[***] Summary: [***]

7 new Pro signatures, 18 new Pro (7+11). Upatre, Various AndroidOS, Password Stealer.

Thanks: Kevin Ross.

[+++] Added rules: [+++]

Open:

2018800 - ET SCAN Chroot-apache0day Unknown Web Scanner User Agent (scan.rules)
2018801 - ET CURRENT_EVENTS Possible Upatre SSL Cert disenart.info (current_events.rules)
2018802 - ET CURRENT_EVENTS Possible Upatre SSL Cert host-galaxy.com (current_events.rules)
2018803 - ET CURRENT_EVENTS Possible Upatre SSL Cert fxbingpanel.fareexchange.co.uk (current_events.rules)
2018804 - ET CURRENT_EVENTS Possible Upatre SSL Cert 66h.66hosting.net (current_events.rules)
2018805 - ET CURRENT_EVENTS Possible Upatre SSL Cert businesswebstudios.com (current_events.rules)
2018806 - ET CURRENT_EVENTS Possible Upatre SSL Cert udderperfection.com (current_events.rules)

Pro:

2808461 - ETPRO MALWARE Win32/BrowseFox.H Checkin 2 (malware.rules)
2808462 - ETPRO MOBILE_MALWARE AndroidOS/GinMaster.AR Checkin (mobile_malware.rules)
2808463 - ETPRO TROJAN Win32/Viknok.D Checkin 1 (trojan.rules)
2808464 - ETPRO TROJAN Win32/Viknok.D Checkin 2 (trojan.rules)
2808465 - ETPRO TROJAN Password Stealer MSIL/VOJIN.A Sending Stolen Info (trojan.rules)
2808466 - ETPRO MOBILE_MALWARE AndroidOS/FakePlayer.A Checkin (mobile_malware.rules)
2808467 - ETPRO MOBILE_MALWARE Android/SMForw.BV Checkin (mobile_malware.rules)
2808468 - ETPRO TROJAN Worm MSIL/Vonriamt.A Checkin 1 (trojan.rules)
2808469 - ETPRO TROJAN Worm MSIL/Vonriamt.A Checkin 2 (trojan.rules)
2808470 - ETPRO TROJAN Password Stealer MSIL/Vonriamt.A Checkin 3 (trojan.rules)
2808471 - ETPRO MOBILE_MALWARE Trojan-SMS.AndroidOS.FakeInst.a Checkin 3 (mobile_malware.rules)

[///] Modified active rules: [///]

2018785 - ET CURRENT_EVENTS Possible ShellCode Passed as Argument to FlashVars (current_events.rules)
2807692 - ETPRO TROJAN Trojan.Banker.ACF Checkin (trojan.rules)
Date: 
Monday, July 28, 2014 - 22:00