Thanks for your submission. We'll check the files and add detection where necesarry.

Detection has been fixed, should reflect in the next few updates.

reported on March 07, 2018;msg874048#msg874048

Last tested on 26 April 2018 still not detected by CIS v5.9, av database 28915

Spend some time to research and found this is Java.Cogyeka / Worm.Java.AutoRun / HEUR:Worm.Script.Generic  / HEUR:Worm.Java.Generic according to following site:

Every time the worm create a copy (every each copy has different random name and SHA ) in windows RECYCLER BIN folder, when scanned CIS treat it as a safe file. Last year i submitted suspicious file in this folder and it was detected after 1 week i updated my av database, when it create another new copy again CIS doesn't detect it as malware or worm.

Help – CID / Re: HTML5 Video Playback
« Last post by knight404 on Today at 01:46:23 PM »
Haven't touched anything, did this as soon as it was installed.

What version of IceDragon and what OS/version?

What does say?
Help – CID / Re: HTML5 Video Playback
« Last post by knight404 on Today at 01:45:14 PM »
(Ver 58.0.1) Win 7 Pro, the thing is no problems on firefox, it's basically the same browser right?
Rules for modsecurity up to v2,9.x: Apache, LiteSpeed, Nginx, IIS
Rules for modsecurity 3: Nginx
Version 1.162

- XSS vulnerability in Two-Factor Authentication - Clockwork SMS plugin 1.0.2 for wordpress (CVE-2017-17780)
- XSS vulnerability in elevanssi plugin 4.0.4 for WordPress (CVE-2018-9034)
- XSS vulnerability in The Iptanus WordPress File Upload plugin before 4.3.4 for wordpress (CVE-2018-9844)
- XSS vulnerability in WP Live Chat Support plugin before 8.0.06 for wordpress (CVE-2018-9864)
- Directory Traversal vulnerability in WP Background Takeover Advertisements plugin before 4.1.5 for wordpress (CVE-2018-9118)
- RCE vulerability in Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 (CVE-2018-7600, CVE-2018-7602)
- SQLi vulnerability in Western Bridge Cobub Razor 0.8.0 (CVE-2018-8057)
- XSS vulnerability in Xiuno BBS 4.0.0 (CVE-2018-8942)
- bl_domains update
