| 번호 | 날짜 | ID | 시그니처 (Total Ruleset: 27,111개) | 
| 23,611 | 2016/09/24 |  2023260  |  ET TROJAN Libyan Scorpions Netwire RAT DNS Lookup (wininit .myq-see.com); [1]  | 
| 23,610 | 2016/09/24 |  2023261  |  ET TROJAN ABUSE.CH Ransomware Domain Detected (Locky C2); [1]  | 
| 23,609 | 2016/09/24 |  2023262  |  ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Gozi MITM); [1]  | 
| 23,608 | 2016/09/24 |  2023258  |  ET TROJAN Libyan Scorpions Adwind DNS Lookup (sara2011 .no-ip.biz); [1]  | 
| 23,607 | 2016/09/24 |  2023259  |  ET TROJAN Libyan Scorpions Netwire RAT DNS Lookup (samsung .ddns.me); [1]  | 
| 23,606 | 2016/09/24 |  2023256  |  ET TROJAN Libyan Scorpions Adwind DNS Lookup (winmeif .myq-see.com); [1]  | 
| 23,605 | 2016/09/24 |  2023255  |  ET SMTP Incoming SMTP Message with Possibly Malicious MIME Epilogue 2016-05-13 (BadEpilogue); [1]  | 
| 23,604 | 2016/09/24 |  2023257  |  ET TROJAN Libyan Scorpions Adwind DNS Lookup (collge .myq-see.com); [1]  | 
| 23,603 | 2016/09/24 |  2023254  |  ET TROJAN MSIL/Spy.Agent.HF Checkin; [1,2]  | 
| 23,602 | 2016/09/22 |  2023253  |  ET EXPLOIT CVE-2015-2419 As observed in Magnitude EK;   | 
| 23,601 | 2016/09/21 |  2023251  |  ET CURRENT_EVENTS Evil Redirector Leading to EK Sep 19 2016 (EItest Inject) M2;   | 
| 23,600 | 2016/09/21 |  2023252  |  ET CURRENT_EVENTS Evil Redirector Leading to EK Sep 20 2016;   | 
| 23,599 | 2016/09/21 |  2023250  |  ET CURRENT_EVENTS Evil Redirector Leading to EK Sep 19 2016 (EItest Inject);   | 
| 23,598 | 2016/09/21 |  2023247  |  ET TROJAN Ransomware Locky .onion Payment Domain (f5xraa2y2ybtrefz);   | 
| 23,597 | 2016/09/21 |  2023249  |  ET CURRENT_EVENTS Possible EITest Flash Redirect Sep 19 2016;   | 
| 23,596 | 2016/09/21 |  2023248  |  ET CURRENT_EVENTS Evil Redirector Leading to EK Sep 19 2016;   | 
| 23,595 | 2016/09/17 |  2023246  |  ET TROJAN Windows sc query Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,594 | 2016/09/16 |  2023243  |  ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Gozi MITM); [1]  | 
| 23,593 | 2016/09/16 |  2023241  |  ET TROJAN LuminosityLink - Inbound Data Channel CnC Delimiter;   | 
| 23,592 | 2016/09/16 |  2023245  |  ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Gozi MITM); [1]  | 
| 23,591 | 2016/09/16 |  2023244  |  ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Gozi MITM); [1]  | 
| 23,590 | 2016/09/16 |  2023242  |  ET TROJAN LuminosityLink - Outbound Data Channel CnC Delimiter;   | 
| 23,589 | 2016/09/16 |  2023224  |  ET TROJAN Windows WMIC SHARE get Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,588 | 2016/09/16 |  2023226  |  ET TROJAN Windows WMIC STARTUP get Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,587 | 2016/09/16 |  2023236  |  ET CURRENT_EVENTS Microsoft Tech Support Scam M2 Sept 15 2016;   | 
| 23,586 | 2016/09/16 |  2023240  |  ET MOBILE_MALWARE iOS DualToy Checkin; [1]  | 
| 23,585 | 2016/09/16 |  2023231  |  ET WEB_SERVER HTTP Request to a *.33db9538.com domain - Anuna Checkin - Compromised PHP Site; [1,2]  | 
| 23,584 | 2016/09/16 |  2023228  |  ET WEB_SERVER DNS Query for Suspicious 9507c4e8.com Domain - Anuna Checkin - Compromised PHP Site; [1,2]  | 
| 23,583 | 2016/09/16 |  2023238  |  ET CURRENT_EVENTS PC Support Tech Support Scam Sept 15 2016;   | 
| 23,582 | 2016/09/16 |  2023239  |  ET CURRENT_EVENTS Microsoft Tech Support Scam M3 Sept 15 2016;   | 
| 23,581 | 2016/09/16 |  2023229  |  ET WEB_SERVER DNS Query for Suspicious e5b57288.com Domain - Anuna Checkin - Compromised PHP Site; [1,2]  | 
| 23,580 | 2016/09/16 |  2023233  |  ET WEB_SERVER HTTP Request to a *.e5b57288.com domain - Anuna Checkin - Compromised PHP Site; [1,2]  | 
| 23,579 | 2016/09/16 |  2023235  |  ET CURRENT_EVENTS Microsoft Tech Support Scam M1 Sept 15 2016;   | 
| 23,578 | 2016/09/16 |  2023237  |  ET CURRENT_EVENTS Possible Fake AV Phone Scam Long Domain Sept 15 2016;   | 
| 23,577 | 2016/09/16 |  2023234  |  ET WEB_SERVER HTTP Request to a *.54dfa1cb.com domain - Anuna Checkin - Compromised PHP Site; [1,2]  | 
| 23,576 | 2016/09/16 |  2023227  |  ET WEB_SERVER DNS Query for Suspicious 33db9538.com Domain - Anuna Checkin - Compromised PHP Site; [1,2]  | 
| 23,575 | 2016/09/16 |  2023230  |  ET WEB_SERVER DNS Query for Suspicious 54dfa1cb.com Domain - Anuna Checkin - Compromised PHP Site; [1,2]  | 
| 23,574 | 2016/09/16 |  2023232  |  ET WEB_SERVER HTTP Request to a *.9507c4e8.com domain - Anuna Checkin - Compromised PHP Site; [1,2]  | 
| 23,573 | 2016/09/16 |  2023225  |  ET TROJAN Windows WMIC SYSACCOUNT get Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,572 | 2016/09/16 |  2023221  |  ET TROJAN Windows WMIC PROCESS get Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,571 | 2016/09/16 |  2023219  |  ET TROJAN Windows WMIC NETLOGIN get Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,570 | 2016/09/16 |  2023217  |  ET TROJAN Windows WMIC OS get Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,569 | 2016/09/16 |  2023218  |  ET TROJAN Windows WMIC COMPUTERSYSTEM get Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,568 | 2016/09/16 |  2023223  |  ET TROJAN Windows WMIC SERVICE get Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,567 | 2016/09/16 |  2023222  |  ET TROJAN Windows WMIC SERVER get Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,566 | 2016/09/16 |  2023220  |  ET TROJAN Windows WMIC NIC get Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,565 | 2016/09/16 |  2023216  |  ET TROJAN Windows netsh advfirewall show allprofiles Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,564 | 2016/09/16 |  2023214  |  ET TROJAN Windows quser Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,563 | 2016/09/16 |  2023215  |  ET TROJAN Windows gpresult Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| 23,562 | 2016/09/16 |  2023213  |  ET TROJAN Windows qwinsta Microsoft Windows DOS prompt command exit OUTBOUND;   | 
| < 71  72  73  74  75  76  77  78  79  80 > |