Sourcefire VRT Update for Sourcefire 3D System

Date: 2014-01-07

This SRU number: 2014-01-06-002
Previous SRU number: 2013-12-30-001

Applies to:

This SEU number: 1025
Previous SEU: 1022

Applies to:

This is the complete list of rules modified in SRU 2014-01-06-002 and SEU 1025.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
16291MALWARE-CNCjustjoke v2.6 variant outbound connectionoffoffdrop
17624MALWARE-BACKDOORremote control 1.7 runtime detection - data connectionoffoffalert
112165MALWARE-CNClithium 1.02 variant outbound connectionoffoffoff
112166MALWARE-CNClithium 1.02 variant outbound connectionoffoffalert
112661MALWARE-CNCtroll.a variant outbound connectionoffoffoff
113508MALWARE-CNCxploit 1.4.5 variant outbound connectionoffoffoff
113509MALWARE-CNCxploit 1.4.5 pc variant outbound connectionoffoffoff
113815MALWARE-CNCzombget.03 variant outbound connectionoffoffoff
113856MALWARE-CNCWin.Trojan.wintrim.z variant outbound connectionoffoffoff
113864POLICY-OTHERMicrosoft Windows Dr. Watson error reporting attemptoffoffoff
113876MALWARE-CNCzlob.acc variant outbound connectionoffoffoff
113877MALWARE-CNCWin.Trojan.delf.uv variant outbound connectionoffoffoff
114086MALWARE-CNCAdware.Win32.Agent.BM variant outbound connection 1offoffoff
114087MALWARE-CNCAdware.Win32.Agent.BM variant outbound connection 2offoffoff
115295MALWARE-CNCWin.Trojan.Bankpatch configuration downloadoffoffdrop
115296MALWARE-CNCWin.Trojan.Bankpatch malicious file downloadoffoffdrop
115297MALWARE-CNCWin.Trojan.Bankpatch report homeoffoffdrop
116097MALWARE-CNCWin.Trojan.agent.vvm variant outbound connectionoffoffoff
116099MALWARE-CNCWin.Trojan.agent.wdv variant outbound connectionoffoffoff
116108MALWARE-CNCWin.Trojan.exchanger.gen2 variant outbound connectionoffoffoff
116270DELETEDMALWARE-CNC Trojan.TDSS.1.Gen keepalive detection
116271MALWARE-CNCTrojan.TDSS.1.Gen keepalive detectionoffoffoff
116457MALWARE-CNCTrojan.Downloader.Win32.Cutwail.AI variant outbound connectionoffoffoff
118311SERVER-WEBAPPNovell iManager getMultiPartParameters arbitrary file upload attemptoffoffoff
118946MALWARE-CNCWin.Trojan.IRCBot.FC variant outbound connectionoffoffoff
118947MALWARE-CNCWin.Trojan.IRCBot.FC variant outbound connectionoffoffoff
118976MALWARE-CNCRogue-Software.AVCare variant outbound connectionoffoffoff
118977MALWARE-CNCTrojan-Proxy.Win32.Agent.boe variant outbound connectionoffoffoff
118978MALWARE-CNCWin.Trojan.Pasta.aoq variant outbound connectionoffoffdrop
118979MALWARE-CNCWorm.Win32.AutoRun.fmo variant outbound connectionoffoffdrop
118980MALWARE-CNCWinSpywareProtect variant outbound connectionoffoffoff
118981MALWARE-CNCWinSpywareProtect variant outbound connectionoffoffoff
118982MALWARE-CNCWinSpywareProtect variant outbound connectionoffoffoff
119016MALWARE-CNCMacBack Win.Trojan.variant outbound connectionoffdropdrop
119017MALWARE-CNCMacBack Win.Trojan.variant outbound connectionoffdropdrop
119018MALWARE-CNCMacBack Win.Trojan.variant outbound connectionoffdropdrop
119019MALWARE-CNCMacBack Win.Trojan.variant outbound connectionoffdropdrop
119021MALWARE-CNCTrojan-Downloader.Win32.FraudLoad.dzm variant outbound connectionoffoffoff
119022MALWARE-CNCTrojan-Downloader.Win32.FraudLoad.dzm variant outbound connectionoffoffoff
119023MALWARE-CNCIRC.Zapchast.zwrc variant outbound connectionoffoffoff
119024MALWARE-CNCWin.Trojan.StartPage variant outbound connectionoffoffoff
119025MALWARE-CNCTrojan-Banker.Win32.Bancos.etf variant outbound connectionoffoffoff
119027MALWARE-CNCBrowserModifier.Win32.Kerlofost variant outbound connectionoffoffoff
119028MALWARE-CNCTrojan-Mailfinder.Win32.Mailbot.dz variant outbound connectionoffoffoff
119029MALWARE-CNCWin.Trojan.PcClient.AI variant outbound connectionoffoffoff
119031MALWARE-CNCiPRIVACY variant outbound connectionoffoffoff
119032MALWARE-CNCTrojanDownloader.Win32.Cornfemo.A variant outbound connectionoffoffoff
119033MALWARE-CNCTrojanDownloader.Win32.Cornfemo.A variant outbound connectionoffoffoff
119034MALWARE-CNCWin.Trojan.Kbot.qd variant outbound connectionoffoffoff
119035MALWARE-CNCWin.Trojan.Vilsel.baqb variant outbound connectionoffoffoff
119053MALWARE-CNCWorm.Win32.Nusump.A variant outbound connectionoffdropdrop
119123MALWARE-CNCDropper Win.Trojan.Cefyns.A variant outbound connectionoffoffoff
119164MALWARE-CNCWin.Trojan.SpyEye variant outbound connectionoffdropdrop
119310MALWARE-CNCDownloader Trojan.Gen3 variant outbound connectionoffoffoff
119312MALWARE-CNCWin.Trojan.Agent.aah variant outbound connectionoffoffoff
119328MALWARE-CNCPointGuide variant outbound connectionoffdropdrop
119329MALWARE-CNCFaceback.exe variant outbound connectionoffoffoff
119330MALWARE-CNCAdclicker Win.Trojan.Zlob.dnz variant outbound connectionoffoffoff
119331MALWARE-CNCAdclicker Win.Trojan.Zlob.dnz variant outbound connectionoffoffoff
119332MALWARE-CNCWin.Trojan.Clampi variant outbound connectionoffoffoff
119339MALWARE-CNCWin.Trojan.Dropper Win.Trojan.Agent.alda variant outbound connectionoffdropdrop
119340MALWARE-CNCWin.Trojan.Fakeav TREAntivirus variant outbound connectionoffoffdrop
119341MALWARE-CNCWorm MSIL.AiO.a variant outbound connectionoffoffdrop
119345MALWARE-CNCREAnti variant outbound connectionoffoffdrop
119346MALWARE-CNCAdditional Guard variant outbound connectionoffoffdrop
119347MALWARE-CNCWin.Trojan.Poison.banr variant outbound connectionoffdropdrop
119348MALWARE-CNCWin.Trojan.Downloader Win.Trojan.FraudLoad.emq variant outbound connectionoffdropdrop
119349MALWARE-CNCFakeav Vaccineclear variant outbound connectionoffoffoff
119351MALWARE-CNCWin.Trojan.Clicker Win.Trojan.Hatigh.C variant outbound connectionoffdropdrop
119352MALWARE-CNCWin.Trojan.Small.D variant outbound connectionoffoffdrop
119353MALWARE-CNCWin.Trojan.Banker.bkhu variant outbound connectionoffdropdrop
119354MALWARE-BACKDOORWin.Trojan.Agent.bhxn variant outbound connectionoffoffdrop
119356MALWARE-CNCWin.Trojan.Fibbit.ax variant outbound connectionoffoffoff
119357MALWARE-CNCWorm Win.Trojan.Sohanad.ila variant outbound connectionoffdropdrop
119358MALWARE-CNCWin.Trojan.XYTvn.A variant outbound connectionoffdropdrop
119359MALWARE-CNCWin.Trojan.Dcbavict.A variant outbound connectionoffoffoff
119360MALWARE-CNCWin.Trojan.Dcbavict.A variant outbound connectionoffoffoff
119361MALWARE-CNCWin.Trojan.Dcbavict.A variant outbound connectionoffoffoff
119363MALWARE-CNCWin.Trojan.Dorkbot.B variant outbound connectionoffoffoff
119366MALWARE-CNCWin.Trojan.HXWAN.A variant outbound connectionoffoffdrop
119367MALWARE-CNCWorm Win.Trojan.Vaubeg.A variant outbound connectionoffoffdrop
119368MALWARE-CNCWin.Trojan.Carberp.D variant outbound connectionoffoffdrop
119369MALWARE-CNCWin.Trojan.Carberp.D variant outbound connectionoffoffdrop
119370MALWARE-CNCWin.Trojan.Carberp.D variant outbound connectionoffoffdrop
119371MALWARE-CNCWin.Trojan.Banker.IC variant outbound connectionoffoffoff
119394MALWARE-CNCWin.Trojan.Tidserv variant outbound connectionoffoffoff
119396MALWARE-CNCWin.Trojan.Beastdoor.b variant outbound connectionoffoffoff
119397MALWARE-CNCWin.Trojan.UltimateDefender.xv variant outbound connectionoffoffoff
119398MALWARE-CNCWin.Trojan.BAT.Shutdown.ef variant outbound connectionoffoffoff
119399MALWARE-CNCEmail Worm Win32.Zhelatin.ch variant outbound connectionoffoffoff
119400MALWARE-CNCWorm Win.Trojan.Sddrop.D variant outbound connectionoffoffoff
119401MALWARE-CNCWorm Win.Trojan.Sddrop.D variant outbound connectionoffoffoff
119402MALWARE-CNCP2P Worm.Win32.Malas.r variant outbound connectionoffoffoff
119404MALWARE-CNCWin.Trojan.Ozdok variant outbound connectionoffoffoff
119426MALWARE-CNCWin.Trojan.Downloader Win.Trojan.Crypter.i variant outbound connectionoffoffoff
119427MALWARE-CNCWin.Trojan.Agent.amjz variant outbound connectionoffoffoff
119428MALWARE-CNCWin.Trojan.Downloader Win.Trojan.Adload.BG variant outbound connectionoffoffoff
119433MALWARE-CNCW32.Fujacks.aw variant outbound connectionoffoffoff
119435MALWARE-CNCWin.Trojan.Litmus.203 variant outbound connectionoffdropdrop
119454MALWARE-CNCTrojan.PWS.Win32.QQPass.IK variant outbound connectionoffoffoff
119455MALWARE-CNCWorm.Win32.AutoRun.aw variant outbound connectionoffoffoff
119456MALWARE-CNCPacked.Win32.Klone.bj variant outbound connectionoffoffoff
119457MALWARE-CNCTrojan-Clicker.Win32.Vesloruki.ajb variant outbound connectionoffoffoff
119476MALWARE-CNCExploit.Win32.SqlShell.r variant outbound connectionoffoffoff
119478MALWARE-CNCWorm.Win32.Taterf.B variant outbound connectionoffoffoff
119479MALWARE-CNCNet-Worm.Win32.Piloyd.m variant outbound connection - request htmloffoffoff
119481MALWARE-CNCEmail-Worm.Win32.Agent.bx variant outbound connectionoffoffoff
119488MALWARE-CNCWorm.Win32.Failnum.A variant outbound connectionoffoffoff
119491MALWARE-CNCWin.Trojan.Downloader Win.Trojan.Genome.vau variant outbound connectionoffoffoff
119492MALWARE-CNCWindows System Defender variant outbound connectionoffoffoff
119494MALWARE-CNCW32.Licum variant outbound connectionoffoffoff
119495MALWARE-CNCWorm Win.Trojan.Pilleuz variant outbound connectionoffoffoff
119554MALWARE-CNCWin.Trojan.Fakeav Antivirus Xp Pro variant outbound connectionoffoffdrop
119555MALWARE-CNCWin.Trojan.Downloader Win.Trojan.Small.akow variant outbound connectionoffoffdrop
119556MALWARE-CNCWin.Trojan.Downloader Win.Trojan.Homa.dk variant outbound connectionoffoffdrop
119557MALWARE-CNCWin.Trojan.Shark.ag variant outbound connectionoffoffdrop
119568MALWARE-CNCTrojan-Spy.Win32.PerfectKeylogger variant outbound connectionoffoffoff
119569MALWARE-CNCTrojan-Downloader.Win32.Perkesh variant outbound connectionoffoffoff
119572MALWARE-CNCWin.Trojan.FFSearch.A variant outbound connectionoffoffoff
119573MALWARE-CNCWorm Win.Trojan.Chiviper.C variant outbound connectionoffoffoff
119574MALWARE-CNCWorm Win.Trojan.Chiviper.C variant outbound connectionoffoffoff
119575MALWARE-CNCWorm Win.Trojan.Emold.U variant outbound connectionoffoffoff
119577MALWARE-CNCWin.Trojan.Dropper Win.Trojan.Dogrobot.E variant outbound connectionoffoffoff
119579MALWARE-CNCWin.Trojan.Potao.A variant outbound connectionoffdropdrop
119581MALWARE-CNCWin.Trojan.Downloader.Win32.Apher.gpd variant outbound connectionoffoffoff
119582MALWARE-CNCWin.Trojan.Downloader.Win32.Apher.gpd variant outbound connectionoffoffoff
119583MALWARE-CNCWin.Trojan.Bumat.rts variant outbound connectionoffoffoff
119584MALWARE-CNCWorm Win.Trojan.Dref.C variant outbound connectionoffoffoff
119585MALWARE-CNCWorm Win.Trojan.Dref.C variant outbound connection - notificationoffoffoff
119586MALWARE-CNCWin.Trojan.Clicker Win.Trojan.Agent.dlg variant outbound connectionoffoffoff
119587MALWARE-CNCWin.Trojan.Sereki.B variant outbound connectionoffoffoff
119590MALWARE-CNCWin.Trojan.Savnut.B variant outbound connectionoffdropdrop
119591MALWARE-CNCWin.Trojan.Powp.pyv variant outbound connectionoffoffoff
119608MALWARE-CNCWin.Trojan.Wisscmd.A variant outbound connectionoffoffoff
119612MALWARE-CNCWin.Trojan.Downloader.Win32.Banload.bvk variant outbound connectionoffoffoff
119613MALWARE-CNCRogue Software Registry Cleaner Pro variant outbound connectionoffoffoff
119614MALWARE-CNCWin.Trojan.IRCBot.kkr variant outbound connectionoffoffoff
119615MALWARE-CNCWin.Trojan.IRCBot.kkr variant outbound connectionoffoffoff
119616MALWARE-CNCWin.Trojan.Banker.Win32.Banbra.mcq variant outbound connectionoffoffoff
119652MALWARE-CNCTeevsock C variant outbound connectionoffoffoff
119658MALWARE-CNCWin.Trojan.MCnovogic.A variant outbound connectionoffdropdrop
119659MALWARE-CNCWin.Trojan.Soleseq.A variant outbound connectionoffoffoff
119660MALWARE-CNCWin.Trojan.Riern.K variant outbound connectionoffoffoff
119695MALWARE-CNCWin.Trojan.Downloader.Win32.VB.nec variant outbound connectionoffoffoff
119697MALWARE-CNCWin.Trojan.Spy.Win32.VB.btm variant outbound connectionoffoffoff
119701MALWARE-CNCWin.Trojan.Hassar.A variant outbound connectionoffoffoff
119702MALWARE-CNCWin.Trojan.Zboter.E variant outbound connectionoffdropdrop
119704MALWARE-CNCWin.Trojan.Agent.grdm variant outbound connectionoffdropdrop
119705MALWARE-CNCWin.Trojan.Agent.grdm variant outbound connectionoffdropdrop
119706MALWARE-CNCWin.Trojan.Agent.cer variant outbound connectionoffdropdrop
119712MALWARE-CNCWin.Trojan.Downloader W32.Genome.gen variant outbound connectionoffdropdrop
119722MALWARE-CNCWin.Trojan.Poshtroper.A variant outbound connectionoffdropdrop
119723MALWARE-CNCWin.Trojan.Pherbot.A variant outbound connectionoffdropdrop
119724MALWARE-CNCWin.Trojan.Agent.dhy variant outbound connectionoffoffdrop
119725MALWARE-CNCWin.Trojan.Poison.AY variant outbound connectionoffoffdrop
119726MALWARE-CNCWin.Trojan.Poison.AY variant outbound connectionoffoffdrop
119727MALWARE-CNCWin.Trojan.Bancos.DI variant outbound connectionoffoffdrop
119728MALWARE-CNCWin.Trojan.Yayih.A variant outbound connectionoffoffoff
119729MALWARE-CNCWin.Trojan.Yayih.A variant outbound connectionoffoffoff
119730MALWARE-CNCWin.Trojan.KukuBot.A variant outbound connectionoffdropdrop
119731MALWARE-CNCWin.Trojan.Darkwebot.A variant outbound connectionoffdropdrop
119732MALWARE-CNCWin.Trojan.Idicaf.B variant outbound connectionoffdropdrop
119733MALWARE-CNCWin.Trojan.Jorik.BRU variant outbound connectionoffoffoff
119739MALWARE-CNCWin.Trojan.Apptom variant outbound connectionoffoffoff
119740MALWARE-CNCWorm.Win32.AutoRun.aczu variant outbound connectionoffoffoff
119742MALWARE-CNCWin.Trojan.Agent.atff variant outbound connectionoffoffoff
119743MALWARE-CNCWin.Trojan.Hupigon.eqlo variant outbound connectionoffoffoff
119745MALWARE-CNCWin.Trojan.FraudLoad.dyl variant outbound connectionoffoffoff
119746MALWARE-CNCWin.Trojan.Agent.biiw variant outbound connectionoffoffoff
119747MALWARE-BACKDOORWin.Trojan.GGDoor.22 variant outbound connectionoffdropdrop
119748MALWARE-CNCTrojan.Crypt.ULPM.Gen IRC variant outbound connectionoffoffoff
119760MALWARE-CNCWin.Trojan.Arsinfoder.A variant outbound connectionoffoffoff
119761MALWARE-CNCWin.Trojan.Ftpharvxqq.A variant outbound connectionoffdropdrop
119762MALWARE-CNCWin.Trojan.RDPdoor.AE variant outbound connectionoffoffoff
119763MALWARE-CNCWin.Trojan.RDPdoor.AE variant outbound connectionoffoffoff
119764MALWARE-CNCWin.Trojan.RDPdoor.AE variant outbound connectionoffoffoff
119765MALWARE-CNCWin.Trojan.Banker.BXF variant outbound connectionoffdropdrop
119766MALWARE-CNCWorm Win.Trojan.Autorun.hi variant outbound connectionoffoffoff
119767MALWARE-CNCWin.Trojan.Msposer.A variant outbound connectionoffdropdrop
119770MALWARE-CNCWin.Trojan.Yoddos.A variant outbound connectionoffdropdrop
119771MALWARE-CNCWin.Trojan.Yoddos.A variant outbound connectionoffdropdrop
119772MALWARE-CNCVirus.Win32.Parite.B variant outbound connectionoffoffoff
119773MALWARE-CNCVirus.Win32.Parite.B variant outbound connectionoffoffoff
119774MALWARE-CNCGen-Trojan.Heur variant outbound connectionoffoffoff
119776MALWARE-CNCWin.Trojan.Agent2.guy dropper variant outbound connectionoffoffoff
119783MALWARE-CNCWin.Trojan.Banload.agcw variant outbound connectionoffoffoff
119784MALWARE-CNCWorm.Win32.AutoRun.sde variant outbound connectionoffoffoff
119785MALWARE-CNCWin.Trojan.Downloader.Win32.Malushka.T variant outbound connectionoffoffoff
119787MALWARE-CNCExploit-PDF.t variant outbound connectionoffoffoff
119789MALWARE-CNCP2P Worm Win.Trojan.SpyBot.pgh variant outbound connectionoffoffoff
119790MALWARE-CNCP2P Worm Win.Trojan.SpyBot.pgh variant outbound connectionoffoffoff
119791MALWARE-CNCTrojan-Dropper.Win32.Small.awa variant outbound connectionoffoffoff
119792MALWARE-CNCWin.Trojan.Downloader Win.Trojan.Caxnet.A variant outbound connectionoffoffoff
119793MALWARE-CNCWin.Trojan.Downloader Win.Trojan.SillyFDC-DS variant outbound connectionoffoffoff
119794MALWARE-CNCW32.Fnumbot variant outbound connectionoffoffoff
119795MALWARE-CNCWin.Trojan.FakeAV NoAdware variant outbound connectionoffoffoff
119796MALWARE-CNCWin.Trojan.DL.CashnJoy.A variant outbound connectionoffoffoff
119797MALWARE-CNCSafety Center variant outbound connectionoffoffoff
119798MALWARE-CNCWin.Trojan.Agent2.kxu variant outbound connectionoffoffoff
119819MALWARE-CNCWin.Trojan.Ertfor.A variant outbound connectionoffoffoff
119820MALWARE-CNCWin.Trojan.Ertfor.A variant outbound connectionoffoffoff
119821MALWARE-CNCWorm.Win32.Bagle.gen.C variant outbound connectionoffoffoff
119822MALWARE-CNCWin.Trojan.Banload.HH variant outbound connectionoffoffoff
119824MALWARE-CNCGen-Trojan.Heur variant outbound connectionoffoffoff
119828MALWARE-CNCWin.Trojan.SpyAgent.B variant outbound connectionoffoffoff
119829MALWARE-CNCWin.Trojan.Rbot.gen variant outbound connectionoffoffoff
119830MALWARE-CNCWin.Trojan.Poebot.BP variant outbound connectionoffoffoff
119831MALWARE-CNCTrojan.Spy.Zbot.SO variant outbound connectionoffoffoff
119832MALWARE-CNCWin.Trojan.Veslorn.gen.A variant outbound connectionoffoffoff
119833MALWARE-CNCWin.Trojan.Banload.bda variant outbound connectionoffoffoff
119834MALWARE-CNCTrojan.Spy.ZBot.RD variant outbound connectionoffoffoff
119850MALWARE-CNCWorm.Win32.AutoRun.qgg variant outbound connectionoffoffoff
119851MALWARE-CNCWorm.Win32.AutoRun.qgg variant outbound connectionoffoffoff
119852MALWARE-CNCWin.Trojan.Downloader.Win32.Delf.tbv variant outbound connectionoffoffoff
119854MALWARE-CNCW32.Sality.AM variant outbound connectionoffoffoff
119855MALWARE-CNCW32.Sality.AM variant outbound connectionoffoffoff
119856MALWARE-CNCPacked.Win32.Krap.i variant outbound connectionoffoffoff
119857MALWARE-CNCWin.Trojan.Hupigon.hhbd variant outbound connection - Windowsoffoffoff
119858MALWARE-CNCWin.Trojan.Hupigon.hhbd variant outbound connection - non-Windowsoffoffoff
119864MALWARE-CNCWin.Trojan.Nvbpass.A variant outbound connectionoffoffdrop
119865MALWARE-CNCWin.Trojan.Arhost.D variant outbound connectionoffoffoff
119895MALWARE-CNCWin.Trojan.Delf.jwh variant outbound connectionoffoffoff
119898MALWARE-CNCCinmus Variant variant outbound connectionoffoffoff
119905MALWARE-CNCWin.Trojan.Small.jog variant outbound connectionoffoffoff
119912MALWARE-CNCTrojan.DelfInject.gen!X variant outbound connectionoffdropdrop
119914MALWARE-CNCWin.Trojan.Quivoe.A variant outbound connectionoffoffoff
119915MALWARE-CNCWin.Trojan.Gnutler.apd variant outbound connectionoffoffoff
119916MALWARE-CNCWin.Trojan.Bancos.ACB variant outbound connectionoffoffoff
119917MALWARE-CNCWin.Trojan.Sogu.A variant outbound connectionoffoffoff
119918MALWARE-CNCWorm Win.Trojan.Ganelp.B variant outbound connectionoffoffoff
119919MALWARE-CNCWin.Trojan.Murcy.A variant outbound connectionoffoffoff
119921MALWARE-CNCWin.Trojan.Puprlehzae.A variant outbound connectionoffoffoff
119922MALWARE-CNCWin.Trojan.Shiz.ivr variant outbound connectionoffoffoff
119923MALWARE-CNCWin.Trojan.Venik.B variant outbound connectionoffoffoff
119924MALWARE-CNCWin.Trojan.Spidern.A variant outbound connectionoffoffoff
119931MALWARE-CNCTrojan.Lineage.Gen.Pac.3 variant outbound connectionoffoffoff
119935MALWARE-CNCWin.Trojan.Dropper Win.Trojan.Delf.aba variant outbound connectionoffoffoff
119936MALWARE-CNCWin.Trojan.Dropper Win.Trojan.Delf.aba variant outbound connectionoffoffoff
119940MALWARE-CNCTrojan-Dropper.IRC.TKB variant outbound connection - dir4youoffoffoff
119941MALWARE-CNCTrojanSpy Win.Trojan.Zbot.Gen variant outbound connectionoffoffoff
119942MALWARE-CNCTrojanSpy Win.Trojan.Zbot.Gen variant outbound connectionoffoffoff
119944MALWARE-CNCWin.Trojan.Downloader.Win32.Banload.ykl variant outbound connectionoffoffoff
119945MALWARE-CNCWin.Trojan.Downloader.Win32.Agent.amwd variant outbound connectionoffoffoff
119946MALWARE-CNCWin.Trojan.Downloader.Win32.Agent.amwd variant outbound connectionoffoffoff
119947MALWARE-CNCWin.Trojan.Agent.amwd variant outbound connectionoffoffoff
119948MALWARE-CNCWin.Trojan.Agent.asjk variant outbound connectionoffoffoff
119949MALWARE-CNCWin.Trojan.Agent.asjk variant outbound connectionoffoffoff
119951MALWARE-CNCDarkstRat 2008 variant outbound connectionoffoffoff
119953MALWARE-CNCBiodox variant outbound connectionoffoffoff
119954MALWARE-CNCHack Style RAT variant outbound connectionoffoffoff
119955MALWARE-CNCPaiN RAT 0.1 variant outbound connectionoffoffoff
119957MALWARE-CNCArabian-Attacker 1.1.0 variant outbound connectionoffoffdrop
119958MALWARE-CNCWin.Trojan.Agent.aulk variant outbound connectionoffoffoff
119959MALWARE-CNCWin.Trojan.Agent.aulk variant outbound connectionoffoffoff
119960MALWARE-CNCWin.Trojan.Agent.aulk variant outbound connectionoffoffoff
119961MALWARE-CNCFouad 1.0 variant outbound connectionoffoffoff
119962MALWARE-CNCEmail-Worm.CryptBox-A variant outbound connectionoffoffoff
119963MALWARE-CNCWin.Trojan.Downloader.Win32.Banload.aajs variant outbound connectionoffoffoff
119964MALWARE-CNCVirus Win.Trojan.Sality.aa variant outbound connectionoffoffoff
119965MALWARE-CNCWin.Trojan.Downloader.Win32.Agent.avzz variant outbound connectionoffoffoff
119967MALWARE-CNCTrojan-PSW.Win32.Papras.dm variant outbound connectionoffoffoff
119968MALWARE-CNCTrojan.PSW.Win32.QQPass.amx variant outbound connectionoffoffoff
119969MALWARE-CNCTrojan.Crypt.CY variant outbound connectionoffoffoff
119970MALWARE-CNCW32.Smalltroj.MHYR variant outbound connectionoffoffoff
119973MALWARE-CNCWorm.Win.Trojan.Nebuler.D variant outbound connectionoffoffoff
119974MALWARE-CNCWin.Trojan.Small.bwj variant outbound connectionoffoffoff
119975MALWARE-CNCWin.Trojan.Crypt.vb variant outbound connectionoffoffoff
119976MALWARE-CNCWorm.Win32.Koobface.hy variant outbound connectionoffoffoff
119977MALWARE-CNCTrojan.LooksLike.Zaplot variant outbound connectionoffoffoff
119982MALWARE-CNCWin.Trojan.Agent.wwe variant outbound connectionoffoffoff
119983MALWARE-CNCWin.Trojan.Kolabc.fic variant outbound connectionoffoffoff
119988MALWARE-CNCAsprox variant outbound connectionoffoffoff
119995MALWARE-CNCWaledac variant outbound connectionoffdropdrop
119996MALWARE-CNCWorm Brontok.C variant outbound connectionoffoffoff
119997MALWARE-CNCWin.Trojan.PSW.Win32.QQPass.gam variant outbound connectionoffoffoff
120001MALWARE-CNCAllaple.e variant outbound connectionoffoffoff
120002MALWARE-CNCAllaple.e variant outbound connectionoffoffoff
120014MALWARE-CNCKaju variant outbound connection - confirmationoffoffoff
120015MALWARE-CNCWin.Trojan.Zeus variant outbound connectionoffoffoff
120016MALWARE-CNCWin.Trojan.Zeus variant outbound connectionoffoffoff
120017MALWARE-CNCWorm Win.Trojan.Koobface.dq variant outbound connectionoffoffoff
120018MALWARE-CNCW32.Autorun.worm.dq variant outbound connectionoffoffoff
120020MALWARE-CNCMalware Doctor variant outbound connectionoffoffoff
120022MALWARE-CNCWorm Win.Trojan.Padobot.z variant outbound connectionoffoffoff
120023MALWARE-CNCAdvanced Virus Remover variant outbound connectionoffoffoff
120024MALWARE-CNCWin.Trojan.Dreamy.bc variant outbound connectionoffoffoff
120026MALWARE-CNCWin.Trojan.Downloader.Win32.Banker.abg.b variant outbound connectionoffoffoff
120028MALWARE-CNCWindows Antivirus Pro variant outbound connectionoffoffoff
120040MALWARE-CNCWin.Trojan.KSpyPro.A variant outbound connectionoffoffoff
120043MALWARE-CNCAdware Kraddare.AZ variant outbound connectionoffoffoff
120074MALWARE-CNCWin.Trojan.IRCBot.iseee variant outbound connectionoffoffoff
120075MALWARE-CNCWin.Trojan.Ruskill.abl variant outbound connectionoffoffoff
120076MALWARE-CNCWin.Trojan.Agobot.ast variant outbound connectionoffoffoff
120077MALWARE-CNCWin.Trojan.Agobot.ast variant outbound connectionoffoffoff
120078MALWARE-CNCWin.Trojan.Russkill.C variant outbound connectionoffoffoff
120079MALWARE-CNCWin.Trojan.Russkill.C variant outbound connectionoffoffoff
120080MALWARE-CNCWin.Trojan.Derusbi.A variant outbound connectionoffoffoff
120081MALWARE-CNCWin.Trojan.Downloader.Win32.Yakes.cbi variant outbound connectionoffdropdrop
120082MALWARE-CNCWin.Trojan.Inject.raw variant outbound connectionoffoffoff
120083MALWARE-CNCWin.Trojan.Fucobha.A variant outbound connectionoffoffoff
120085MALWARE-CNCWin.Trojan.Veebuu.BX variant outbound connectionoffoffoff
120086MALWARE-CNCWin.Trojan.Banload.ABY variant outbound connectionoffoffoff
120087MALWARE-CNCWin.Trojan.Banker.FGU variant outbound connectionoffoffoff
120088MALWARE-CNCWin.Trojan.Emudbot.A variant outbound connectionoffoffoff
120096MALWARE-CNCWin.Trojan.Agent.dcir variant outbound connectionoffoffoff
120098MALWARE-CNCWin.Trojan.KeyLogger.wav variant outbound connectionoffoffoff
120099MALWARE-CNCWin.Trojan.Xtrat.A variant outbound connectionoffoffoff
120107MALWARE-CNCWin.Trojan.Downloader.Win32.Small.Cns variant outbound connectionoffoffoff
120108MALWARE-CNCWin.Trojan.Banker.Pher variant outbound connectionoffoffoff
120109MALWARE-CNCWin.Trojan.Zombie.sm variant outbound connectionoffoffoff
120202MALWARE-CNCApple OSX.Revir-1 variant outbound connectionoffdropdrop
120204MALWARE-CNCWin.Trojan.Taidoor variant outbound connectionoffdropdrop
120217MALWARE-CNCWin.Trojan.Ramagedos.A variant outbound connectionoffoffoff
120218MALWARE-CNCWin.Trojan.Ramagedos.A variant outbound connectionoffoffoff
120219MALWARE-CNCWin.Trojan.ToriaSpy.A variant outbound connectionoffoffoff
120221MALWARE-CNCTrojan.Injector variant outbound connectionoffdropdrop
120222MALWARE-CNCWin.Trojan.Payazol.B variant outbound connectionoffoffoff
120232MALWARE-CNCWin.Trojan.Cycbot variant outbound connectionoffdropdrop
120233MALWARE-CNCWin.Trojan.Virut variant outbound connectionoffoffdrop
120289MALWARE-CNCWin.Trojan.Doschald.A variant outbound connectionoffoffoff
120291MALWARE-CNCWin.Trojan.Mybios.A variant outbound connectionoffoffoff
120292MALWARE-CNCWin.Trojan.FresctSpy.A variant outbound connectionoffoffoff
120428MALWARE-CNCWin.Trojan.Zewit.A variant outbound connectionoffoffoff
120432MALWARE-CNCWin.Trojan.Hiloti variant outbound connectionoffoffoff
120447MALWARE-CNCWin.Trojan.Agent.JAAK variant outbound connectionoffoffdrop
120448MALWARE-CNCWin.Trojan.Meciv.A variant outbound connectionoffoffoff
120449MALWARE-CNCWorm Win.Trojan.Busifom.A variant outbound connectionoffoffoff
120527MALWARE-CNCSirefef initial C&C connection variant outbound connectionoffdropdrop
120569MALWARE-CNCWin.Trojan.Small.kb variant outbound connectionoffoffoff
120570MALWARE-CNCWin.Trojan.Small.kb variant outbound connectionoffoffoff
120571MALWARE-CNCWin.Trojan.Small.kb variant outbound connectionoffoffoff
120639MALWARE-CNCMalware Win.Trojan.Higest.N variant outbound connectionoffoffoff
120754MALWARE-CNCWin.Trojan.Virut-3 variant outbound connectionoffdropdrop
120755MALWARE-CNCWin.Trojan.Krap variant outbound connectionoffdropdrop
120759MALWARE-CNCWin.Trojan.Gbot.oce variant outbound connectionoffdropdrop
120762MALWARE-CNCMacOS.Flashback.A variant outbound connectionoffdropdrop
120763MALWARE-CNCWin.Trojan.Spyeye-206 variant outbound connectionoffdropdrop
120830MALWARE-CNCWin.Trojan.Banbra.amdu variant outbound connectionoffoffoff
120877MALWARE-CNCRunTime Worm.Win32.Warezov.gs variant outbound connectionoffoffdrop
120927MALWARE-CNCTrojan.Spyeye-207 variant outbound connectionoffdropdrop
121055MALWARE-CNCWin.Trojan.Utka.A variant outbound connectionoffoffoff
121178MALWARE-CNCWin.Trojan.Downloader Win.Trojan.Chekafe.A variant outbound connectionoffoffoff
121179MALWARE-CNCWin.Trojan.Coofus.RFM variant outbound connectionoffoffoff
121180MALWARE-CNCWorm.Win32.Magania.clfv variant outbound connectionoffoffoff
121181MALWARE-CNCWin.Trojan.Agent.czgu variant outbound connectionoffoffoff
121182MALWARE-CNCWin.Trojan.MeSub.ac variant outbound connectionoffoffoff
121183MALWARE-CNCWin.Trojan.Agent.alfu variant outbound connectionoffoffoff
121187MALWARE-CNCWin.Trojan.Xlahlah.A variant outbound connectionoffoffoff
121192MALWARE-CNCWin.Trojan.Syswrt.dvd variant outbound connectionoffoffoff
121193MALWARE-CNCWin.Trojan.Dalbot.A variant outbound connectionoffoffoff
121194MALWARE-CNCWin.Trojan.Wealwedst.A variant outbound connectionoffoffoff
121195MALWARE-CNCWin.Trojan.Protux.B variant outbound connectionoffoffoff
121196MALWARE-CNCWin.Trojan.Caphaw.A variant outbound connectionoffoffoff
121197MALWARE-CNCWin.Trojan.Caphaw.A variant outbound connectionoffoffoff
121198MALWARE-CNCWin.Trojan.Qinubot.A variant outbound connectionoffoffoff
121199MALWARE-CNCWin.Trojan.Qinubot.A variant outbound connectionoffoffoff
121200MALWARE-CNCWin.Trojan.Yakes.cmu variant outbound connectionoffoffoff
121201MALWARE-CNCWin.Trojan.Yakes.cmu variant outbound connectionoffoffoff
121202MALWARE-CNCWin.Trojan.Scapzilla.A variant outbound connectionoffoffoff
121203MALWARE-CNCVirus Win.Trojan.Induc.B variant outbound connectionoffoffoff
121204MALWARE-CNCVirus Win.Trojan.Induc.B variant outbound connectionoffoffoff
121205MALWARE-CNCVirus Win.Trojan.Induc.B variant outbound connectionoffoffoff
121207MALWARE-CNCWin.Trojan.Dekara.A variant outbound connectionoffoffoff
121208MALWARE-CNCWin.Trojan.RShot.brw variant outbound connectionoffdropdrop
121209MALWARE-CNCWin.Trojan.Enviserv.A variant outbound connectionoffoffoff
121210MALWARE-CNCWin.Trojan.Rallovs.A variant outbound connectionoffoffoff
121211MALWARE-CNCWin.Trojan.Banker.slrj variant outbound connectionoffoffoff
121212MALWARE-CNCWin.Trojan.Hupigon.nkor variant outbound connectionoffoffoff
121213MALWARE-CNCWorm.Win32.Cridex.B variant outbound connectionoffoffoff
121215MALWARE-CNCWin.Trojan.Banker.Am variant outbound connectionoffoffoff
121216MALWARE-CNCWin.Trojan.Banker.Am variant outbound connectionoffoffoff
121217MALWARE-CNCWin.Trojan.Banker.Am variant outbound connectionoffoffoff
121218MALWARE-CNCWin.Trojan.Sodager.C variant outbound connectionoffoffdrop
121219MALWARE-CNCWin.Trojan.Sysckbc variant outbound connectionoffoffoff
121221MALWARE-CNCWin.Trojan.Susnatache.A variant outbound connectionoffoffoff
121222MALWARE-CNCWin.Trojan.Kcahneila.A variant outbound connectionoffoffoff
121223MALWARE-CNCWin.Trojan.Gyplit.A variant outbound connectionoffoffoff
121224MALWARE-CNCTrojan.MacOS.DevilRobber.A variant outbound connectionoffoffoff
121226MALWARE-CNCWin.Trojan.Louisdreyfu.A variant outbound connectionoffoffoff
121227MALWARE-CNCTrojan-Downloader.Win32.Bulknet.A variant outbound connectionoffoffoff
121228MALWARE-CNCWin.Trojan.Cerberat.A variant outbound connectionoffoffoff
121229MALWARE-CNCWin.Trojan.Synljdos.A variant outbound connectionoffoffoff
121230MALWARE-CNCWin.Trojan.Betad.A variant outbound connectionoffoffoff
121231MALWARE-CNCWin.Trojan.Bedobot.B variant outbound connectionoffoffoff
121240MALWARE-CNCWin.Trojan.MsUpdater variant outbound connectionoffdropdrop
121241MALWARE-CNCWin.Trojan.MsUpdater initial variant outbound connectionoffdropdrop
121242MALWARE-CNCWin.Trojan.MsUpdater variant outbound connectionoffdropdrop
121251MALWARE-CNCWin.Trojan.Payazol.B variant outbound connectionoffoffoff
121252MALWARE-CNCWin.Trojan.Sirefef.P variant outbound connectionoffoffoff
121318MALWARE-CNCWin.Trojan.FakeAV TDSS/PurpleHaze variant outbound connection - base64 encodedoffdropdrop
121400MALWARE-CNCWin.Trojan.Kenzor.B variant outbound connectionoffoffoff
121401MALWARE-CNCWin.Trojan.Kenzor.B variant outbound connectionoffoffoff
121402MALWARE-CNCWin.Trojan.Ponfoy.A variant outbound connectionoffoffoff
121403MALWARE-CNCWorm.Win32.Vobfus.DL variant outbound connectionoffoffoff
121404MALWARE-CNCWorm.Win32.Vobfus.DL variant outbound connection contoffoffoff
121416MALWARE-CNCWin.Trojan.Bankpatch authentication string detectedoffoffdrop
121418MALWARE-CNCTrojan.FareIt variant outbound connectionoffdropdrop
121428MALWARE-CNCW32.Trojan.Generic-24 variant outbound connectionoffdropdrop
121434MALWARE-CNCWin.Trojan.Mentor variant outbound connectionoffoffoff
121444MALWARE-CNCWin.Trojan.Webmoner.zu connect to serveroffoffdrop
121454MALWARE-CNCWin.Trojan.Banbra.vec variant outbound connectionoffoffoff
121461MALWARE-CNCWin.Trojan.DarkComet variant outbound connection - post infectionoffoffoff
121474MALWARE-CNCWin.Trojan.Lancafdo.A variant outbound connectionoffoffoff
121477MALWARE-CNCTrojan.Noobot variant outbound connectionoffoffdrop
121495MALWARE-CNCTrojan.Vilsel variant outbound connectionoffoffoff
121497MALWARE-CNCTrojan.Saeeka variant outbound connectionoffoffdrop
121511MALWARE-CNCTrojan.Vaxpy variant outbound connectionoffoffdrop
121551MALWARE-CNCTrojan.Kahn variant outbound connectionoffdropdrop
121610MALWARE-CNCWin.Trojan.Refroso.azyg variant outbound connectionoffoffoff
121635MALWARE-CNCWin.Trojan.Phdet.gen.A variant outbound connectionoffoffoff
121769MALWARE-CNCWin.Trojan.LogonInvader.a variant outbound connectionoffoffdrop
121848MALWARE-OTHERTDS Sutra - page redirecting to a SutraTDSoffoffdrop
121877MALWARE-CNCApple OSX.Sabpub variant outbound connectionoffdropdrop
121947MALWARE-CNCWin.Trojan.VicSpy.A variant outbound connectionoffoffoff
121968MALWARE-BACKDOORWin.Backdoor.Rebhip.A variant outbound connection type Aoffoffdrop
121969MALWARE-BACKDOORWin.Backdoor.Rebhip.A variant outbound connection type Boffoffdrop
121971MALWARE-BACKDOORWin.Backdoor.Zlob.P variant inbound connectionoffoffoff
121972MALWARE-BACKDOORWin.Backdoor.ZZSlash variant outbound connectionoffoffoff
121976MALWARE-CNCTrojan-Downloader.Win32.Lapurd.D variant outbound connectionoffoffoff
121977MALWARE-BACKDOORWin.Backdoor.Pinit variant outbound connectionoffoffoff
121979MALWARE-BACKDOORWin.Backdoor.Nervos variant inbound connectionoffoffdrop
121980MALWARE-CNCTrojan.Winac variant outbound connectionoffoffoff
121981MALWARE-CNCTrojan-Downloader.Win32.Selvice.vq variant outbound connectionoffoffoff
121982MALWARE-CNCWin.Trojan.Insain.mh variant outbound connectionoffoffoff
122000MALWARE-CNCWorm.VB.amna variant outbound connection Aoffoffdrop
122001MALWARE-CNCApple OSX Flashback malware variant outbound connectionoffoffdrop
122033MALWARE-CNCApple OSX Flashback malware variant outbound connectionoffdropdrop
122034MALWARE-CNCApple OSX Flashback malware variant outbound connectionoffdropdrop
122060MALWARE-CNCTrojan.Fepgul variant outbound connectionoffdropdrop
122095MALWARE-BACKDOORWin.Backdoor.Agent variant outbound connectionoffdropdrop
122103MALWARE-CNCWin.Trojan.Coswid.klk variant outbound connectionoffdropdrop
122937MALWARE-CNCTrojan.Proxyier variant outbound connectionoffoffoff
123214MALWARE-CNCWin.Trojan.Waprox.A variant outbound connectionoffoffoff
123215MALWARE-CNCWin.Trojan.Waprox.A variant outbound connectionoffoffoff
123255MALWARE-CNCTrojan.Duojeen variant outbound connectionoffoffdrop
123262MALWARE-CNCTrojan.Banker variant outbound connectionoffdropdrop
123308MALWARE-CNCTrojan.Downloader.Bucriv variant outbound connectionoffoffdrop
123317MALWARE-CNCTrojan.Dropper initial variant outbound connectionoffoffdrop
123331MALWARE-CNCTrojan.Mybot variant outbound connectionoffoffoff
123332MALWARE-CNCWin.Trojan.Dishigy variant outbound connectionoffdropdrop
123335MALWARE-CNCTrojan.Swisyn variant outbound connectionoffdropdrop
123340MALWARE-CNCWin.Trojan.Nitol.B variant outbound connectionoffoffdrop
123344MALWARE-CNCWin.Trojan.Harvso.A variant outbound connectionoffoffdrop
123345MALWARE-CNCRunTime Win.Trojan.tchfro.A variant outbound connectionoffoffoff
123377MALWARE-CNCTrojan.Sasfis variant outbound connectionoffoffdrop
123378MALWARE-CNCTrojan.Sasfis variant outbound connectionoffoffdrop
123380MALWARE-CNCTrojan.Ventana initial variant outbound connectionoffoffdrop
123382MALWARE-CNCTrojan.SpyEye variant outbound connectionoffdropdrop
123387MALWARE-CNCWin.Trojan.Banker variant outbound connectionoffoffdrop
123388MALWARE-CNCWin.Trojan.FakeMSN.I variant outbound connectionoffoffoff
123391MALWARE-CNCWin.Trojan.Hioles.C variant outbound connectionoffdropdrop
123446MALWARE-CNCTrojan.Sojax.A variant outbound connectionoffoffdrop
123447MALWARE-CNCTrojan.Sojax.A variant outbound connectionoffoffdrop
123451MALWARE-CNCWin.Trojan.RedSip.A variant outbound connectionoffoffoff
123460MALWARE-CNCTrojan.Belesak.A variant outbound connectionoffoffoff
123468MALWARE-CNCTrojan.Dropper variant outbound connectionoffoffdrop
123469MALWARE-CNCTrojan.Dropper variant outbound connectionoffoffdrop
123494MALWARE-CNCWin.Trojan.Onitab.A variant outbound connectionoffoffdrop
123495MALWARE-CNCTrojan.Kugdifod.A variant outbound connectionoffoffdrop
123600MALWARE-CNCWin.Trojan.Gamarue outbound conntectionoffdropdrop
123610MALWARE-CNCWorm.Crass.A variant outbound connectionoffoffoff
123615MALWARE-CNCACAD.Medre.A variant outbound connectionoffdropdrop
123825MALWARE-CNCFinFisher initial variant outbound connectionoffoffoff
123826MALWARE-CNCFinFisher variant outbound connectionoffoffoff
123938MALWARE-CNCWin.Trojan.Ibabyfa.dldr variant outbound connectionoffdropdrop
123945MALWARE-CNCTrojan.Backdoor variant outbound connectionoffdropdrop
123968MALWARE-CNCWin.Trojan.Crisis variant outbound connectionoffdropdrop
123987MALWARE-CNCTrojan.Kryptik.Kazy variant outbound connectionoffdropdrop
124010MALWARE-CNCruntime Trojan.Radil variant outbound connectionoffoffoff
124077MALWARE-CNCWin.Trojan.Upof variant outbound connectionoffoffoff
124082MALWARE-CNCWin.Trojan.Banbra variant outbound connectionoffoffdrop
124092MALWARE-CNCWin.Trojan.Clisbot variant outbound connectionoffoffdrop
124182MALWARE-CNCWin.Worm.Helompy variant outbound connectionoffoffoff
124184MALWARE-CNCWin.Worm.Rokiwobi variant outbound connectionoffoffoff
124235MALWARE-CNCWin.Trojan.Wuwo initial infection variant outbound connectionoffdropdrop
124236MALWARE-CNCWin.Trojan.Wuwo post infection variant outbound connectionoffdropdrop
124288MALWARE-CNCWin.Trojan.Flexty variant outbound connectionoffoffdrop
124416MALWARE-CNCWin.Trojan.Agent variant outbound connectionoffoffdrop
124417MALWARE-CNCWin.Trojan.Agent variant outbound connectionoffoffdrop
124440MALWARE-CNCWin.Trojan.Chiviper variant outbound connectionoffdropdrop
124531MALWARE-CNCWin.Trojan.Scondatie.A variant outbound connectionoffdropdrop
124540MALWARE-BACKDOORWin.Trojan.Spy.Heur variant outbound connection attemptoffoffdrop
124541MALWARE-CNCWin.Trojan.Unebot variant outbound connectionoffoffdrop
124586MALWARE-CNCWin.Trojan.Barkiofork variant outbound connectionoffoffdrop
124858MALWARE-CNCWin.Trojan.Quarian variant outbound connection - proxy connectionoffdropdrop
124886MALWARE-CNCWin.Trojan.Dorkbot variant outbound connectionoffdropdrop
124976MALWARE-CNCWin.Trojan.Agent variant outbound connectionoffoffdrop
125049MALWARE-CNCWin.Trojan.Jorik.Kolilks variant outbound connectionoffdropdrop
125067MALWARE-CNCWin.Trojan.Riler variant outbound connectionoffoffdrop
125256MALWARE-CNCWin.Worm.Gamarue variant outbound connectionoffdropdrop
125257MALWARE-CNCWin.Trojan.Skintrim variant outbound connectionoffdropdrop
125258MALWARE-CNCWin.Trojan.Rombrast variant outbound connectionoffdropdrop
125259MALWARE-CNCWin.Trojan.BancosBanload variant outbound connectionoffdropdrop
125269MALWARE-CNCWin.Trojan.Buterat variant outbound connectionoffdropdrop
125271MALWARE-CNCWin.Trojan.Buzus variant outbound connectionoffdropdrop
125570MALWARE-CNCWin.Trojan.Medialabs variant outbound connectionoffdropdrop
125571MALWARE-CNCWin.Trojan.Medialabs variant outbound connectionoffdropdrop
125765MALWARE-CNCTrojan Agent YEH variant outbound connectionoffdropdrop
125830FILE-JAVAOracle Java malicious class download attemptdropdropdrop
126010MALWARE-CNCCNC Dirtjumper variant outbound connectionoffdropdrop
126011MALWARE-CNCCNC Dirtjumper variant outbound connectionoffdropdrop
126178MALWARE-CNCWin.Trojan.Hiloti variant outbound connectionoffoffoff
126264MALWARE-CNCDapato banking Trojan variant outbound connectionoffdropdrop
126288MALWARE-CNCBrontok Worm variant outbound connectionoffdropdrop
126343EXPLOIT-KITNuclear exploit kit landing pageoffdropdrop
126463MALWARE-CNCWin.Trojan.Linog.A variant outbound connectionoffoffdrop
126464MALWARE-CNCWin.Trojan.Linog.A variant outbound connectionoffoffdrop
126613MALWARE-CNCMedfos Trojan variant outbound connectionoffdropdrop
126657MALWARE-CNCWin.Trojan.Shiz variant outbound connectionoffdropdrop
126696MALWARE-CNCCbeplay Ransomware variant outbound connection - Abnormal HTTP Headersoffalertdrop
126697MALWARE-CNCCbeplay Ransomware variant outbound connection - POST Bodyoffdropdrop
126774MALWARE-CNCWin.Worm.Luder variant outbound connectionoffdropdrop
126775MALWARE-CNCWin.Trojan.Blocker variant outbound connection HTTP Header Structureoffdropdrop
126776MALWARE-CNCWin.Trojan.Blocker variant outbound connection POSToffdropdrop
126815MALWARE-CNCOSX.Trojan.KitM variant outbound connection user-agentoffdropdrop
126816MALWARE-CNCOSX.Trojan.KitM variant outbound connectionoffdropdrop
126835MALWARE-CNCRDN Banker POST variant outbound connectionoffoffdrop
126923MALWARE-CNCWin.Trojan.Zeus variant outbound connectionoffdropdrop
126930MALWARE-CNCWin.Trojan.Zeroaccess variant outbound connectiondropdropdrop
126931MALWARE-CNCWin.Trojan.Zeroaccess variant outbound connectiondropdropdrop
126932MALWARE-CNCWin.Trojan.Zeroaccess variant outbound connectionoffoffdrop
126984MALWARE-CNCWin.Trojan.Injector Info Stealer Trojan variant outbound connectionoffdropdrop
126997MALWARE-CNCWin.Downloader.Agent variant outbound connectionoffalertdrop
127007MALWARE-CNCWin.Trojan.Zbot variant outbound connectionoffdropdrop
127008MALWARE-CNCWin.Trojan.Zbot variant outbound connectionoffdropdrop
127033MALWARE-CNCWin.Backdoor.Transhell variant outbound connection user-agentoffoffdrop
127049MALWARE-CNCWin.Trojan.Dokstormac variant outbound connectionoffdropdrop
127054MALWARE-CNCWin.Trojan.Yakes variant outbound connectionoffdropdrop
127057MALWARE-CNCWin.Trojan.Dalbot variant outbound connectionoffdropdrop
127058MALWARE-CNCOSX.Trojan.HackBack variant outbound connectionoffdropdrop
127252MALWARE-CNCWin.Trojan.ZeroAccess 111-byte URL variant outbound connectionoffoffdrop
127596MALWARE-CNCWin.Redyms variant outbound connectionoffdropdrop
127599MALWARE-CNCWin.Redyms variant outbound connectionoffdropdrop
127629MALWARE-CNCWin.Backdoor.Aumlib variant outbound connectionoffdropdrop
127630MALWARE-CNCWin.Backdoor.Aumlib variant outbound connectionoffdropdrop
127631MALWARE-CNCWin.Backdoor.Aumlib variant outbound connectionoffdropdrop
127633MALWARE-CNCWorm.Silly variant outbound connectionoffdropdrop
127654MALWARE-CNCWin.Backdoor.Agent variant outbound connectionoffoffoff
127708MALWARE-CNCWin.Ransomware.Urausy outbound conntectionoffoffoff
127711MALWARE-CNCWin.Trojan.FakeAV variant outbound connectionoffdropdrop
127746MALWARE-CNCUnix.Trojan.Hanthie variant outbound connectionoffdropdrop
127802MALWARE-CNCWin.Trojan.PRISM variant outbound connectionoffdropdrop
127803MALWARE-CNCWin.Trojan.PRISM variant outbound connectionoffdropdrop
127804MALWARE-CNCWin.Trojan.PRISM variant outbound connectionoffdropdrop
127964MALWARE-CNCGh0st RAT variant outbound connectionoffdropdrop
128042MALWARE-CNCWin.Trojan.Caphaw variant outbound connectionoffdropdrop
128079MALWARE-CNCWin.Trojan.Napolar variant outbound connectionoffdropdrop
128105MALWARE-CNCWin.Trojan.Banload variant outbound connectionoffdropdrop
128111EXPLOIT-KITNuclear/Magnitude exploit kit post Java compromise download attemptoffdropdrop
128242MALWARE-CNCWin.Trojan.Tuxido outbound commincation attemptoffdropdrop
128244MALWARE-CNCWin.Trojan.Phrovon outbound conntectionoffdropdrop
128247MALWARE-CNCWin.Trojan.Dropper variant outbound connectionoffdropdrop
128254MALWARE-CNCTrojan.Perl.Shellbot variant outbound connectionoffdropdrop
128300MALWARE-CNCWin.Trojan.Agent variant conntectionoffdropdrop
128305MALWARE-CNCWin.Trojan.Mecifg variant outbound connectionoffdropdrop
128323MALWARE-CNCWin.Backdoor.Chopper web shell conntectionoffdropdrop
128325MALWARE-CNCWin.Backdoor.Zuza variant outbound connectionoffdropdrop
128326MALWARE-CNCWin.Backdoor.Zuza variant outbound connectionoffdropdrop
128328MALWARE-CNCWin.Backdoor.Hupigon variant outbound connectionoffdropdrop
128366MALWARE-CNCWin.Backdoor.Venik variant outbound connectionoffdropdrop
128373MALWARE-CNCWin.Trojan.Mutopy variant outbound connectionoffdropdrop
128399MALWARE-CNCLinux.Backdoor.Tsunami outbound conntectionoffdropdrop
128416MALWARE-CNCWin.Trojan.CryptoLocker outbound conntectionoffdropdrop
128417MALWARE-CNCWin.Trojan.Molgomsg variant outbound connectionoffdropdrop
128418MALWARE-CNCWin.Downloader.Dtcontx outbound conntectionoffdropdrop
128419MALWARE-CNCWin.Trojan.Tesch variant outbound connectionoffdropdrop
128439MALWARE-CNCWin.Trojan.Bspire variant conntectionoffdropdrop
128444MALWARE-CNCWin.Backdoor.CBgate variant outbound connectionoffdropdrop
128482MALWARE-CNCWin.Trojan.Terminator RAT variant outbound connectiondropdropdrop
128484MALWARE-CNCWin.Trojan.Delpbank variant outbound connectionoffdropdrop
128485MALWARE-CNCWin.Trojan.Khalog variant outbound connectionoffdropdrop
128486MALWARE-CNCWin.Trojan.Codiltak variant outbound connectionoffdropdrop
128493MALWARE-CNCDeputyDog diskless method variant outbound connectionoffdropdrop
128538MALWARE-CNCWin.Trojan.Qadars variant outbound connectionoffoffdrop
128547MALWARE-CNCWin.Trojan.Banker variant outbound conntectionoffdropdrop
128548MALWARE-CNCWin.Trojan.chfx variant outbound connectionoffdropdrop
128551MALWARE-CNCWin.Trojan.NXI ftp username connectionoffdropdrop
128559MALWARE-CNCWin.Trojan.Castov variant conntectionoffdropdrop
128560MALWARE-CNCWin.Trojan.Plugx FTP keepalive outbound conntectiondropdropdrop
128561MALWARE-CNCWin.Trojan.Plugx outbound conntectiondropdropdrop
128562MALWARE-CNCWin.Trojan.Sidopa variant outbound connectionoffdropdrop
128563MALWARE-CNCWin.Trojan.Pkdesco variant outbound connectionoffdropdrop
128564MALWARE-CNCWin.Trojan.Pkdesco variant outbound connectionoffdropdrop
128565MALWARE-CNCWin.Trojan.Pkdesco variant outbound connectionoffdropdrop
128599MALWARE-CNCWin.Backdoor.Lesirt variant outbound connectionoffdropdrop
128604MALWARE-CNCWin.Trojan.Kasnam variant conntectionoffdropdrop
128605MALWARE-CNCWin.Trojan.Kasnam variant conntectionoffdropdrop
128606MALWARE-CNCWin.Trojan.Surtr variant conntectionoffdropdrop
128607MALWARE-CNCWin.Trojan.Fareit variant outbound conntectionoffdropdrop
128724MALWARE-CNCWin.Trojan.Agent outbound conntectionoffdropdrop
128799MALWARE-CNCWin.Trojan.Mxtcycle variant outbound connectionoffdropdrop
128800MALWARE-CNCWin.Trojan.Zeus outbound connectionoffdropdrop
128802MALWARE-CNCWin.Trojan.Zeus outbound connectionoffdropdrop
128803MALWARE-CNCWin.Trojan.Injector outbound conntectionoffdropdrop
128804MALWARE-CNCWin.Trojan.Injector outbound conntectionoffdropdrop
128805MALWARE-CNCWin.Trojan.Palevo outbound conntectionoffdropdrop
128808MALWARE-CNCWin.Backdoor.Ptiger variant outbound connectionoffdropdrop
128809MALWARE-CNCWin.Trojan.Dofoil outbound conntectionoffdropdrop
128813MALWARE-CNCWin.Trojan.Ufraie variant outbound connectionoffdropdrop
128816MALWARE-CNCWin.Trojan.Siluhdur variant outbound connectionoffdropdrop
128817MALWARE-CNCWin.Backdoor.Iniduoh variant outbound connectionoffdropdrop
128820MALWARE-CNCWin.Backdoor.Iniduoh variant outbound connectionoffdropdrop
128853MALWARE-CNCWin.Trojan.Dipverdle variant outbound conntectiondropdropdrop
128856MALWARE-CNCWin.Trojan.Yowdab variant conntectionoffdropdrop
128861MALWARE-CNCWin.Trojan.Roxfora variant outbound conntectionoffdropdrop
128864MALWARE-CNCWin.Trojan.Tofsee variant outbound conntectionoffdropdrop
128879MALWARE-CNCWin.Backdoor.Tavdig variant outbound conntectionoffdropdrop
128886MALWARE-CNCWin.Trojan.Scar variant outbound conntectionoffdropdrop
128913MALWARE-BACKDOORZollard variant outbound connection attemptoffoffoff
128914MALWARE-CNCWin.Trojan.Anony variant conntectionoffdropdrop
128947MALWARE-CNCWin.Trojan.Tapaoux variant conntectionoffdropdrop
128948MALWARE-CNCWin.Trojan.Kishlog variant outbound conntectionoffdropdrop
128949MALWARE-CNCWin.Trojan.Kishlog variant outbound conntectionoffdropdrop
128986MALWARE-CNCWin.Worm.Neeris IRCbot variant outbound connectionoffdropdrop
128987MALWARE-CNCWin.Worm.Steckt IRCbot variant outbound connectionoffdropdrop
128988MALWARE-CNCWin.Worm.Steckt IRCbot variant outbound connectionoffdropdrop
128989MALWARE-CNCWin.Trojan.Egobot variant outbound conntectionoffdropdrop
128996MALWARE-CNCWin.Trojan.Bunitu variant outbound connectionoffdropdrop
129011MALWARE-CNCWin.Trojan.Dotconta variant outbound conntectionoffdropdrop
129012MALWARE-OTHERPossible Win.Trojan.Zbot variant outbound connectionoffdropdrop
129013MALWARE-OTHERPossible Win.Trojan.Zbot variant outbound connectionoffdropdrop
129026MALWARE-CNCWin.Trojan.Limlspy variant outbound conntectionoffdropdrop
129038MALWARE-CNCWin.Trojan.Banload variant outbound communicationoffdropdrop
129044MALWARE-CNCWin.Trojan.Lorask variant outbound connectionoffdropdrop
129045MALWARE-CNCWin.Trojan.Lorask variant outbound connectionoffdropdrop
129057MALWARE-CNCWin.Trojan.Descrantol variant outbound connectionoffdropdrop
129058MALWARE-CNCWin.Trojan.Umberial variant outbound connectionoffdropdrop
129076MALWARE-CNCWin.Trojan.Epixed variant outbound connectionoffdropdrop
129077MALWARE-CNCWin.Trojan.Platidium variant outbound connectionoffdropdrop
129081MALWARE-CNCWin.Trojan.Budir initial variant outbound connectionoffdropdrop
129082MALWARE-CNCWin.Trojan.Ldmon variant outbound connectionoffdropdrop
129087MALWARE-CNCWin.Trojan.Kboy variant outbound connectionoffdropdrop
129095MALWARE-CNCWin.Trojan.Fotip FTP file upload variant outbound connectionoffdropdrop
129104MALWARE-CNCWin.Trojan.Iniptad variant outbound connectionoffdropdrop
129109MALWARE-CNCWin.Trojan.Drafukey variant outbound conntectionoffdropdrop
129114MALWARE-CNCWin.Trojan.Sotark variant outbound connectionoffdropdrop
129115MALWARE-CNCWin.Trojan.Alset variant outbound connectionoffdropdrop
129123DELETEDMALWARE-OTHER Win.Trojan.InstallMonster variant outbound connection
129124MALWARE-OTHERWin.Trojan.InstallMonster variant outbound connectionoffoffoff
129125MALWARE-CNCWin.Trojan.Valden variant outbound connectionoffdropdrop
129136MALWARE-CNCWin.Trojan.Neos variant outbound connectionoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
17183MALWARE-CNCSnoopware barok variant outbound connectionoffoffdrop
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
12420FILE-IDENTIFYRealNetworks Realplayer .rmp playlist file download requestoffoffoff
116124MALWARE-CNCTrojan.nsis.agent.s variant outbound connectionoffoffoff
117230FILE-IDENTIFYTiff big endian file magic detectedoffoffoff
117732FILE-IDENTIFYTIFF file download requestoffoffoff
119596MALWARE-CNCPoison Ivy variant outbound connectionoffoffoff
119597MALWARE-CNCWin.Trojan.Agent.cws variant outbound connectionoffoffoff
119744MALWARE-CNCWorm.Win32.Deecee.a variant outbound connectionoffoffoff
119971MALWARE-CNCWin.Trojan.Mudrop.lj variant outbound connectionoffoffoff
121593MALWARE-CNCWin.Trojan.Dropper variant outbound connectionoffdropdrop
123710FILE-IDENTIFYTiff big endian file magic detectedoffoffoff
124463FILE-IDENTIFYTIFF file attachment detectedoffoffoff
124464FILE-IDENTIFYTIFF file attachment detectedoffoffoff
128528MALWARE-CNCWin.Trojan.Qadars variant outbound connectionoffdropdrop
128529MALWARE-CNCWin.Trojan.Qadars variant outbound connectionoffdropdrop