ET-3400
📛 Threat Title
Ruleset Update Summary - 2026/07/27 - v11242
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- Ruleset Update Summary - 2026/07/27 - v11242 Emerging Threats Community
Remediations (10)
-
web:community.emergingthreats.net
Summary : 8 new OPEN, 9 new PRO (8 + 1) Added rules: Open: 2071124 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (azevedo .lol) (exploit_kit.rules) 2071125 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (fra…
-
web:community.emergingthreats.net
Summary : 13 new OPEN, 23 new PRO (13 + 10) Added rules: Open: 2071132 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (carreiro .lol) (exploit_kit.rules) 2071133 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (henreques .lol) (exploit_kit.rules) 2071134 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (carreiro .lol) (exploit_kit.rules) 2071135 - ET EXPLOIT_KIT LandUpdate808 Domain in ...
-
web:community.emergingthreats.net
Summary : 14 new OPEN, 16 new PRO (14 + 2) Added rules: Open: 2071214 - ET WEB_SPECIFIC_APPS Sonicwall SMA1000 AMC Authenticated Path Traversal (CVE-2026-15410) (web_specific_apps.rules) 2071215 - ET WEB_SPECIFIC_APPS Splunk Cloud & Enterprise edit_user Capability Privilege Escalation (CVE-2023-32707) (web_specific_apps.rules) 2071216 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup ...
-
web:community.emergingthreats.net
Summary : 7 new OPEN, 7 new PRO (7 + 0) Added rules: Open: 2071228 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (meltedpleasandtws .shop) (malware.rules) 2071229 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (meltedpleasandtws .shop) in TLS SNI (malware.rules) 2071230 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (deckerh .cyou) (malware.rules ...
-
web:community.emergingthreats.net
Summary : 9 new OPEN, 12 new PRO (9 + 3) Added rules: Open: 2071235 - ET WEB_SPECIFIC_APPS SonicWall SMA Websocket Tunnel Bypass (CVE-2026-15409) (web_specific_apps.rules) 2071236 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (meduurst .space) (exploit_kit.rules) 2071237 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (meduurst .space) (exploit_kit.rules) 2071238 - ET MALWARE TA569 ...
-
web:community.emergingthreats.net
Summary : 9 new OPEN, 37 new PRO (9 + 28) Added rules: Open: 2071268 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (appallf .pics) (malware.rules) 2071269 - ET MALWARE Observed Win32/Lumma Stealer R…
-
web:community.emergingthreats.net
Summary : 36 new OPEN, 46 new PRO (36 + 10) Added rules: Open: 2071293 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (abangan .cyou) (malware.rules) 2071294 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (abangan .cyou) in TLS SNI (malware.rules) 2071295 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (boothroundupdow .fun) (malware.rules) 2071296 ...
-
web:community.emergingthreats.net
Summary : 9 new OPEN, 19 new PRO (9 + 10) Added rules: Open: 2071329 - ET WEB_SPECIFIC_APPS Veracore timeoutWarning PmSess1 Parameter SQL Injection Attempt (CVE-2025-25181) (web_specific_apps.rules) 2071336 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (phiplips .click) (exploit_kit.rules) 2071337 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (phiplips .click) (exploit_kit.rules ...
-
web:www.fedramp.gov
This section contains the entire Consolidated Rules for 2026 as a standalone reference for each ruleset .
-
web:www.regulations.gov
Regulations.gov is the federal government's platform for public access to and participation in regulatory processes.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.