RULE(RULE ID:320746)

Rule General Information
Release Date: 2018-05-28
Rule Name: Unix/VPNFilter IP Check
Severity:
CVE ID:
Rule Protection Details
Description: VPNFilter is a new malware targeting routers and network-attached storage(NAS) devices. The malware can maintain a persistent presence on the infected device, even after a reboot.
Impact: The malware will make the infected device unusable.
Affected OS: Network Device
Reference: https://www.symantec.com/blogs/threat-intelligence/vpnfilter-iot-malware
https://blogs.cisco.com/security/talos/vpnfilter
Solutions
Apply the latest patches of affected device and ensure that none default credentials are used.