Sourcefire VRT Update for Sourcefire 3D System

Date: 2014-04-28

This SRU number: 2014-04-28-003
Previous SRU number: 2014-04-28-002

Applies to:

This SEU number: 1098
Previous SEU: 1097

Applies to:

This is the complete list of rules added in SRU 2014-04-28-003 and SEU 1098.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
130824BLACKLISTDNS request for known malware domain betterbrowse.net - Win.Trojan.Mudropoffdropdrop
130825BLACKLISTDNS request for known malware domain browsemark.net - Win.Trojan.Mudropoffdropdrop
130826BLACKLISTDNS request for known malware domain browsesmart.net - Win.Trojan.Mudropoffdropdrop
130827BLACKLISTDNS request for known malware domain diamondata.net - Win.Trojan.Mudropoffdropdrop
130828BLACKLISTDNS request for known malware domain grabmyrez.co - Win.Trojan.Mudropoffdropdrop
130829BLACKLISTDNS request for known malware domain jotzey.net - Win.Trojan.Mudropoffdropdrop
130830BLACKLISTDNS request for known malware domain kozaka.net - Win.Trojan.Mudropoffdropdrop
130831BLACKLISTDNS request for known malware domain lemurleap.info - Win.Trojan.Mudropoffdropdrop
130832BLACKLISTDNS request for known malware domain luckyleap.net - Win.Trojan.Mudropoffdropdrop
130833BLACKLISTDNS request for known malware domain megabrowse.biz - Win.Trojan.Mudropoffdropdrop
130834BLACKLISTDNS request for known malware domain outobox.net - Win.Trojan.Mudropoffdropdrop
130835BLACKLISTDNS request for known malware domain plurpush.net - Win.Trojan.Mudropoffdropdrop
130836BLACKLISTDNS request for known malware domain qualitink.net - Win.Trojan.Mudropoffdropdrop
130837BLACKLISTDNS request for known malware domain saltarsmart.biz - Win.Trojan.Mudropoffdropdrop
130838BLACKLISTDNS request for known malware domain secretsauce.biz - Win.Trojan.Mudropoffdropdrop
130839BLACKLISTDNS request for known malware domain serialtrunc.com - Win.Trojan.Mudropoffdropdrop
130840BLACKLISTDNS request for known malware domain towertilt.com - Win.Trojan.Mudropoffdropdrop
130841BLACKLISTDNS request for known malware domain websparkle.biz - Win.Trojan.Mudropoffdropdrop
130842BLACKLISTDNS request for known malware domain wisenwizard.net - Win.Trojan.Mudropoffdropdrop
130843FILE-FLASHAdobe Acrobat Reader cross-site scripting attemptoffoffoff
130844FILE-FLASHAdobe Acrobat Reader cross-site scripting attemptoffoffoff
130845FILE-FLASHAdobe Flash Player SWF ActionScript exploit attemptoffdropdrop
130846FILE-FLASHAdobe Flash Player SWF ActionScript exploit attemptoffdropdrop
130847BROWSER-IEMicrosoft Internet Explorer CElement event handler use after free attemptoffdropdrop
130848BROWSER-IEMicrosoft Internet Explorer CElement event handler use after free attemptoffdropdrop
130849BROWSER-IEMicrosoft Internet Explorer type confusion attemptoffdropdrop
130850BROWSER-IEMicrosoft Internet Explorer type confusion attemptoffdropdrop
130851BROWSER-IEMicrosoft Internet Explorer type confusion attemptoffdropdrop
130852EXPLOIT-KITAngler exploit kit landing page - base64 encoded xml/jnlp statementoffdropdrop
130853APP-DETECTDNS request for known bitcoin domain bitseed.xf2.orgoffoffoff
130854APP-DETECTDNS request for known bitcoin domain dnsseed.btcltcftc.comoffoffoff
130855APP-DETECTDNS request for known bitcoin domain dnsseed.fc.altcointech.netoffoffoff
130856APP-DETECTDNS request for known bitcoin domain dnsseed.feathercoin.comoffoffoff
130857APP-DETECTDNS request for known bitcoin domain dnsseed.koin-project.comoffoffoff
130858APP-DETECTDNS request for known bitcoin domain dnsseed.litecoinpool.orgoffoffoff
130859APP-DETECTDNS request for known bitcoin domain dnsseed.litecointools.comoffoffoff
130860APP-DETECTDNS request for known bitcoin domain dnsseed.ltc.xurious.comoffoffoff
130861APP-DETECTDNS request for known bitcoin domain dnsseed.ppc.altcointech.netoffoffoff
130862APP-DETECTDNS request for known bitcoin domain dnsseed.xpm.altcointech.netoffoffoff
130863APP-DETECTDNS request for known bitcoin domain dvcstable01.dvcnode.orgoffoffoff
130864APP-DETECTDNS request for known bitcoin domain dvcstable02.dvcnode.orgoffoffoff
130865APP-DETECTDNS request for known bitcoin domain seed.bitcoinstats.comoffoffoff
130866APP-DETECTDNS request for known bitcoin domain seed.dglibrary.orgoffoffoff
130867APP-DETECTDNS request for known bitcoin domain seed.dogechain.infooffoffoff
130868APP-DETECTDNS request for known bitcoin domain seed.dogecoin.comoffoffoff
130869APP-DETECTDNS request for known bitcoin domain seed.mophides.comoffoffoff
130870APP-DETECTDNS request for known bitcoin domain seed.ppcoin.netoffoffoff
130871APP-DETECTDNS request for known bitcoin domain seed1.metiscoininvest.infooffoffoff
130872APP-DETECTDNS request for known bitcoin domain seed1.net.terracoin.orgoffoffoff
130873APP-DETECTDNS request for known bitcoin domain seed1.qrkcoin.orgoffoffoff
130874APP-DETECTDNS request for known bitcoin domain seed2.net.terracoin.orgoffoffoff
130875APP-DETECTDNS request for known bitcoin domain tnseed.ppcoin.netoffoffoff
130876FILE-MULTIMEDIAAdobe Flash pixel bender buffer overflow attemptoffdropdrop
130877FILE-MULTIMEDIAAdobe Flash pixel bender buffer overflow attemptoffdropdrop

Updated Rules:

Updated rules can be found at this link.