rules)
13869 <-> SPYWARE-PUT Adware antispywaremaster runtime detection - sale/register request (spyware-put.rules)
13870 <-> SPYWARE-PUT Adware coopen 5.0.0.87 runtime detection - init conn (spyware-put.rules)
13871 <-> SPYWARE-PUT Adware coopen 5.0.0.87 runtime detection - ads (spyware-put.rules)
13872 <-> SPYWARE-PUT Trickler fushion 1.2.4.17 runtime detection - notice (spyware-put.rules)
13873 <-> SPYWARE-PUT Trickler fushion 1.2.4.17 runtime detection - underground traffic (spyware-put.rules)
13874 <-> SPYWARE-PUT Adware malware destructor 4.5 runtime detection - order request (spyware-put.rules)
13875 <-> SPYWARE-PUT Adware malware destructor 4.5 runtime detection - auto update (spyware-put.rules)
13876 <-> BACKDOOR zlob.acc runtime detection (backdoor.rules)
13877 <-> BACKDOOR trojan-spy.win32.delf.uv runtime detection (backdoor.rules)
13878 <-> BACKDOOR trojan-spy.win32.delf.uv runtime detection (backdoor.rules)