*********************** snort-2.9.0-enhanced open-nogpl *********************** [***] Results from Oinkmaster started Tue Nov 12 19:47:29 2019 [***] [+++] Added rules: [+++] 2009545 - ET USER_AGENTS User-Agent (_TEST_) (emerging-user_agents.rules) 2028963 - ET TROJAN DADJOKE/Rail Tycoon Initial Macro Execution (emerging-trojan.rules) 2028964 - ET TROJAN DADJOKE/Rail Tycoon Payload Extraction (emerging-trojan.rules) 2028965 - ET TROJAN DADJOKE/Rail Tycoon Payload Execution (emerging-trojan.rules) [///] Modified active rules: [///] 2027325 - ET TROJAN CobaltStrike SMB P2P Default Msagent Named Pipe Interaction (emerging-trojan.rules) [---] Removed rules: [---] 2009545 - ET MALWARE User-Agent (_TEST_) (emerging-malware.rules) [+++] Added non-rule lines: [+++] -> Added to sid-msg.map (4): 2009545 || ET USER_AGENTS User-Agent (_TEST_) || url,doc.emergingthreats.net/2009545 2028963 || ET TROJAN DADJOKE/Rail Tycoon Initial Macro Execution || md5,4c89d5d8016581060d9781433cfb0bb5 2028964 || ET TROJAN DADJOKE/Rail Tycoon Payload Extraction || md5,4c89d5d8016581060d9781433cfb0bb5 2028965 || ET TROJAN DADJOKE/Rail Tycoon Payload Execution || md5,4c89d5d8016581060d9781433cfb0bb5 [---] Removed non-rule lines: [---] -> Removed from sid-msg.map (1): 2009545 || ET MALWARE User-Agent (_TEST_) || url,doc.emergingthreats.net/2009545