New Filters: 44528: TLS: Cobalt Strike Team Server (Cat Leak Self-signed SSL/TLS Certificate) - IPS Version: 3.9.5 and after. - TPS Version: 5.2.2 and after. - vTPS Version: 5.2.2 and after. - Category: Virus - Severity: High - Description: This filter is deployed in the Malware Filter Package. - Deployments: - Deployment: Default (Block / Notify) - Deployment: Performance-Optimized (Disabled) - Release Date: July 30, 2024 44559: HTTP: Backdoor.PHP.FoxAnonAuto.A Runtime Detection (Response) - IPS Version: 3.9.5 and after. - TPS Version: 5.2.2 and after. - vTPS Version: 5.2.2 and after. - Category: Virus - Severity: High - Description: This filter is deployed in the Malware Filter Package. - Deployments: - Deployment: Default (Block / Notify) - Deployment: Performance-Optimized (Disabled) - Release Date: July 30, 2024 44561: TCP: Malicious Certificate File Content - (PEM-Encoded) - IPS Version: 3.9.5 and after. - TPS Version: 5.2.2 and after. - vTPS Version: 5.2.2 and after. - Category: Virus - Severity: High - Description: This filter attempts to detect a suspicious PEM-encoded certificate file with non-conforming content. - Deployments: - Deployment: Default (Block / Notify) - Deployment: Performance-Optimized (Disabled) - Release Date: July 30, 2024 44564: HTTP: Trojan.MSIL.GenesisStealer.A Runtime Detection (Notify C2) - IPS Version: 3.9.5 and after. - TPS Version: 5.2.2 and after. - vTPS Version: 5.2.2 and after. - Category: Virus - Severity: High - Description: This filter is deployed in the Malware Filter Package. - Deployments: - Deployment: Default (Block / Notify) - Deployment: Performance-Optimized (Disabled) - Release Date: July 30, 2024 44565: HTTP: Trojan.MSIL.GenesisStealer.A Runtime Detection (Data Exfiltration) - IPS Version: 3.9.5 and after. - TPS Version: 5.2.2 and after. - vTPS Version: 5.2.2 and after. - Category: Virus - Severity: High - Description: This filter is deployed in the Malware Filter Package. - Deployments: - Deployment: Default (Block / Notify) - Deployment: Performance-Optimized (Disabled) - Release Date: July 30, 2024 44566: HTTP: Trojan-Downloader.MSIL.JellyfishLoader.A Runtime Detection - IPS Version: 3.9.5 and after. - TPS Version: 5.2.2 and after. - vTPS Version: 5.2.2 and after. - Category: Virus - Severity: High - Description: This filter is deployed in the Malware Filter Package. - Deployments: - Deployment: Default (Block / Notify) - Deployment: Performance-Optimized (Disabled) - Release Date: July 30, 2024 44571: FTP: Trojan.Python.XenotixLogger.A Runtime Detection - IPS Version: 3.9.5 and after. - TPS Version: 5.2.2 and after. - vTPS Version: 5.2.2 and after. - Category: Virus - Severity: High - Description: This filter is deployed in the Malware Filter Package. - Deployment: Not enabled by default in any deployment. - Release Date: July 30, 2024 44572: HTTP: Trojan.Win64.ICEDID.YXEC2Z Runtime Detection - IPS Version: 3.9.5 and after. - TPS Version: 5.2.2 and after. - vTPS Version: 5.2.2 and after. - Category: Virus - Severity: High - Description: This filter is deployed in the Malware Filter Package. - Deployments: - Deployment: Default (Block / Notify) - Deployment: Performance-Optimized (Disabled) - Release Date: July 30, 2024 Modified Filters (logic changes): * = Enabled in Default deployments * 33996: HTTP: Trojan.Win32.Nixrukoz.A Runtime Detection - IPS Version: 3.7.0 and after. - TPS Version: 4.0.0 and after. - vTPS Version: 4.0.1 and after. - Detection logic updated. - Release Date: January 15, 2019 - Last Modified Date: July 30, 2024 44557: HTTP: Backdoor.PHP.FoxAnonAuto.A Runtime Detection - IPS Version: 3.9.5 and after. - TPS Version: 5.2.2 and after. - vTPS Version: 5.2.2 and after. - Detection logic updated. - Vulnerability references updated. - Release Date: July 23, 2024 - Last Modified Date: July 30, 2024 Modified Filters (metadata changes only): None Removed Filters: None |