Palo Alto Networks (PAN-OS) Products November 2024 Security Update Advisory
Overview Palo Alto Networks(https://www.paloaltonetworks.com/) has released a security update that fixes vulnerabilities in products...
November 20, 2024
November 20, 2024 Hash 1eab86e99e51a5e312a2c0405a845882b 221ba02bc838bb2b83709cf62f7f12ac7 39390f99af9805fbd945ac043b35208ac URL 1https[:]//www[.]molekinha[.]com[.]br/jogos/sign/login[.]alibaba[.]com/newlogin/icbuLogin[.]htm/Login[.]php 2http[:]//196[.]189[.]198[.]173[:]49637/Mozi[.]m 3https[:]//deliv[.]cfd/63×9 IP 1114[.]35[.]82[.]225 2210[.]16[.]188[.]254 3185[.]164[.]72[.]200...
Weekly Detection Rule (YARA and Snort) Information – Week 3, November 2024
The following is the information on Yara and Snort rules (week 3, November 2024) collected and shared by the AhnLab TIP service. 1 YARA Rules Detection name Description Source MAL_ELF_Xlogin_Nov24_1 Detects xlogin backdoor samples https://github.com/Neo23x0/signature-base 4 Snort Rules Detection name Source ET WEB_SPECIFIC_APPS Symphony PHP Symfony Profiler Environment Manipulation (CVE-2024-50340)
Warning Against Malware in SVG Format Distributed via Phishing Emails
AhnLab SEcurity Intelligence Center (ASEC) has recently identified multiple instances of malware being distributed in Scalable Vector Graphics (SVG) format. An SVG file is an XML-based file format that represents scalable vector graphics. SVG files are primarily used for icons, charts, and graphs, and they support the use of CSS
Infected Systems Controlled Through Remote Administration Tools – Detected by EDR (2)
Remote administration tools, also known as RAT, are software that provide the ability to manage and control terminals at remote locations. Recently, there has been an increase in cases where remote administration tools are installed instead of backdoor malware during the initial access or lateral movement phases to control the

