Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

ThreatDV - Malware Filter Package #1549

    • Updated:
    • 4 Sep 2018
    • Product/Version:
    • TippingPoint ThreatDV
    • Platform:
Summary
ThreatDV - Malware Filter Package #1549      August 4, 2018
Details
Public
Thank you for subscribing to Threat Digital Vaccine updates brought to you by Trend Micro™ TippingPoint DVLabs.

New content is now available at the Threat Management Center (TMC): https://tmc.tippingpoint.com

To learn more about the capabilities of this filter set, please reference: TippingPoint Deployment Note: Threat Digital Vaccine (ThreatDV).

SMS customers can update the malware filter set through the SMS client. Go to Profiles > Auxiliary DVs > Download to detect and load the latest update.
 
System Requirements
The malware filter package requires TOS v3.7.0.4200, NGFW v1.1.1.4200, TPS v4.0.0.4300, vTPS v4.0.1.4300 and higher. This filter package is supported only on the N and NX Platform IPS, NGFW, TPS and vTPS systems licensed for the ThreatDV (formerly ReputationDV) service.
 
The Malware Filter Package can also be manually downloaded from the following URL:
https://tmc.tippingpoint.com/TMC/ViewPackage?parentFolderId=malware&contentId=Malware_3.7.0_1549.pkg

Update Details

Table of Contents

--------------------------
Filters
 New Filters
 Modified Filters (logic changes)
 Modified Filters (metadata changes only)
 Removed Filters

Filters
----------------
  New Filters:
    32910: HTTP: PyLocky Ransomware - Checkin Request
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Virus
      - Severity: Critical
      - Description: This filter is deployed in the Malware Filter Package.
      - Deployment: Not enabled by default in any deployment.

    32912: HTTP: Jeus Downloader Checkin Request (AppleJeus/Lazarus)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Virus
      - Severity: High
      - Description: This filter is deployed in the Malware Filter Package.
      - Deployments:
        - Deployment: Default (Block / Notify)
        - Deployment: Performance-Optimized (Disabled)

  Modified Filters (logic changes):
    * = Enabled in Default deployments

    18303: HTTP: RiskTool.AndroidOS.SMSreg.ja Checkin 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.

    21076: HTTP: Possible TDS Redirecting to EK Aug 19 2015
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    22057: HTTP: Win32/Banload.XA Conf Download
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    22413: HTTP: AutoClicker Test Page
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    23586: TCP: Win32/Skeeyah Checkin 3
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    24192: HTTP: CVE-2014-6332 Sep 01 2016 (HFS Actor) M1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    24293: HTTP: Android.Riskware.SmsPay.C Checkin 8
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27793: HTTP: Win32.Swizzor Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27794: HTTP: Document Macro Downloading Ursnif Jul 25
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27795: HTTP: Win32/Spy.Banker.BR Downloading Module
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27796: HTTP: Win32/Spy.Banker.BR Downloading Module 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27797: HTTP: R980 Ransomware Requesting Image 1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27799: TCP: Trojan-Banker.AndroidOS.Marcher.l SSL CnC Cert
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27800: HTTP: Win32/Unknown TViewer RAT Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    27801: HTTP: ARIK Keylogger Checkin 1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27802: HTTP: ARIK Keylogger Module Download
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27803: TLS: Evil Redirector to EK SSL Cert Aug 1 2016 T1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    27854: HTTP: Android/SLocker.AC Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27855: TCP: Android.Trojan.AndroRAT.P Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27856: HTTP: Ransomware Locky CnC Beacon Aug 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27858: TLS: Zeus Panda Banker Malicious SSL Certificate Detected
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27859: HTTP: Android.Trojan.Ztorg.AV Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27861: TCP: Orcus RAT SSL Certificate
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27864: TLS: Pony CnC Domain in SSL Client Hello SNI
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    27866: SMTP: iSpy Keylogger Reporting Infection via SMTP M2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27867: HTTP: Win32/Kryptik.FCPN Facebook Stealer Activity
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27869: HTTP: Trojan-Banker.AndroidOS.Gepew.a Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27870: HTTP: Win32.Spy/TVRat Checkin 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "27870: HTTP: Win32.Spy/TVRat/Shade Ransomware Checkin 2".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27871: TLS: Malicious SSL certificate detected (Malware C2)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27872: HTTP: Android.Trojan.FakeBank.BA APK Download
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27874: HTTP: ZeusPOS Payload M2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27877: TCP: PoisonIvy Keepalive to CnC (youtube.swf actor) 1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27878: TCP: PoisonIvy Keepalive to CnC (youtube.swf actor) 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27879: TCP: PoisonIvy Keepalive to CnC (youtube.swf actor) 4
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27880: TCP: PoisonIvy Keepalive to CnC (youtube.swf actor) 5
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27881: TCP: Trojan-Banker.AndroidOS.Marcher.l SSL CnC Cert 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27882: TCP: Trojan-Banker.AndroidOS.Marcher.l SSL CnC Cert 3
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27883: TLS: Evil Redirector to EK - Observed Malicious SSL Cert
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    27884: TCP: Cromwi CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27885: TCP: Cromwi CnC Beacon Response
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27886: HTTP: Trojan-Banker.AndroidOS.Hqwar.z Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27887: HTTP: Trojan-Banker.AndroidOS.Hqwar.z Checkin 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27889: HTTP: Win32.KeyLogger.dyiuae Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27891: HTTP: W32/Banload.XMY Variant Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27892: HTTP: W32/Joinme Stealer Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27893: HTTP: Alma Locker CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27894: TLS: Win32/Maptrepol.A SSL Certificate Detected
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27895: TCP: NanoCore RAT CnC 11
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27896: TCP: NanoCore RAT CnC 12
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27897: HTTP: Android Unknown Trojan Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27899: TLS: Malicious SSL certificate detected (Dreambot/Gozi CnC)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    27900: TLS: Terdot.A/Zloader Malicious SSL Cert Observed
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    27901: HTTP: Win32/Banload Variant Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27902: TCP: NanoCore RAT CnC 13
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27952: TCP: NanoCore RAT CnC 14
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27953: HTTP: W32/Banload.XMY Variant Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27954: HTTP: Ransomware.MarsJoke Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27955: HTTP: Ransomware Bart CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27956: HTTP: Ransomware Bart User-Agent
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27957: TCP: Orcus RAT Malicious SSL Certificate Detected
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27958: TCP: PoisonIvy Keepalive to CnC 484
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27959: HTTP: Android/SMForw.MV Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27960: TCP: Trojan.Win32.HTSS Bot USER Command
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27961: TLS: Trojan-Banker.AndroidOS.Marcher.l SSL CnC Cert 4
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27963: HTTP: Win32/Shade/Troldesh Ransomware External IP Check 3
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27964: HTTP: Win32/Fantom Ransomware Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27965: TCP: Win32.KillProc.eewdhh Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27966: SMTP: HawkEye Keylogger Reporting via SMTP
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27967: TCP: NanoCore RAT CnC 15
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27968: TCP: Win32/Remcos RAT Checkin 1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27969: HTTP: Trojan-Banker.AndroidOS.Marcher.o Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27970: HTTP: Trojan-Banker.AndroidOS.Marcher.o Checkin 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27971: TLS: Zeus Panda Banker Malicious SSL Certificate Detected
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27972: HTTP: MSIL/OmegaNET HTTP Bot CnC Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27973: TCP: NanoCore RAT CnC 16
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27976: HTTP: Trojan-Spy.AndroidOS.Agent.kz CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27977: HTTP: Trojan.AndroidOS.Fakeapp.t Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27979: TCP: MSIL/Crimson CnC Client Command (supdat)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27980: HTTP: Sbidith CnC Beacon 1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27981: HTTP: Sbidith CnC Beacon 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27982: HTTP: Sbidith CnC Beacon 3
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27983: HTTP: DetoxCrypto Ransomware CnC Activity
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27984: HTTP: MSIL/Unknown HTTP Bot Screenshot Upload
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    27985: HTTP: Android/JSmsHider.O Checkin 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27986: TCP: PoisonIvy Keepalive to CnC 510
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27987: HTTP: Win32/Wadereh Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27988: HTTP: Win32.Unknown Updateinfo Command
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27989: HTTP: Govdi/Goggles/Foxy Payload Request
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27990: TCP: Android/Spy.Agent.HG Checkin 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27991: HTTP: Win32/Banload.XOV CnC Activity
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27992: HTTP: Win32/Flyper Ransomware CnC Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27993: TLS: Shifu SSL Cert
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27994: TCP: NanoCore RAT CnC 17
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27995: HTTP: Etirehni/PYLOT CnC Beacon - Downloaded by Cmstar
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "27995: HTTP: Etirehni CnC Beacon - Downloaded by Cmstar".
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    27998: TCP: Trojan-Dropper.Win32.Injector.oocq / DualToy Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28052: HTTP: Win32/Unknown HTTP Bot CnC Checkin 1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28053: HTTP: Win32/Unknown HTTP Bot CnC Checkin 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28054: HTTP: Win32/Philadelphia Ransomware CnC Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28055: TCP: Loda Logger Screenshot Command from CnC
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28056: HTTP: Trojan-Spy.AndroidOS.Agent.kg Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28057: HTTP: Trojan-Ransom.AndroidOS.Svpeng.v Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28058: TLS: Malicious SSL certificate detected (Ursnif Injects)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    28059: TCP: Trojan-Spy.AndroidOS.Rax.a Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28060: HTTP: Android/Spy.Banker.GK File Download
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28063: HTTP: Trojan.AndroidOS.Agent.la Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28064: HTTP: Trojan.AndroidOS.Agent.la Checkin 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28065: HTTP: Trojan.AndroidOS.Agent.gz Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28066: TLS: Trojan-Banker.AndroidOS.Marcher.l SSL CnC Cert 5
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28067: HTTP: Trojan-Spy.AndroidOS.SmsThief.lt Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28069: HTTP: Caretni Bot CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28070: HTTP: Trojan.AndroidOS.Agent.ll CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28071: HTTP: Trojan.AndroidOS.Agent.ll CnC Beacon 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28072: TLS: Observed Malicious SSL Cert (Zeus Panda)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    28073: HTTP: Trojan.AndroidOS.Agent.lp Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28074: TCP: NanoCore RAT CnC 18
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28075: HTTP: Dreambot/Gozi DGA Seed Request
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    28076: HTTP: Trojan.AndroidOS.Casseb.a Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28077: HTTP: BKDR_ASPXSPY.A Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28078: HTTP: Win32/CONFUCIUS_B CnC Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28079: TCP: NanoCore RAT CnC 19
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28080: HTTP: Trojan.AndroidOS.Rootnik.bz Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28081: HTTP: Trojan.AndroidOS.Rootnik.bx Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28083: TLS: Malicious SSL certificate detected (Odinaff CnC)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28084: HTTP: 2016-0189 Exploit (Kniaz Variant)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    28086: TCP: PoisonIvy Keepalive to CnC 554
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28087: TLS: Ursnif VNC Module CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28088: TCP: NanoCore RAT CnC 20
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28131: HTTP: Trojan.AndroidOS.Triada.bw Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28132: HTTP: W32.Palibu Banker Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28133: HTTP: Ransomware Locky CnC Beacon Oct 3
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28135: HTTP: W32.Raum Update Config HTTP Request
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28136: HTTP: W32.Raum Update Config HTTP Request
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28137: HTTP: Evil Redirector Leading to EK Oct 09
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    28140: HTTP: Backdoor.Win32.Mocker Variant Checkin M2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28141: HTTP: Ursnif Variant CnC Beacon 6
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28142: TLS: Observed Malicious SSL Cert (Zeus Panda)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    28144: TLS: Win32/CONFUCIUS_B SSL Cert
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28148: HTTP: Unknown Backdoor Client Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28152: HTTP: TheTrick Banking Trojan Affiliate Download
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28153: TLS: Win32/Etumbot.G CnC SSL Certificate Detected
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28154: TLS: Observed Malicious SSL Cert (Zeus Panda)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28156: DNS: Trojan-Banker.AndroidOS.Marcher DNS Lookup
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28157: TLS: Trojan-Banker.AndroidOS.Marcher SSL CnC Cert
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28158: TLS: Trojan-Banker.AndroidOS.Marcher SSL CnC Cert
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28159: HTTP: PassCV Win32/TrojanDownloader.VB.NOY CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28160: UDP: PassCV Win32/DyCode.A CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28161: TCP: PassCV Win32/Kitkiot.B CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28162: HTTP: Known Malicious User-Agent (pb) Possible Win32.ProxyBack or Win32.Htbot.B
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28165: TCP: Win32/Spdevbot.A CnC SSL Certificate Detected
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28166: TLS: Observed PS Empire Downloader SSL Cert via MalDoc Oct 20
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    28167: HTTP: DiamondFox HTTP POST CnC Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28169: HTTP: DiamondFox HTTP POSTing JPEG
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28171: HTTP: W32.Plugx CnC HTTP Request
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28173: HTTP: Unknown ForceXYZ Downloader CnC Checkin 1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28174: HTTP: Unknown ForceXYZ Downloader CnC Checkin 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

    28175: HTTP: Unknown ForceXYZ Downloader Module Request
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28176: TLS: Zeus Panda Banker Malicious SSL Certificate Detected
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28177: TCP: Trojan-Banker.AndroidOS.Marcher SSL CnC Cert
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    28179: TCP: APT.Gabby/Rambo CnC Beacon Response
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    29689: TCP: PoisonIvy Keepalive to CnC (youtube.swf actor) 3
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    29789: TLS: Malicious SSL certificate detected (Odinaff CnC)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.
      - Vulnerability references updated.

    32400: HTTP: Win32/HydraCrypt CnC Beacon 3
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.
      - Vulnerability references updated.

  Modified Filters (metadata changes only):
    * = Enabled in Default deployments

    20972: HTTP: Fake AV Phone Scam Landing July 20 2015 M4
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Vulnerability references updated.

    21086: HTTP: Evil Redirector Leading to EK Aug 31 2015 T2 (BizCN)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Miscellaneous modification.

    22719: TLS: ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Bancos/DarkTequila CnC)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "22719: TLS: ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Bancos CnC)".
      - Description updated.

    22720: TLS: ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Bancos/DarkTequila CnC)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "22720: TLS: ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Bancos CnC)".
      - Description updated.

    27790: DNS: Sefnit .onion Proxy Domain
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Vulnerability references updated.

    27873: HTTP: ZeusPOS Payload M1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28068: HTTP: Astrum EK Plugin Detect Reporitng URI Struct
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Vulnerability references updated.

    28082: HTTP: MSIL/Eskimo.A Steam PWS CnC Activity
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28138: TCP: StrongPity SSL Cert 1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28145: HTTP: Win32/CONFUCIUS_B External IP Check to CnC
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28146: DNS: DNS Query to Cerber Domain (56185u . top)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28147: HTTP: AutoLOG v2 Keylogger Client Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28149: DNS: DNS Query to Cerber Domain (kb6051 . bid)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28150: DNS: DNS Query to Cerber Domain (hhc366 . bid)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28151: DNS: DNS Query to Cerber Domain (249isv . bid)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28155: DNS: DNS Query to Cerber Domain (065ism . bid)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28164: DNS: DNS Query to Cerber Domain (dsv023 . bid)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28178: TCP: APT.Gabby/Rambo CnC Beacon
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28232: HTTP: W32.Cerber Ransomware HTTP Pattern
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28865: HTTP: Possible MalDoc Payload Download Nov 11 2014
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "28865: HTTP: Possible Dridex Campaign Download Nov 11 2014".
      - Description updated.

    32103: TCP: Babylon RAT C2 Server Response
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Miscellaneous modification.

    32110: TCP: Android/Spy.Agent.HG Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "32110: TCP: Android/Trojan.Andup.A Checkin".

    32111: TCP: Observed Malicious SSL Cert (MalDoc DL)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Vulnerability references updated.

    32113: UDP: Shade/Troldesh Ransomware C2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Vulnerability references updated.

    32120: TLS: W32.Unknown CnC SSL Cert
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Vulnerability references updated.

    32176: HTTP: MSIL/ApolloHTTP Bot CnC Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Miscellaneous modification.

    32177: HTTP: MSIL/ApolloHTTP Bot CnC Keep-Alive
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Miscellaneous modification.

    32179: TCP: MSIL/Bladabindi/njRAT Variant CnC Checkin (boolLove)
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Miscellaneous modification.

  Removed Filters:

    14810: HTTP: Unknown Exploit Kit Payload Request
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    27789: HTTP: Trojan-Spy.AndroidOS.SmForw.iw SMS Exfil
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    27798: HTTP: R980 Ransomware Requesting Image 2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    27853: HTTP: Trojan-SMS.AndroidOS.Agent.ue SMS Exfil
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    27898: HTTP: Win32/AbStealer Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    27997: HTTP: MSIL/Oldbot HTTP Bot CnC Checkin M2
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    28139: HTTP: Backdoor.Win32.Mocker Variant Checkin M1
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    28143: HTTP: Win32/Philadelphia Ransomware Encryption Activity
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    28163: HTTP: MSIL/Exotic CnC Checkin
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    28168: HTTP: DiamondFox HTTP Requesting Module
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    28933: TCP: Win32/Remcos RAT Checkin 4
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.

    29788: HTTP: Lance Stealer Screenshot Exfil
      - IPS Version: 3.7.0 and after.
      - NGFW Version: 1.1.1 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
Top of the Page
Premium
Internal
Rating:
Category:
Configure; Troubleshoot; Deploy
Solution Id:
TP000119854
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.