| 번호 | 날짜 | ID | 시그니처 (Total Ruleset: 27,111개) |
| 23,611 | 2016/09/24 | 2023260 | ET TROJAN Libyan Scorpions Netwire RAT DNS Lookup (wininit .myq-see.com); [1] |
| 23,610 | 2016/09/24 | 2023261 | ET TROJAN ABUSE.CH Ransomware Domain Detected (Locky C2); [1] |
| 23,609 | 2016/09/24 | 2023262 | ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Gozi MITM); [1] |
| 23,608 | 2016/09/24 | 2023258 | ET TROJAN Libyan Scorpions Adwind DNS Lookup (sara2011 .no-ip.biz); [1] |
| 23,607 | 2016/09/24 | 2023259 | ET TROJAN Libyan Scorpions Netwire RAT DNS Lookup (samsung .ddns.me); [1] |
| 23,606 | 2016/09/24 | 2023256 | ET TROJAN Libyan Scorpions Adwind DNS Lookup (winmeif .myq-see.com); [1] |
| 23,605 | 2016/09/24 | 2023255 | ET SMTP Incoming SMTP Message with Possibly Malicious MIME Epilogue 2016-05-13 (BadEpilogue); [1] |
| 23,604 | 2016/09/24 | 2023257 | ET TROJAN Libyan Scorpions Adwind DNS Lookup (collge .myq-see.com); [1] |
| 23,603 | 2016/09/24 | 2023254 | ET TROJAN MSIL/Spy.Agent.HF Checkin; [1,2] |
| 23,602 | 2016/09/22 | 2023253 | ET EXPLOIT CVE-2015-2419 As observed in Magnitude EK; |
| 23,601 | 2016/09/21 | 2023251 | ET CURRENT_EVENTS Evil Redirector Leading to EK Sep 19 2016 (EItest Inject) M2; |
| 23,600 | 2016/09/21 | 2023252 | ET CURRENT_EVENTS Evil Redirector Leading to EK Sep 20 2016; |
| 23,599 | 2016/09/21 | 2023250 | ET CURRENT_EVENTS Evil Redirector Leading to EK Sep 19 2016 (EItest Inject); |
| 23,598 | 2016/09/21 | 2023247 | ET TROJAN Ransomware Locky .onion Payment Domain (f5xraa2y2ybtrefz); |
| 23,597 | 2016/09/21 | 2023249 | ET CURRENT_EVENTS Possible EITest Flash Redirect Sep 19 2016; |
| 23,596 | 2016/09/21 | 2023248 | ET CURRENT_EVENTS Evil Redirector Leading to EK Sep 19 2016; |
| 23,595 | 2016/09/17 | 2023246 | ET TROJAN Windows sc query Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,594 | 2016/09/16 | 2023243 | ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Gozi MITM); [1] |
| 23,593 | 2016/09/16 | 2023241 | ET TROJAN LuminosityLink - Inbound Data Channel CnC Delimiter; |
| 23,592 | 2016/09/16 | 2023245 | ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Gozi MITM); [1] |
| 23,591 | 2016/09/16 | 2023244 | ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Gozi MITM); [1] |
| 23,590 | 2016/09/16 | 2023242 | ET TROJAN LuminosityLink - Outbound Data Channel CnC Delimiter; |
| 23,589 | 2016/09/16 | 2023224 | ET TROJAN Windows WMIC SHARE get Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,588 | 2016/09/16 | 2023226 | ET TROJAN Windows WMIC STARTUP get Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,587 | 2016/09/16 | 2023236 | ET CURRENT_EVENTS Microsoft Tech Support Scam M2 Sept 15 2016; |
| 23,586 | 2016/09/16 | 2023240 | ET MOBILE_MALWARE iOS DualToy Checkin; [1] |
| 23,585 | 2016/09/16 | 2023231 | ET WEB_SERVER HTTP Request to a *.33db9538.com domain - Anuna Checkin - Compromised PHP Site; [1,2] |
| 23,584 | 2016/09/16 | 2023228 | ET WEB_SERVER DNS Query for Suspicious 9507c4e8.com Domain - Anuna Checkin - Compromised PHP Site; [1,2] |
| 23,583 | 2016/09/16 | 2023238 | ET CURRENT_EVENTS PC Support Tech Support Scam Sept 15 2016; |
| 23,582 | 2016/09/16 | 2023239 | ET CURRENT_EVENTS Microsoft Tech Support Scam M3 Sept 15 2016; |
| 23,581 | 2016/09/16 | 2023229 | ET WEB_SERVER DNS Query for Suspicious e5b57288.com Domain - Anuna Checkin - Compromised PHP Site; [1,2] |
| 23,580 | 2016/09/16 | 2023233 | ET WEB_SERVER HTTP Request to a *.e5b57288.com domain - Anuna Checkin - Compromised PHP Site; [1,2] |
| 23,579 | 2016/09/16 | 2023235 | ET CURRENT_EVENTS Microsoft Tech Support Scam M1 Sept 15 2016; |
| 23,578 | 2016/09/16 | 2023237 | ET CURRENT_EVENTS Possible Fake AV Phone Scam Long Domain Sept 15 2016; |
| 23,577 | 2016/09/16 | 2023234 | ET WEB_SERVER HTTP Request to a *.54dfa1cb.com domain - Anuna Checkin - Compromised PHP Site; [1,2] |
| 23,576 | 2016/09/16 | 2023227 | ET WEB_SERVER DNS Query for Suspicious 33db9538.com Domain - Anuna Checkin - Compromised PHP Site; [1,2] |
| 23,575 | 2016/09/16 | 2023230 | ET WEB_SERVER DNS Query for Suspicious 54dfa1cb.com Domain - Anuna Checkin - Compromised PHP Site; [1,2] |
| 23,574 | 2016/09/16 | 2023232 | ET WEB_SERVER HTTP Request to a *.9507c4e8.com domain - Anuna Checkin - Compromised PHP Site; [1,2] |
| 23,573 | 2016/09/16 | 2023225 | ET TROJAN Windows WMIC SYSACCOUNT get Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,572 | 2016/09/16 | 2023221 | ET TROJAN Windows WMIC PROCESS get Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,571 | 2016/09/16 | 2023219 | ET TROJAN Windows WMIC NETLOGIN get Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,570 | 2016/09/16 | 2023217 | ET TROJAN Windows WMIC OS get Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,569 | 2016/09/16 | 2023218 | ET TROJAN Windows WMIC COMPUTERSYSTEM get Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,568 | 2016/09/16 | 2023223 | ET TROJAN Windows WMIC SERVICE get Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,567 | 2016/09/16 | 2023222 | ET TROJAN Windows WMIC SERVER get Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,566 | 2016/09/16 | 2023220 | ET TROJAN Windows WMIC NIC get Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,565 | 2016/09/16 | 2023216 | ET TROJAN Windows netsh advfirewall show allprofiles Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,564 | 2016/09/16 | 2023214 | ET TROJAN Windows quser Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,563 | 2016/09/16 | 2023215 | ET TROJAN Windows gpresult Microsoft Windows DOS prompt command exit OUTBOUND; |
| 23,562 | 2016/09/16 | 2023213 | ET TROJAN Windows qwinsta Microsoft Windows DOS prompt command exit OUTBOUND; |
| < 71 72 73 74 75 76 77 78 79 80 > |