Search
Keyword: Possible_OLGM-23
NOTES: Attack Phase: Point of Entry or Lateral Movement Protocol: SMB2 Risk Type: OTHERS (Note: OTHERS can be network connections related to hacking attempts, exploits, connections done by grayware, or suspicious traffic.) Threat Type: ...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Directory Server LDAP 1011531* - Microsoft Windows Active Directory Certificate Services Privilege Escalation Vulnerability (CVE-2022-34691) Web Ser...
* indicates a new version of an existing rule Deep Packet Inspection Rules: PaperCut 1011731* - PaperCut NG Authentication Bypass Vulnerability (CVE-2023-27350) 1011732 - PaperCut NG Authentication Bypass Vulnerability (CVE-20...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Web Server HTTPS 1011878 - Cacti SQL Injection Vulnerability (CVE-2023-39361) Web Server Miscellaneous 1011882 - Atlassian Confluence Data Center an...
NOTES: Attack Phase: Point of Entry or Lateral Movement Protocol: VNC Risk Type: OTHERS (Note: OTHERS can be network connections related to hacking attempts, exploits, connections done by grayware, or suspicious traffic.) Threat Type: S...
NOTES: Attack Phase: Data Exfiltration Protocol: DNS Risk Type: OTHERS (Note: OTHERS can be network connections related to hacking attempts, exploits, connections done by grayware, or suspicious traffic.) Threat Type: Suspicious Behavio...
NOTES: Attack Phase: Point of Entry or Lateral Movement Protocol: TELNET Risk Type: OTHERS (Note: OTHERS can be network connections related to hacking attempts, exploits, connections done by grayware, or suspicious traffic.) Threat Type...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Lansweeper 1011679 - Lansweeper Directory Traversal Vulnerability (CVE-2022-27498) NFS Server 1011492* - Microsoft Windows Network File System Remo...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Ivanti Avalanche Remote Control Server 1011719 - Ivanti Avalanche Authentication Bypass Vulnerability (CVE-2022-44574) PaperCut 1011731 - PaperCut NG ...
* indicates a new version of an existing rule Deep Packet Inspection Rules: NFS Server 1011740 - Microsoft Windows Network File System Remote Code Execution Vulnerability (CVE-2023-24941) Web Client Common 1011710* - Foxit PDF Re...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Ivanti Endpoint Manager 1012616 - Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability (CVE-2026-5786) JetBrains TeamCity 1012612 - JetBr...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Redis Server 1011555* - Redis Integer Overflow Vulnerability (CVE-2022-35951) Web Application PHP Based 1011689* - LibreNMS Cross-Site Scripting Vulne...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Splunk Enterprise 1011912 - Splunk Enterprise Privilege Escalation Vulnerability (CVE-2023-32707) Web Client Common 1011920 - Google Chrome Type Con...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Web Server HTTPS 1011893 - Microsoft Exchange Server-Side Request Forgery Vulnerability (ZDI-CAN-22090) 1011895 - Microsoft Exchange Server-Side Req...
* indicates a new version of an existing rule Deep Packet Inspection Rules: JetBrains TeamCity 1011815 - JetBrains TeamCity Cross-Site Scripting Vulnerability (CVE-2023-34220) PaperCut 1011855 - PaperCut NG Remote Code Exec...
This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
* indicates a new version of an existing rule Deep Packet Inspection Rules: Redis Server 1011681 - Redis Integer Overflow Vulnerability (CVE-2022-35977) Web Application Common 1010562* - Mantis Bug Tracker 'verify.php' Remo...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Advanced Message Queuing Protocol (AMQP) 1011703 - SolarWinds Network Performance Monitor Insecure Deserialization Vulnerability (CVE-2023-23836) DCER...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Web Server Common 1012589 - Control Web Panel Command Injection Vulnerability (CVE-2025-67888) 1012578 - Fuxa Path Traversal Vulnerability (CVE-2026-25...
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
