Sourcefire VRT Update for Sourcefire 3D System

Date: 2014-04-28

This SRU number: 2014-04-28-003
Previous SRU number: 2014-04-28-002

Applies to:

This SEU number: 1098
Previous SEU: 1097

Applies to:

This is the complete list of rules modified in SRU 2014-04-28-003 and SEU 1098.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
126395APP-DETECTUfasoft bitcoin miner possible data uploadoffoffoff
129724FILE-OFFICEMicrosoft Word invalid sprmPNumRM recordoffoffdrop
129726FILE-OFFICEMicrosoft Word invalid sprmPNumRM recordoffoffdrop
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
128557PROTOCOL-DNSMalformed DNS query with HTTP contentoffoffdrop