IPS Signature Database Update

Name ips.sig
Version 3.0.66
StoneOS NIPS/IDS 5.5R5-3.5 or above, and BDS 5.5R8-3.3 or above
Release Date 2021-07-26
New Signature
(286)
Rule ID Rule Name Detail
105632 Linux/Xorddos DDoS Attack Participation click for more information
105595 APT32/OceanLotus Associated Domain Observed click for more information
105622 GandCrab Ransomware CnC/IP Check Domain Observed click for more information
333827 Win32/GandCrab Ransomware IP Address Check M2 click for more information
333782 Win32/IRCBot.ARX Connectivity Check click for more information
105627 OSX/OceanLotus.D CnC DNS Lookup click for more information
333844 W32/Trickbot IP check click for more information
714983 ATTACKER IRCBot - ipconfig - PRIVMSG Command click for more information
1908997 Duqu 2.0 Accessing SMB/SMB2 Named Pipe (Unicode) 5 click for more information
105608 GandCrab Ransomware Domain Observed click for more information
333737 Trickbot Webinject Activity M2 (response) click for more information
714992 ATTACKER IRCBot - PRIVMSG Response - ipconfig command output click for more information
714943 MSIL/IRCbot.M!bit Command (Join) click for more information
333799 WildFire Locker CnC Activity click for more information
333754 RemoteAccess.Win32/Prorat reporting via ICQ WWW script click for more information
714952 Dark Halo/SUNBURST SSL Cert Inbound click for more information
105599 GandCrab Domain Observed click for more information
333816 Trojan-Locker.AndroidOS.Sauron CnC Beacon 2 click for more information
333775 Trickbot Checkin Response click for more information
714965 DarkComet-RAT CnC Response (inv) click for more information
......
Updated Signature
(1)
Rule ID Rule Name Detail
330099 HAProxy cookie Denial of Service Vulnerability (CVE-2019-14241) Click here for more information