IPS Threat Content Update Release Notes 24.102.13

IPS Threat Content Update Release Notes 24.102.13

Following is the summary of signatures deployed on January 16th, 2024 with the IPS content release:

  • Signatures Added: 36

  • Signatures Modified: 1

  • Signatures Removed: 2

Signatures Added

SIDDescriptionReference
150725MALWARE-CNC Cobalt Strike APT1.VT.Profile traffic detectedcobaltstrike.com
150726MALWARE-CNC Cobalt Strike msupdate.getonly traffic detectedcobaltstrike.com
150727MALWARE-CNC Cobalt Strike amazon.db.search traffic detectedcobaltstrike.com
150728MALWARE-CNC Cobalt Strike msnbc.video.get traffic detectedcobaltstrike.com
150729MALWARE-CNC Cobalt Strike ocsp.get traffic detectedcobaltstrike.com
150730MALWARE-CNC Cobalt Strike owa.calendar.get traffic detectedcobaltstrike.com
150731MALWARE-CNC Cobalt Strike onedrive.get traffic detectedcobaltstrike.com
150732MALWARE-CNC Cobalt Strike pandora.get traffic detectedcobaltstrike.com
150733MALWARE-CNC Cobalt Strike poseidon.get traffic detectedcobaltstrike.com
150734MALWARE-CNC Cobalt Strike powrunner.get traffic detectedcobaltstrike.com
150735MALWARE-CNC Cobalt Strike qakbot.get traffic detectedcobaltstrike.com
150736MALWARE-CNC Cobalt Strike ramnit.get traffic detectedcobaltstrike.com
150737MALWARE-CNC Cobalt Strike ratankba.get traffic detectedcobaltstrike.com
150738MALWARE-CNC Cobalt Strike salesforce.get traffic detectedcobaltstrike.com
150739MALWARE-CNC Cobalt Strike slack.get traffic detectedcobaltstrike.com
150740MALWARE-CNC Cobalt Strike sofacy.get traffic detectedcobaltstrike.com
150741MALWARE-CNC Cobalt Strike stackoverflow.get traffic detectedcobaltstrike.com
150742MALWARE-CNC Cobalt Strike so.paerls.get traffic detectedcobaltstrike.com
150743MALWARE-CNC Cobalt Strike template.profile.get traffic detectedcobaltstrike.com
150744MALWARE-CNC Cobalt Strike trevor.profile.get traffic detectedcobaltstrike.com
150745MALWARE-CNC Cobalt Strike trick-ryuk.profile.get traffic detectedcobaltstrike.com
150746MALWARE-CNC Cobalt Strike ursnif-icedid.profile.get traffic detectedcobaltstrike.com
150747MALWARE-CNC Cobalt Strike xbash.profile.get traffic detectedcobaltstrike.com
150748MALWARE-CNC Cobalt Strike zloader.profile.get traffic detectedcobaltstrike.com
150749MALWARE-CNC Cobalt Strike zillow.profile.get traffic detectedcobaltstrike.com
150750MALWARE-CNC Cobalt Strike zoom.profile.get traffic detectedcobaltstrike.com
62788MALWARE-CNC Win.Trojan.GravityRAT variant outbound connectionhttps://www.virustotal.com/gui/file/caf0a39318cfc1e65eae773a28de62ce08b7cf1b9d4264e843576165411e2a84
62816MALWARE-OTHER Win.Dropper.Generic variant binary download attemptNo Reference
62817MALWARE-CNC Win.Infostealer.Generic variant outbound connectionhttps://www.virustotal.com/gui/file/bc25f7836c273763827e1680856ec6d53bd73bbc4a03e9f743eddfc53cf68789
62818MALWARE-OTHER Win.Trojan.GravityRat variant malware download attempthttps://www.virustotal.com/gui/file/caf0a39318cfc1e65eae773a28de62ce08b7cf1b9d4264e843576165411e2a84
62848OS-WINDOWS Microsoft Windows Win32k elevation of privilege attemptCVE-2024-20683
62850OS-WINDOWS Microsoft Windows Kernel elevation of privilege attemptCVE-2024-20698
62855OS-WINDOWS Microsoft Windows Common Log File System escalation of privilege attemptCVE-2024-20653
62857OS-WINDOWS Microsoft Windows Common Log File System escalation of privilege attemptCVE-2024-20653
62859OS-WINDOWS Microsoft Windows Common Log File System escalation of privilege attemptCVE-2024-20653
62861OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attemptCVE-2024-21310

Signatures Removed

Removed the following signature due to False Positives (FP):

  • 50436

  • 62722

Share this Doc

IPS Threat Content Update Release Notes 24.102.13

Or copy link

In this topic ...