[***] Summary: [***]
2 new OPEN, 15 new PRO (2 + 13). Trojan-Spy.AndroidOS.Agent.aab
Checkin and PHISHING.
Due to company holiday observations, there will be no signatures
released Friday, 12/31/2021 or Monday, 1/3/2022.
Please share issues, feedback, and requests at
https://feedback.emergingthreats.net/feedback
[+++] Added rules: [+++]
Open:
2034829 - ET POLICY DNS Query for Observed CVE-2021-44228 Callback
Domain (dns .cyberwar .nl) (policy.rules)
2034846 - ET MALWARE Observed Malicious SSL Cert (showmypc.com)
(malware.rules)
Pro:
2850741 - ETPRO MOBILE_MALWARE Trojan-Spy.AndroidOS.Agent.aab
Checkin (mobile_malware.rules)
2850742 - ETPRO MOBILE_MALWARE Trojan-Spy.AndroidOS.Agent.aab
Checkin 2 (mobile_malware.rules)
2850743 - ETPRO MOBILE_MALWARE Trojan-Spy.AndroidOS.Agent.aab
Checkin 3 (mobile_malware.rules)
2850744 - ETPRO MOBILE_MALWARE Trojan-Spy.AndroidOS.Agent.aab
Checkin 4 (mobile_malware.rules)
2850745 - ETPRO CURRENT_EVENTS Successful Generic Phish 2021-12-29
(set) (current_events.rules)
2850746 - ETPRO CURRENT_EVENTS Successful Generic Phish 2021-12-29
(current_events.rules)
2850747 - ETPRO CURRENT_EVENTS Successful Generic Phish 2021-12-29
(current_events.rules)
2850748 - ETPRO CURRENT_EVENTS Successful Generic Phish 2021-12-29
(current_events.rules)
2850749 - ETPRO CURRENT_EVENTS Successful Westpac One Phish
2021-12-29 (current_events.rules)
2850750 - ETPRO CURRENT_EVENTS Successful Netflix Phish 2021-12-29
(current_events.rules)
2850751 - ETPRO CURRENT_EVENTS Succesful Generic Phish 2021-12-29
(current_events.rules)
[///] Modified active rules: [///]
2018793 - ET TROJAN EUPUDS.A Requests for Boleto replacement (trojan.rules)
[---] Disabled rules: [---]
2034670 - ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228
Callback Domain (bingsearchlib .com) (attack_response.rules)
[---] Removed rules: [---]
2034829 - ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228
Callback Domain (dns .cyberwar .nl) (attack_response.rules)