Skip to content

Commit cb29e43

Browse files
committed
Update changelog for 20181220.165251 release
1 parent 5606d57 commit cb29e43

File tree

1 file changed

+124
-0
lines changed

1 file changed

+124
-0
lines changed

debian/changelog

+124
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,127 @@
1+
mwscan (20181220.165251) xenial; urgency=medium
2+
3+
[ Willem de Groot ]
4+
* Updated CentOS instructions
5+
6+
[ Max Chadwick ]
7+
* Use HTTPS in instructions (#206)
8+
9+
[ thomasbrockmeier ]
10+
* add brewtees.com burner domain (#207)
11+
12+
[ Willem de Groot ]
13+
* brewtees.com from burner to hijacked, see #207 (#208)
14+
15+
[ thomasbrockmeier ]
16+
* add compromised domain (#209)
17+
18+
[ Willem de Groot ]
19+
* Add cratfsman hijacker (#210)
20+
* Add extra rule for encrypted webshell (#211)
21+
* Add reinfection mechanism sample (#212)
22+
* Py2.6 doesnt have keyword args for decode() (#205)
23+
* Maxided server spam (#215)
24+
25+
[ Jeroen Vermeulen ]
26+
* Whitelisted es5-ext JS file (#214)
27+
28+
[ thomasbrockmeier ]
29+
* This strain was spotted in the wild with an 8 character offset (#216)
30+
* adds jquery-js.com (#217)
31+
32+
[ Willem de Groot ]
33+
* Added google-anaiytic.com burner
34+
* Add cdn-ch.org skimmer (#218)
35+
* Froghopper backdoor dropper in gif asset (#219)
36+
* Update README.md
37+
* Removed fp due to false positives (#220)
38+
* Walletgear obfuscated malware (#221)
39+
* Malware killing malware (#222)
40+
* Added market-stats.com burner (reg 2017) (#223)
41+
* Found a load of new malware by cross-referencing (#224)
42+
* TCI auto hijacked lightbox (#225)
43+
* Remove hex eval: FP (#226)
44+
* Remove too generic FP sigs (#227)
45+
* Update burner-domains.txt
46+
* Erpflex hijack (#228)
47+
48+
[ GoonCyberSec ]
49+
* Update burner-domains.txt (#230)
50+
51+
[ Willem de Groot ]
52+
* Add fake googletagmanager burner (#232)
53+
* Add jscontroller.stream burner (~500 hits) (#233)
54+
* Add allyouwant.online, see SE question (#234)
55+
* Update burner-domains.txt
56+
* Add https://magentocore.net/clear.json
57+
* Moved FP to suspicious.yar (#235)
58+
* Add mage.js from magentocore.net
59+
* Remove FP from custom
60+
* Moved cloudservice.tw from frontend to burners
61+
* Add g-analytics analytics.js
62+
* Added magento.name (replacement for magentocore.net)
63+
64+
[ Besselink ]
65+
* Update who-is-using.md (#236)
66+
67+
[ krautface ]
68+
* Added exfil domains (#237)
69+
70+
[ Willem de Groot ]
71+
* Update README with early access notice
72+
* README.md typo
73+
* Update README.md
74+
* Update README.md
75+
* Added Gossi's find https://twitter.com/GossiTheDog/status/1042807834109456384
76+
77+
[ pmcmanaman ]
78+
* Update burner-domains.txt (#238)
79+
* add domains from (#239)
80+
81+
[ Fabio Ros ]
82+
* New malwares, and doc improvements (#240)
83+
84+
[ Roland Walraven ]
85+
* Add whitelist entries for obfuscated licence check. (#241)
86+
87+
[ Willem de Groot ]
88+
* Update README.md
89+
90+
[ pmcmanaman ]
91+
* add more domains (#242)
92+
93+
[ Willem de Groot ]
94+
* Update README.md
95+
96+
[ evlhomer ]
97+
* Added magento-analytics.com (#243)
98+
99+
[ Dave Chamberlain ]
100+
* Added new domain (#244)
101+
102+
[ Edwin ]
103+
* Update burner-domains.txt (#245)
104+
105+
[ Jonas Hünig ]
106+
* Added whitelist for phpwcms (#248)
107+
108+
[ leeps ]
109+
* Whitelist: Add more versions of sqlparser.lib.php (#247)
110+
111+
[ Jonas Hünig ]
112+
* more exact matching for eval_post (#249)
113+
114+
[ Lucas van Staden ]
115+
* Add way to combine with mailx for hosted server cron usage (#250)
116+
117+
[ Yuxael Egotk ]
118+
* Fix handling of files with cached rulesets (#251)
119+
120+
[ Willem de Groot ]
121+
* Update version in setup.py to 20181220.165251
122+
123+
-- Willem de Groot <[email protected]> Thu, 20 Dec 2018 16:52:58 +0100
124+
1125
mwscan (20180510.172121) xenial; urgency=medium
2126

3127
[ evlhomer ]

0 commit comments

Comments
 (0)