IPS Threat Content Update Release Notes 23.125.17

IPS Threat Content Update Release Notes 23.125.17

Refer to the following summary of signatures deployed on 27th June, 2023 with the IPS content release:

  • Signatures added: 12
  • Signatures modified: 14
  • Signatures removed: 5
Signatures Added
SIDDescriptionReference
150621MALWARE-CNC Sliver.C2.Session Start traffic detectedNo Reference
150624MALWARE-CNC Sliver.C2.File traffic detectedNo Reference
150626MALWARE-CNC Sliver.C2.Generic traffic detectedNo Reference
61904MALWARE-CNC Win.Trojan.Gozi malicious file downloadwww.virustotal.com/gui/file/d67275e2cd7f5764d1d7fe088fa1683bc9aa873447e82d02fc2c6da2e11f01bc
61902MALWARE-CNC Win.Trojan.Redline malicious file downloadwww.virustotal.com/gui/file/666e5755e21665e8fd2a26425563d05f1cbd0a5024ad763c71e6d62e68cac438
61948MALWARE-OTHER Win.Trojan.Barys file download attemptNo Reference
150622MALWARE-CNC Sliver.C2.Session Message traffic detectedNo Reference
150623MALWARE-CNC Sliver.C2.Poll traffic detectedNo Reference
61906FILE-OTHER Microsoft Visual Studio Python Interpreter Services remote code execution attemptCVE-2021-27068
61950MALWARE-OTHER Win.Trojan.Barys file download attemptNo Reference
61916OS-WINDOWS Microsoft Windows TPM device driver elevation of privilege attemptCVE-2023-29360
61914MALWARE-TOOLS Win.Proxy.frp download attemptgithub.com/fatedier/frp
Signatures Removed

Removed the following signatures due to False Positives (FP):

  • 41457
  • 18357
  • 39603
  • 39601
  • 61455
Share this Doc

IPS Threat Content Update Release Notes 23.125.17

Or copy link

In this topic ...