Risk | Vulnerability/Situation | References | Related Fingerprint | Situation Type | Change Description |
High |
Pony-Downloader-C2-Traffic |
No CVE/CAN |
HTTP_CS-Pony-Downloader-C2-Traffic |
Suspected Botnet |
Category tag situation Suspected Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
TinyNuke-Malware-C2-Traffic |
No CVE/CAN |
HTTP_CS-TinyNuke-Malware-C2-Traffic |
Potential Botnet |
Category tag situation Potential Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
AZORult-Stealer-C2-Traffic |
No CVE/CAN |
HTTP_CS-AZORult-Stealer-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
Loki-Bot-C2-Traffic |
No CVE/CAN |
HTTP_CS-Loki-Bot-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
Risk | Vulnerability/Situation | References | Related Fingerprint | Situation Type | Change Description |
High |
LuminosityLink-RAT-C2-Traffic |
No CVE/CAN |
Generic_TCP-LuminosityLink-RAT-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
Generic_CS-FlawedAmmyy-RAT-C2-Traffic |
No CVE/CAN |
Generic_CS-FlawedAmmyy-RAT-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
DanaBot-C2-Traffic |
No CVE/CAN |
Generic_CS-DanaBot-C2-Traffic |
Suspected Botnet |
Category tag situation Suspected Botnet added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
DarkVNC-C2-Traffic |
No CVE/CAN |
Generic_TCP-DarkVNC-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
RevengeRAT-Malware-C2-Traffic |
No CVE/CAN |
Generic_CS-RevengeRAT-Malware-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
AveMaria-Stealer-C2-Traffic |
No CVE/CAN |
Generic_CS-AveMaria-Stealer-C2-Traffic |
Suspected Botnet |
Category tag situation Suspected Botnet added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
Remcos-RAT-C2-Traffic |
No CVE/CAN |
Generic_CS-Remcos-RAT-C2-Traffic |
Suspected Botnet |
Category tag situation Suspected Botnet added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
NanoCore-RAT-C2-Traffic |
No CVE/CAN |
Generic_CS_NanoCore-RAT-C2-Traffic |
Suspected Botnet |
Category tag situation Suspected Botnet added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
Risk | Vulnerability/Situation | References | Related Fingerprint | Situation Type | Change Description |
High |
LogPOS-Malware |
No CVE/CAN |
HTTP_CSU-LogPOS-Malware-Traffic-Detected |
Botnet |
Category tag situation Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
SideWinder-APT-C2-Traffic |
No CVE/CAN |
HTTP_CSU-SideWinder-APT-C2-Traffic |
Suspected Botnet |
Category tag situation Suspected Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
KeyBase-Keylogger-C2-Traffic |
No CVE/CAN |
HTTP_CSU-KeyBase-Keylogger-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
Saefko-RAT-C2-Traffic |
No CVE/CAN |
HTTP_CSU-Saefko-RAT-C2-Traffic |
Suspected Botnet |
Category tag situation Suspected Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
Predator-The-Thief-C2-Traffic |
No CVE/CAN |
HTTP_CSU-Predator-The-Thief-C2-Traffic |
Suspected Botnet |
Category tag situation Suspected Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
ARS-VBS-Loader-C2-Traffic |
No CVE/CAN |
HTTP_CSU-ARS-VBS-Loader-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group TCP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
Risk | Vulnerability/Situation | References | Related Fingerprint | Situation Type | Change Description |
High |
Pulse-Secure-Diag.cgi-Command-Injection |
CVE-2019-11539 |
HTTP_CRL-Pulse-Secure-Diag.cgi-Command-Injection |
Suspected Compromise |
Fingerprint regexp changed |
|
High |
Linux-Backdoor-C2-Traffic |
No CVE/CAN |
HTTP_CRL-Linux-Backdoor-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
RevCode-RAT-C2-Traffic |
No CVE/CAN |
HTTP_CRL-RevCode-RAT-C2-Traffic |
Suspected Botnet |
Category tag situation Suspected Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
Agent-Tesla-C2-Traffic |
No CVE/CAN |
HTTP_CRL-Agent-Tesla-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
OpenSSH-Backdoor-C2-Traffic |
No CVE/CAN |
HTTP_CRL-OpenSSH-Backdoor-C2-Traffic |
Potential Botnet |
Category tag situation Potential Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
Hancitor-C2-Traffic |
No CVE/CAN |
HTTP_CRL-Hancitor-C2-Traffic |
Botnet |
Category tag situation Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
High |
Ekeoil-Malware-C2-Traffic |
No CVE/CAN |
HTTP_CRL-Ekeoil-Malware-C2-Traffic |
Suspected Botnet |
Category tag situation Suspected Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
Type | Name | Changes |
Category | Botnet |
|
Network Element | TOR exit nodes |
|
Protocol Agent | DNS |
|
Service | DNS (UDP with SafeSearch) |
|
Situation | HTTP_CRL-Banker-Trojan-Keylogger |
Category tag situation Botnet added |
Category tag group HTTP Correlation Dependency Group added |
Category tag group Severity over 4 Correlation Dependency Group added |
Category tag situation Spyware, Malware and Adware removed |
|
IPList | Åland |
|
IPList | Bulgaria |
|
IPList | Mauritius |
|
IPList | Iceland |
|
IPList | India |
|
IPList | Burkina Faso |
|
IPList | Guinea-Bissau |
|
IPList | Cyprus |
|
IPList | Palau |
|
IPList | France |
|
IPList | Sint Maarten |
|
IPList | Gabon |
|
IPList | South Korea |
|
IPList | Costa Rica |
|
IPList | Belgium |
|
IPList | Niue |
|
IPList | Tanzania |
|
IPList | Lebanon |
|
IPList | Botswana |
|
IPList | Turkey |
|
IPList | Heard Island and McDonald Islands |
|
IPList | Liberia |
|
IPList | Mongolia |
|
IPList | Réunion |
|
IPList | Slovakia |
|
IPList | Ukraine |
|
IPList | Kenya |
|
IPList | Ethiopia |
|
IPList | Morocco |
|
IPList | Guernsey |
|
IPList | United States |
|
IPList | Republic of Lithuania |
|
IPList | Belize |
|
IPList | Germany |
|
IPList | Gambia |
|
IPList | Estonia |
|
IPList | Marshall Islands |
|
IPList | Cameroon |
|
IPList | Bouvet Island |
|
IPList | Grenada |
|
IPList | Canada |
|
IPList | St Kitts and Nevis |
|
IPList | Rwanda |
|
IPList | Eritrea |
|
IPList | Equatorial Guinea |
|
IPList | Nicaragua |
|
IPList | Barbados |
|
IPList | Madagascar |
|
IPList | Bolivia |
|
IPList | TOR relay nodes IP Address List |
|
IPList | South Africa |
|
IPList | U.S. Virgin Islands |
|
IPList | Democratic Republic of Timor-Leste |
|
IPList | Saint Martin |
|
IPList | Sri Lanka |
|
IPList | Cambodia |
|
IPList | Saint Helena |
|
IPList | Cayman Islands |
|
IPList | Argentina |
|
IPList | Poland |
|
IPList | Papua New Guinea |
|
IPList | Japan |
|
IPList | Mexico |
|
IPList | Bermuda |
|
IPList | Portugal |
|
IPList | Sierra Leone |
|
IPList | Uganda |
|
IPList | Paraguay |
|
IPList | Western Sahara |
|
IPList | Fiji |
|
IPList | Mayotte |
|
IPList | Peru |
|
IPList | North Korea |
|
IPList | Tunisia |
|
IPList | Latvia |
|
IPList | Nauru |
|
IPList | Luxembourg |
|
IPList | Venezuela |
|
IPList | Greenland |
|
IPList | U.S. Minor Outlying Islands |
|
IPList | Honduras |
|
IPList | Svalbard and Jan Mayen |
|
IPList | Tokelau |
|
IPList | Bhutan |
|
IPList | Indonesia |
|
IPList | United Arab Emirates |
|
IPList | Cuba |
|
IPList | Spain |
|
IPList | Puerto Rico |
|
IPList | Montserrat |
|
IPList | Guadeloupe |
|
IPList | South Sudan |
|
IPList | British Indian Ocean Territory |
|
IPList | Nigeria |
|
IPList | Thailand |
|
IPList | Lesotho |
|
IPList | Curaçao |
|
IPList | Italy |
|
IPList | North Macedonia |
|
IPList | Ecuador |
|
IPList | Libya |
|
IPList | Guatemala |
|
IPList | Maldives |
|
IPList | Sudan |
|
IPList | South Georgia and the South Sandwich Islands |
|
IPList | Brazil |
|
IPList | Dominica |
|
IPList | Albania |
|
IPList | Trinidad and Tobago |
|
IPList | Egypt |
|
IPList | Panama |
|
IPList | Israel |
|
IPList | Somalia |
|
IPList | Russia |
|
IPList | Chile |
|
IPList | Austria |
|
IPList | Myanmar |
|
IPList | Antarctica |
|
IPList | Anguilla |
|
IPList | Hungary |
|
IPList | Greece |
|
IPList | Yemen |
|
IPList | Haiti |
|
IPList | Serbia |
|
IPList | Turkmenistan |
|
IPList | Georgia |
|
IPList | New Caledonia |
|
IPList | Algeria |
|
IPList | Pakistan |
|
IPList | Vatican City |
|
IPList | Suriname |
|
IPList | Angola |
|
IPList | Kyrgyzstan |
|
IPList | Finland |
|
IPList | Dominican Republic |
|
IPList | Republic of the Congo |
|
IPList | Guyana |
|
IPList | Saint Lucia |
|
IPList | Iran |
|
IPList | Niger |
|
IPList | Cocos [Keeling] Islands |
|
IPList | Bahamas |
|
IPList | Bonaire, Sint Eustatius, and Saba |
|
IPList | Azerbaijan |
|
IPList | Switzerland |
|
IPList | Bangladesh |
|
IPList | Norfolk Island |
|
IPList | Cabo Verde |
|
IPList | Belarus |
|
IPList | Oman |
|
IPList | Ivory Coast |
|
IPList | Kuwait |
|
IPList | Vanuatu |
|
IPList | Slovenia |
|
IPList | El Salvador |
|
IPList | Christmas Island |
|
IPList | French Southern Territories |
|
IPList | Kazakhstan |
|
IPList | Martinique |
|
IPList | Solomon Islands |
|
IPList | Romania |
|
IPList | Syria |
|
IPList | Jamaica |
|
IPList | Federated States of Micronesia |
|
IPList | TOR exit nodes IP Address List |
|
IPList | Falkland Islands |
|
IPList | Uzbekistan |
|
IPList | Hong Kong |
|
IPList | Croatia |
|
IPList | Kosovo |
|
IPList | Congo |
|
IPList | Saint Vincent and the Grenadines |
|
IPList | São Tomé and Príncipe |
|
IPList | Iraq |
|
IPList | Sweden |
|
IPList | French Guiana |
|
IPList | United Kingdom |
|
IPList | Malta |
|
IPList | Singapore |
|
IPList | Burundi |
|
IPList | Ghana |
|
IPList | Malawi |
|
IPList | Hashemite Kingdom of Jordan |
|
IPList | Ireland |
|
IPList | Nepal |
|
IPList | Andorra |
|
IPList | Macao |
|
IPList | Vietnam |
|
IPList | Jersey |
|
IPList | China |
|
IPList | Togo |
|
IPList | Zimbabwe |
|
IPList | Gibraltar |
|
IPList | Netherlands |
|
IPList | Benin |
|
IPList | Bosnia and Herzegovina |
|
IPList | Taiwan |
|
IPList | Mozambique |
|
IPList | Namibia |
|
IPList | Australia |
|
IPList | Zambia |
|
IPList | Mauritania |
|
IPList | Monaco |
|
IPList | Comoros |
|
IPList | British Virgin Islands |
|
IPList | Saint Barthélemy |
|
IPList | Armenia |
|
IPList | Saint Pierre and Miquelon |
|
IPList | Central African Republic |
|
IPList | Isle of Man |
|
IPList | Mali |
|
IPList | Faroe Islands |
|
IPList | Montenegro |
|
IPList | Qatar |
|
IPList | Chad |
|
IPList | Denmark |
|
IPList | Guinea |
|
IPList | Colombia |
|
IPList | Wallis and Futuna |
|
IPList | Antigua and Barbuda |
|
IPList | Norway |
|
IPList | French Polynesia |
|
IPList | Uruguay |
|
IPList | Kiribati |
|
IPList | Guam |
|
IPList | Tuvalu |
|
IPList | New Zealand |
|
IPList | Eswatini |
|
IPList | Malaysia |
|
IPList | Republic of Moldova |
|
IPList | Cook Islands |
|
IPList | Pitcairn Islands |
|
IPList | Czechia |
|
IPList | Samoa |
|
IPList | Turks and Caicos Islands |
|
IPList | Brunei |
|
IPList | Djibouti |
|
IPList | Bahrain |
|
IPList | Afghanistan |
|
IPList | Tajikistan |
|
IPList | Palestine |
|
IPList | Philippines |
|
IPList | Aruba |
|
IPList | San Marino |
|
IPList | Laos |
|
IPList | Senegal |
|
IPList | Tonga |
|
IPList | Seychelles |
|
IPList | American Samoa |
|
IPList | Saudi Arabia |
|
IPList | Northern Mariana Islands |
|
IPList | Liechtenstein |
|