Talos Rules 2020-09-03
This release adds and modifies rules in several categories.

Talos has added and modified multiple rules in the browser-chrome, browser-webkit, malware-other and server-webapp rule sets to provide coverage for emerging threats from these technologies.

For information about Snort Subscriber Rulesets available for purchase, please visit the Snort product page.

Change logs

2020-09-03 12:28:34 UTC

Snort Subscriber Rules Update

Date: 2020-09-03

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091601.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:54924 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54925 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54926 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54927 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54928 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54929 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54930 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54931 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54932 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54933 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54934 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54935 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54936 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54937 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54938 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54939 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54940 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54941 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54942 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54943 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54944 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54945 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54946 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54947 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54948 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54949 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54950 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54951 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54952 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54953 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54954 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54955 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54956 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54957 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54958 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54959 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54960 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54961 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54962 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54963 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54964 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54965 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54966 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54967 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54968 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54969 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54970 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54971 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54972 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54973 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54974 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54975 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54976 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54977 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54978 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54979 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54980 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54981 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54982 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54983 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54984 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54985 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54986 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54987 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54988 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54989 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54990 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54991 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54992 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54993 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54994 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54995 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54996 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54997 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54998 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:54999 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:55000 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55001 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55002 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55003 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55004 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55005 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55006 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55007 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55008 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55009 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55010 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55011 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55012 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55013 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55014 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55015 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55019 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55020 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55021 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55022 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55023 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55024 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55025 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55026 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55027 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55028 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55029 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55030 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55031 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55032 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55033 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:55034 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 3:55016 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55018 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55017 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55036 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)
 * 3:55035 <-> ENABLED <-> SERVER-OTHER Cisco Jabber client remote code execution attempt (server-other.rules)
 * 3:55037 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)

Modified Rules:



2020-09-03 12:28:34 UTC

Snort Subscriber Rules Update

Date: 2020-09-03

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091600.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55008 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55009 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55007 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55010 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55011 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55012 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55013 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55014 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55015 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55019 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55020 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55021 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55022 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55023 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55024 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55025 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55026 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55027 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55028 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55029 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55030 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55031 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55032 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55033 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:55034 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:54924 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54926 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54925 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54928 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54927 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54930 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54929 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54932 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54931 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54933 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54935 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54934 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54937 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54936 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54939 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54938 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54941 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54940 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54943 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54942 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54944 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54946 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54945 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54948 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54947 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54949 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54951 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54950 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54953 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54952 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54955 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54954 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54957 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54956 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54959 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54958 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54961 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54960 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54962 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54963 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54965 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54964 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54967 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54966 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54969 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54968 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54971 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54970 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54972 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54973 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54975 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54974 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54976 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54978 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54977 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54980 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54979 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54982 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54981 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54984 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54983 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54986 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54985 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54988 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54987 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54990 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54989 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54991 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54993 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54992 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54995 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54994 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54997 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54996 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54998 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:54999 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:55001 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55000 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55003 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55002 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55004 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55005 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55006 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 3:55017 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55016 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55018 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55036 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)
 * 3:55035 <-> ENABLED <-> SERVER-OTHER Cisco Jabber client remote code execution attempt (server-other.rules)
 * 3:55037 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)

Modified Rules:



2020-09-03 12:28:34 UTC

Snort Subscriber Rules Update

Date: 2020-09-03

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091501.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55011 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55012 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55013 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55014 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55015 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55019 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55020 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55021 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55022 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55023 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55024 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55025 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55026 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55027 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55028 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55029 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55030 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55031 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55032 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55033 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:55034 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:54924 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54925 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54926 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54927 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54928 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54929 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54930 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54931 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54932 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54933 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54934 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54935 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54936 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54937 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54938 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54939 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54940 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54941 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54942 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54943 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54944 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54945 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54946 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54947 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54948 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54949 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54950 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54951 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54952 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54953 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54954 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54955 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54956 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54957 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54958 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54959 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54960 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54961 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54962 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54963 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54964 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54965 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54966 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54967 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54968 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54969 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54970 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54971 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54972 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54973 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54974 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54975 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54976 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54977 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54978 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54979 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54980 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54981 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54982 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54983 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54984 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54985 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54986 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54987 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54988 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54989 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54990 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54991 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54992 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54993 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54994 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54995 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54996 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54997 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54998 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:54999 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:55000 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55001 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55002 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55003 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55004 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55005 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55007 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55006 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55008 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55009 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55010 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 3:55016 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55018 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55017 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55036 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)
 * 3:55037 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)
 * 3:55035 <-> ENABLED <-> SERVER-OTHER Cisco Jabber client remote code execution attempt (server-other.rules)

Modified Rules:



2020-09-03 12:28:34 UTC

Snort Subscriber Rules Update

Date: 2020-09-03

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091500.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55022 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55023 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55024 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55025 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55026 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55029 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55030 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55031 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55032 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55033 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:55034 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:55020 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55005 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55021 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55027 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55028 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:54924 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54925 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54926 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54927 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54928 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54929 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54930 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54931 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54932 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54933 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54934 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54935 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54936 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54937 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54938 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54939 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54940 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54941 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54942 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54943 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54944 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54945 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54946 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54947 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54948 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54949 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54950 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54951 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54952 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54953 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54954 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54955 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54956 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54957 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54958 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54959 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54960 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54961 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54962 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54963 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54964 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54965 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54966 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54967 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54968 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54969 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54970 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54971 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54972 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54973 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54974 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54975 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54976 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54977 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54978 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54979 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54980 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54981 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54982 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54983 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54984 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54985 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54986 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54987 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54988 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54989 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54990 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54991 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54992 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54993 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54994 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54995 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54996 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54997 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54998 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:54999 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:55000 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55007 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55001 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55019 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55002 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55013 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55003 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55014 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55009 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55011 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55012 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55010 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55008 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55015 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55006 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55004 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 3:55016 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55035 <-> ENABLED <-> SERVER-OTHER Cisco Jabber client remote code execution attempt (server-other.rules)
 * 3:55017 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55036 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)
 * 3:55018 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55037 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)

Modified Rules:



2020-09-03 12:28:34 UTC

Snort Subscriber Rules Update

Date: 2020-09-03

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091401.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55007 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55021 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55023 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55022 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55020 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55024 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55025 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55026 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55027 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55029 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55028 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55005 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55030 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55032 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55031 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55034 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:55033 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:54924 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54925 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54926 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54927 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54928 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54929 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54930 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54931 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54932 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54933 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54934 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54935 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54936 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54937 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54938 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54939 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54940 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54941 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54942 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54943 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54944 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54945 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54946 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54947 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54948 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54949 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54950 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54951 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54952 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54953 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54954 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54955 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54956 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54957 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54958 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54959 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54960 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54961 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54962 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54963 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54964 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54965 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54966 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54967 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54968 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54969 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54970 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54971 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54972 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54973 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54974 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54975 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54976 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54977 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54978 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54979 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54980 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54981 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54982 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54983 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54984 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54985 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54986 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54987 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54988 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54989 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54990 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54991 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54992 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54993 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54994 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54995 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54996 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54997 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54998 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:54999 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:55000 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55001 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55002 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55019 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55003 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55004 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55013 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55006 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55011 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55015 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55012 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55010 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55008 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55009 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55014 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 3:55035 <-> ENABLED <-> SERVER-OTHER Cisco Jabber client remote code execution attempt (server-other.rules)
 * 3:55018 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55016 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55017 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55036 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)
 * 3:55037 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)

Modified Rules:



2020-09-03 12:28:34 UTC

Snort Subscriber Rules Update

Date: 2020-09-03

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091300.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55014 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55021 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55023 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55022 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55020 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55024 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55025 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55026 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55027 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55029 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55028 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55008 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55010 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55005 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55031 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55030 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55033 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:55034 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:55032 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55007 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55012 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55015 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:54924 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54925 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54926 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54927 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54928 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54929 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54930 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54931 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54932 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54933 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54934 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54935 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54936 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54937 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54938 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54939 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54940 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54941 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54942 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54943 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54944 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54945 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54946 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54947 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54948 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54949 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54950 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54951 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54952 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54953 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54954 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54955 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54956 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54957 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54958 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54959 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54960 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54961 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54962 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54963 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54964 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54965 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54966 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54967 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54968 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54969 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54970 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54971 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54972 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54973 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54974 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54975 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54976 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54977 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54978 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54979 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54980 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54981 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54982 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54983 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54984 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54985 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54986 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54987 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54988 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:55011 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55009 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:54989 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54990 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54991 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54992 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54993 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54994 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54995 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54996 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:55006 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:54997 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54998 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:54999 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:55000 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55013 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55001 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55019 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55002 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55003 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55004 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 3:55017 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55035 <-> ENABLED <-> SERVER-OTHER Cisco Jabber client remote code execution attempt (server-other.rules)
 * 3:55037 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)
 * 3:55036 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)
 * 3:55018 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55016 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)

Modified Rules:



2020-09-03 12:28:34 UTC

Snort Subscriber Rules Update

Date: 2020-09-03

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091101.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55027 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:55019 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55023 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55022 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55029 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55020 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55024 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55005 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55025 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55009 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55010 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55014 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55015 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:55032 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55030 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55033 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:55031 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55034 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:55007 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55021 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55028 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:54924 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54925 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54926 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54927 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54928 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54929 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54930 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54931 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54932 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54933 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54934 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54935 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54936 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54937 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54938 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54939 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54940 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54941 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54942 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54943 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54944 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54945 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54946 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54947 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54948 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54949 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54950 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54951 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54952 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54953 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54954 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54955 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54956 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54957 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54958 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54959 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54960 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54961 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54962 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54963 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54964 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54965 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54966 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54967 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54968 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54969 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54970 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54971 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54972 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54973 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:54974 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54975 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54976 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54977 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:54978 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54979 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54980 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54981 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54982 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:54983 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:55012 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:54984 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54985 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54986 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:55006 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:54987 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54988 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54989 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54990 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54991 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54992 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54993 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54994 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54995 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54996 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54997 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54998 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:54999 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:55000 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55001 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55002 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55003 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55026 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55004 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55008 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55011 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55013 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 3:55018 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55016 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55017 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55035 <-> ENABLED <-> SERVER-OTHER Cisco Jabber client remote code execution attempt (server-other.rules)
 * 3:55036 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)
 * 3:55037 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)

Modified Rules:



2020-09-03 12:28:34 UTC

Snort Subscriber Rules Update

Date: 2020-09-03

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3000.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:55021 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (snort3-malware-other.rules)
 * 1:55019 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (snort3-malware-other.rules)
 * 1:54924 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (snort3-malware-other.rules)
 * 1:55034 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (snort3-malware-other.rules)
 * 1:54925 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (snort3-malware-other.rules)
 * 1:55033 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (snort3-malware-other.rules)
 * 1:54926 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (snort3-malware-other.rules)
 * 1:54927 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (snort3-malware-other.rules)
 * 1:54928 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (snort3-malware-other.rules)
 * 1:54929 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (snort3-malware-other.rules)
 * 1:54930 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (snort3-malware-other.rules)
 * 1:54931 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (snort3-malware-other.rules)
 * 1:54932 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (snort3-malware-other.rules)
 * 1:54933 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (snort3-malware-other.rules)
 * 1:54934 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (snort3-malware-other.rules)
 * 1:54935 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (snort3-malware-other.rules)
 * 1:54936 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (snort3-malware-other.rules)
 * 1:54937 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (snort3-malware-other.rules)
 * 1:54938 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (snort3-malware-other.rules)
 * 1:54939 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (snort3-malware-other.rules)
 * 1:54940 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (snort3-malware-other.rules)
 * 1:54941 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (snort3-malware-other.rules)
 * 1:54942 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (snort3-malware-other.rules)
 * 1:54943 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (snort3-malware-other.rules)
 * 1:54944 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (snort3-malware-other.rules)
 * 1:54945 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (snort3-malware-other.rules)
 * 1:54946 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (snort3-malware-other.rules)
 * 1:54947 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (snort3-malware-other.rules)
 * 1:54948 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (snort3-malware-other.rules)
 * 1:54949 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (snort3-malware-other.rules)
 * 1:54950 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (snort3-malware-other.rules)
 * 1:54951 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (snort3-malware-other.rules)
 * 1:54952 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (snort3-malware-other.rules)
 * 1:54953 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (snort3-malware-other.rules)
 * 1:54954 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (snort3-malware-other.rules)
 * 1:54955 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (snort3-malware-other.rules)
 * 1:54956 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (snort3-malware-other.rules)
 * 1:54957 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (snort3-malware-other.rules)
 * 1:54958 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (snort3-malware-other.rules)
 * 1:54959 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (snort3-malware-other.rules)
 * 1:54960 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (snort3-malware-other.rules)
 * 1:54961 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (snort3-malware-other.rules)
 * 1:54962 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (snort3-malware-other.rules)
 * 1:54963 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (snort3-malware-other.rules)
 * 1:54964 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (snort3-malware-other.rules)
 * 1:54965 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (snort3-malware-other.rules)
 * 1:54966 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (snort3-malware-other.rules)
 * 1:54967 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (snort3-malware-other.rules)
 * 1:54968 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (snort3-malware-other.rules)
 * 1:54969 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (snort3-malware-other.rules)
 * 1:54970 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (snort3-malware-other.rules)
 * 1:54971 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (snort3-malware-other.rules)
 * 1:54972 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (snort3-malware-other.rules)
 * 1:54973 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (snort3-malware-other.rules)
 * 1:54974 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (snort3-malware-other.rules)
 * 1:54975 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (snort3-malware-other.rules)
 * 1:54976 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (snort3-malware-other.rules)
 * 1:54977 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (snort3-malware-other.rules)
 * 1:54978 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (snort3-malware-other.rules)
 * 1:54979 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (snort3-malware-other.rules)
 * 1:54980 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (snort3-malware-other.rules)
 * 1:54981 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (snort3-malware-other.rules)
 * 1:54982 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (snort3-malware-other.rules)
 * 1:54983 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (snort3-malware-other.rules)
 * 1:54984 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (snort3-malware-other.rules)
 * 1:54985 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (snort3-malware-other.rules)
 * 1:54986 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (snort3-malware-other.rules)
 * 1:54987 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (snort3-malware-other.rules)
 * 1:54988 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (snort3-malware-other.rules)
 * 1:54991 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (snort3-malware-other.rules)
 * 1:54992 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (snort3-malware-other.rules)
 * 1:54993 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (snort3-malware-other.rules)
 * 1:54994 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (snort3-server-webapp.rules)
 * 1:54995 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (snort3-server-webapp.rules)
 * 1:55027 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (snort3-malware-other.rules)
 * 1:54996 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (snort3-malware-other.rules)
 * 1:54997 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (snort3-malware-other.rules)
 * 1:54998 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (snort3-malware-other.rules)
 * 1:54999 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (snort3-malware-other.rules)
 * 1:55000 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (snort3-malware-other.rules)
 * 1:55001 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (snort3-malware-other.rules)
 * 1:55002 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (snort3-malware-other.rules)
 * 1:55003 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (snort3-malware-other.rules)
 * 1:55025 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (snort3-malware-other.rules)
 * 1:55004 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (snort3-malware-other.rules)
 * 1:55005 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (snort3-malware-other.rules)
 * 1:55006 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (snort3-malware-other.rules)
 * 1:55024 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (snort3-malware-other.rules)
 * 1:55007 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (snort3-malware-other.rules)
 * 1:55008 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (snort3-malware-other.rules)
 * 1:55028 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (snort3-malware-other.rules)
 * 1:55030 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (snort3-malware-other.rules)
 * 1:55029 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (snort3-malware-other.rules)
 * 1:55032 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (snort3-malware-other.rules)
 * 1:55031 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (snort3-malware-other.rules)
 * 1:55020 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (snort3-malware-other.rules)
 * 1:55026 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (snort3-malware-other.rules)
 * 1:54989 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (snort3-malware-other.rules)
 * 1:54990 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (snort3-malware-other.rules)
 * 1:55014 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (snort3-malware-other.rules)
 * 1:55010 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (snort3-malware-other.rules)
 * 1:55023 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (snort3-malware-other.rules)
 * 1:55011 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (snort3-malware-other.rules)
 * 1:55022 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (snort3-malware-other.rules)
 * 1:55015 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (snort3-malware-other.rules)
 * 1:55012 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (snort3-browser-webkit.rules)
 * 1:55009 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (snort3-malware-other.rules)
 * 1:55013 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (snort3-browser-webkit.rules)

Modified Rules:



2020-09-03 12:28:34 UTC

Snort Subscriber Rules Update

Date: 2020-09-03

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2983.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:54969 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54958 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:55002 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:55023 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55001 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:55022 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:55024 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (malware-other.rules)
 * 1:55020 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 1:55009 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:55029 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:54993 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54985 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:54995 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:55031 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:55030 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (malware-other.rules)
 * 1:55032 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (malware-other.rules)
 * 1:54972 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:55015 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:54963 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54924 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54926 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54925 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (malware-other.rules)
 * 1:54927 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (malware-other.rules)
 * 1:54929 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54928 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (malware-other.rules)
 * 1:54931 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54930 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (malware-other.rules)
 * 1:54933 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54932 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (malware-other.rules)
 * 1:54935 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54934 <-> DISABLED <-> MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (malware-other.rules)
 * 1:54937 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54936 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (malware-other.rules)
 * 1:54939 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54938 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (malware-other.rules)
 * 1:54941 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54940 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (malware-other.rules)
 * 1:54942 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54944 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54943 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (malware-other.rules)
 * 1:54946 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54945 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (malware-other.rules)
 * 1:54948 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54947 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (malware-other.rules)
 * 1:54949 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (malware-other.rules)
 * 1:54950 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54952 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54951 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (malware-other.rules)
 * 1:54954 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54953 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (malware-other.rules)
 * 1:54979 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54997 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54992 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (malware-other.rules)
 * 1:54990 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:55033 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:54983 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:55006 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:55014 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (malware-other.rules)
 * 1:54989 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:55004 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:55007 <-> DISABLED <-> MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (malware-other.rules)
 * 1:54970 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:55012 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:55028 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:54996 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (malware-other.rules)
 * 1:54986 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54988 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (malware-other.rules)
 * 1:54987 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (malware-other.rules)
 * 1:54981 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:55026 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:55005 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (malware-other.rules)
 * 1:54955 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (malware-other.rules)
 * 1:54971 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (malware-other.rules)
 * 1:54977 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:55021 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (malware-other.rules)
 * 1:54960 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:55008 <-> DISABLED <-> MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (malware-other.rules)
 * 1:54964 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:55011 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:55034 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (malware-other.rules)
 * 1:54974 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:54956 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:55027 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (malware-other.rules)
 * 1:54961 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (malware-other.rules)
 * 1:54973 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (malware-other.rules)
 * 1:55013 <-> DISABLED <-> BROWSER-WEBKIT WebKit AudioArray allocate out of bounds access attempt (browser-webkit.rules)
 * 1:54999 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:54994 <-> DISABLED <-> SERVER-WEBAPP TeamViewer custom URL protocol handler SMB connection attempt (server-webapp.rules)
 * 1:54968 <-> DISABLED <-> MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (malware-other.rules)
 * 1:54967 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54957 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (malware-other.rules)
 * 1:54959 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (malware-other.rules)
 * 1:54965 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Egkk-9627862-0 download attempt (malware-other.rules)
 * 1:54966 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (malware-other.rules)
 * 1:54998 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (malware-other.rules)
 * 1:55003 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (malware-other.rules)
 * 1:54975 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (malware-other.rules)
 * 1:55000 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Delf-9632869-0 download attempt (malware-other.rules)
 * 1:54976 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (malware-other.rules)
 * 1:55025 <-> DISABLED <-> MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (malware-other.rules)
 * 1:54982 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (malware-other.rules)
 * 1:55010 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (malware-other.rules)
 * 1:54980 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (malware-other.rules)
 * 1:54991 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (malware-other.rules)
 * 1:54978 <-> DISABLED <-> MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (malware-other.rules)
 * 1:54962 <-> DISABLED <-> MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (malware-other.rules)
 * 1:54984 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (malware-other.rules)
 * 1:55019 <-> DISABLED <-> MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (malware-other.rules)
 * 3:55018 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55016 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55017 <-> ENABLED <-> SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (server-other.rules)
 * 3:55037 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)
 * 3:55035 <-> ENABLED <-> SERVER-OTHER Cisco Jabber client remote code execution attempt (server-other.rules)
 * 3:55036 <-> ENABLED <-> BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (browser-chrome.rules)

Modified Rules: