Talos Rules 2020-09-15
This release adds and modifies rules in several categories.

Talos has added and modified multiple rules in the and os-windows rule sets to provide coverage for emerging threats from these technologies.

Change logs

2020-09-15 19:49:47 UTC

Snort Subscriber Rules Update

Date: 2020-09-15

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091601.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55669 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55670 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55671 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55672 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55673 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55674 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55675 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55676 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55677 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55678 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55679 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55680 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55681 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55682 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55683 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55684 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55685 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55686 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55687 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55688 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55689 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)
 * 1:55690 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)
 * 1:55691 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55692 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55693 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55694 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55695 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55696 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55697 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55698 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55699 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55700 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55701 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55702 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55703 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerReqChallenge elevation of privilege attempt (os-windows.rules)
 * 1:55704 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerAuthenticate or NetrServerPasswordSet elevation of privilege attempt (os-windows.rules)
 * 1:55649 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55650 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55651 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55652 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55653 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55654 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55655 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55656 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55657 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55658 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55659 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55660 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55661 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55662 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55663 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55664 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55665 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55666 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55667 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55668 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)

Modified Rules:



2020-09-15 19:49:47 UTC

Snort Subscriber Rules Update

Date: 2020-09-15

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091600.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55690 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)
 * 1:55649 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55650 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55651 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55652 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55653 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55654 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55655 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55656 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55657 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55658 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55659 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55660 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55661 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55662 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55663 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55664 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55665 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55666 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55667 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55668 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55669 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55670 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55694 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55693 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55695 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55696 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55697 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55698 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55699 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55700 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55701 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55702 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55703 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerReqChallenge elevation of privilege attempt (os-windows.rules)
 * 1:55704 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerAuthenticate or NetrServerPasswordSet elevation of privilege attempt (os-windows.rules)
 * 1:55692 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55691 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55671 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55672 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55673 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55674 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55675 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55676 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55677 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55678 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55679 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55680 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55681 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55682 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55683 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55684 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55685 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55686 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55687 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55688 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55689 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)

Modified Rules:



2020-09-15 19:49:47 UTC

Snort Subscriber Rules Update

Date: 2020-09-15

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091501.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55649 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55650 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55651 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55652 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55653 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55654 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55655 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55656 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55657 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55658 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55659 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55660 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55661 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55662 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55663 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55664 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55665 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55666 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55667 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55668 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55669 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55690 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)
 * 1:55670 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55693 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55692 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55691 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55671 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55694 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55695 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55697 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55696 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55698 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55699 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55700 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55701 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55702 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55703 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerReqChallenge elevation of privilege attempt (os-windows.rules)
 * 1:55704 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerAuthenticate or NetrServerPasswordSet elevation of privilege attempt (os-windows.rules)
 * 1:55672 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55673 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55674 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55675 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55676 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55677 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55678 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55679 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55680 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55681 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55682 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55683 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55684 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55685 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55686 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55687 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55688 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55689 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)

Modified Rules:



2020-09-15 19:49:47 UTC

Snort Subscriber Rules Update

Date: 2020-09-15

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091500.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55695 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55694 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55697 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55698 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55699 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55700 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55701 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55702 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55703 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerReqChallenge elevation of privilege attempt (os-windows.rules)
 * 1:55704 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerAuthenticate or NetrServerPasswordSet elevation of privilege attempt (os-windows.rules)
 * 1:55649 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55650 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55651 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55652 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55653 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55654 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55655 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55690 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)
 * 1:55696 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55656 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55657 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55658 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55659 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55692 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55660 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55661 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55691 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55662 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55663 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55664 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55665 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55666 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55667 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55668 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55669 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55670 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55671 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55672 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55693 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55673 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55674 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55675 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55676 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55677 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55678 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55679 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55680 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55681 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55682 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55683 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55684 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55685 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55686 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55687 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55688 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55689 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)

Modified Rules:



2020-09-15 19:49:47 UTC

Snort Subscriber Rules Update

Date: 2020-09-15

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091401.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55691 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55694 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55693 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55697 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55649 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55650 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55651 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55690 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)
 * 1:55652 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55695 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55699 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55698 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55701 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55700 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55703 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerReqChallenge elevation of privilege attempt (os-windows.rules)
 * 1:55702 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55704 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerAuthenticate or NetrServerPasswordSet elevation of privilege attempt (os-windows.rules)
 * 1:55653 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55696 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55654 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55655 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55656 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55657 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55658 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55659 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55660 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55661 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55692 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55662 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55663 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55664 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55665 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55666 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55667 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55668 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55669 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55670 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55671 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55672 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55673 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55674 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55675 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55676 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55677 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55678 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55679 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55680 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55681 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55682 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55683 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55684 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55685 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55686 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55687 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55688 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55689 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)

Modified Rules:



2020-09-15 19:49:47 UTC

Snort Subscriber Rules Update

Date: 2020-09-15

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091300.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55690 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)
 * 1:55695 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55698 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55701 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55700 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55699 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55702 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55704 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerAuthenticate or NetrServerPasswordSet elevation of privilege attempt (os-windows.rules)
 * 1:55703 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerReqChallenge elevation of privilege attempt (os-windows.rules)
 * 1:55649 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55650 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55693 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55651 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55697 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55652 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55653 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55696 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55654 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55655 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55692 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55656 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55657 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55694 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55658 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55691 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55659 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55660 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55661 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55662 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55663 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55664 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55665 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55666 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55667 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55668 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55669 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55670 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55671 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55672 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55673 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55674 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55675 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55676 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55677 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55678 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55679 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55680 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55681 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55682 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55683 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55684 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55685 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55686 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55687 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55688 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55689 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)

Modified Rules:



2020-09-15 19:49:47 UTC

Snort Subscriber Rules Update

Date: 2020-09-15

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091101.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55696 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55690 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)
 * 1:55695 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55700 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55701 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55699 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55698 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55704 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerAuthenticate or NetrServerPasswordSet elevation of privilege attempt (os-windows.rules)
 * 1:55703 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerReqChallenge elevation of privilege attempt (os-windows.rules)
 * 1:55702 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55693 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55649 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55697 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55650 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55651 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55652 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55691 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55653 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55654 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55655 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55656 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55694 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55692 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55657 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55658 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55659 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55660 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55661 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55662 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55663 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55664 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55665 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55666 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55667 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55668 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55669 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55670 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55671 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55672 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55673 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55674 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55675 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55676 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55677 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55678 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55679 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55680 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55681 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55682 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55683 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55684 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55685 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55686 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55687 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55688 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55689 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)

Modified Rules:



2020-09-15 19:49:47 UTC

Snort Subscriber Rules Update

Date: 2020-09-15

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3000.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55690 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (snort3-malware-other.rules)
 * 1:55696 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (snort3-malware-other.rules)
 * 1:55695 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (snort3-malware-other.rules)
 * 1:55700 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (snort3-malware-other.rules)
 * 1:55699 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (snort3-malware-other.rules)
 * 1:55698 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (snort3-malware-other.rules)
 * 1:55704 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerAuthenticate or NetrServerPasswordSet elevation of privilege attempt (snort3-os-windows.rules)
 * 1:55702 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (snort3-malware-other.rules)
 * 1:55701 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (snort3-malware-other.rules)
 * 1:55703 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerReqChallenge elevation of privilege attempt (snort3-os-windows.rules)
 * 1:55693 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (snort3-malware-other.rules)
 * 1:55697 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (snort3-malware-other.rules)
 * 1:55649 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (snort3-malware-other.rules)
 * 1:55650 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (snort3-malware-other.rules)
 * 1:55651 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (snort3-malware-other.rules)
 * 1:55692 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (snort3-malware-other.rules)
 * 1:55652 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (snort3-malware-other.rules)
 * 1:55653 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (snort3-malware-other.rules)
 * 1:55654 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (snort3-malware-other.rules)
 * 1:55655 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (snort3-malware-other.rules)
 * 1:55656 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (snort3-malware-other.rules)
 * 1:55657 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (snort3-malware-other.rules)
 * 1:55658 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (snort3-malware-other.rules)
 * 1:55659 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (snort3-malware-other.rules)
 * 1:55660 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (snort3-malware-other.rules)
 * 1:55661 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (snort3-malware-other.rules)
 * 1:55662 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (snort3-malware-other.rules)
 * 1:55694 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (snort3-malware-other.rules)
 * 1:55663 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (snort3-malware-other.rules)
 * 1:55664 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (snort3-malware-other.rules)
 * 1:55665 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (snort3-malware-other.rules)
 * 1:55666 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (snort3-malware-other.rules)
 * 1:55691 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (snort3-malware-other.rules)
 * 1:55667 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (snort3-malware-other.rules)
 * 1:55668 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (snort3-malware-other.rules)
 * 1:55669 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (snort3-malware-other.rules)
 * 1:55670 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (snort3-malware-other.rules)
 * 1:55671 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (snort3-malware-other.rules)
 * 1:55672 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (snort3-malware-other.rules)
 * 1:55673 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (snort3-malware-other.rules)
 * 1:55674 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (snort3-malware-other.rules)
 * 1:55675 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (snort3-malware-other.rules)
 * 1:55676 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (snort3-malware-other.rules)
 * 1:55677 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (snort3-malware-other.rules)
 * 1:55678 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (snort3-malware-other.rules)
 * 1:55679 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (snort3-malware-other.rules)
 * 1:55680 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (snort3-malware-other.rules)
 * 1:55681 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (snort3-malware-other.rules)
 * 1:55682 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (snort3-malware-other.rules)
 * 1:55683 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (snort3-malware-other.rules)
 * 1:55684 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (snort3-malware-other.rules)
 * 1:55685 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (snort3-malware-other.rules)
 * 1:55686 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (snort3-malware-other.rules)
 * 1:55687 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (snort3-malware-other.rules)
 * 1:55688 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (snort3-malware-other.rules)
 * 1:55689 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (snort3-malware-other.rules)

Modified Rules:



2020-09-15 19:49:47 UTC

Snort Subscriber Rules Update

Date: 2020-09-15

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2983.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55700 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55697 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55695 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55693 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)
 * 1:55696 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (malware-other.rules)
 * 1:55649 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55650 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (malware-other.rules)
 * 1:55651 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55652 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (malware-other.rules)
 * 1:55653 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55691 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55654 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (malware-other.rules)
 * 1:55655 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55656 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (malware-other.rules)
 * 1:55657 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55658 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (malware-other.rules)
 * 1:55659 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55660 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (malware-other.rules)
 * 1:55661 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55662 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (malware-other.rules)
 * 1:55663 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55664 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (malware-other.rules)
 * 1:55665 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55666 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (malware-other.rules)
 * 1:55667 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55668 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (malware-other.rules)
 * 1:55669 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55690 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)
 * 1:55670 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (malware-other.rules)
 * 1:55671 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55672 <-> DISABLED <-> MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (malware-other.rules)
 * 1:55673 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55674 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (malware-other.rules)
 * 1:55675 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55676 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (malware-other.rules)
 * 1:55677 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55678 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (malware-other.rules)
 * 1:55679 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55680 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (malware-other.rules)
 * 1:55698 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (malware-other.rules)
 * 1:55681 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55699 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (malware-other.rules)
 * 1:55682 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (malware-other.rules)
 * 1:55683 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55701 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55684 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Zeus-9760773-0 download attempt (malware-other.rules)
 * 1:55702 <-> DISABLED <-> MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (malware-other.rules)
 * 1:55685 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55703 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerReqChallenge elevation of privilege attempt (os-windows.rules)
 * 1:55686 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (malware-other.rules)
 * 1:55704 <-> ENABLED <-> OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerAuthenticate or NetrServerPasswordSet elevation of privilege attempt (os-windows.rules)
 * 1:55687 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55688 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (malware-other.rules)
 * 1:55689 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (malware-other.rules)
 * 1:55692 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (malware-other.rules)
 * 1:55694 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (malware-other.rules)

Modified Rules: