Sourcefire VRT Update for Sourcefire 3D System

Date: 2014-09-18

This SRU number: 2014-09-17-002
Previous SRU number: 2014-09-15-001

Applies to:

This SEU number: 1172
Previous SEU: 1170

Applies to:

This is the complete list of rules added in SRU 2014-09-17-002 and SEU 1172.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
131907MALWARE-CNCWin.Trojan.MSIL.Honerep variant outbound connection attemptoffdropdrop
131908BLACKLISTDNS request for known malware domain recoalmeida.gratisphphost.info - Win.Trojan.Basostaboffdropdrop
131909MALWARE-CNCWin.Trojan.Basostab variant outbound connectiondropdropdrop
131910DELETEDMALWARE-CNC Win.Trojan.Kanav variant outbound connection
131911MALWARE-CNCWin.Trojan.MSIL.Gareme variant outbound connection attemptoffdropdrop
131912SERVER-WEBAPPcPanel 9.01 multiple URI parameters cross site scripting attemptoffoffoff
131913MALWARE-CNCWin.Trojan.Maozhi variant outbound connectionoffdropdrop
131914SERVER-WEBAPPMicrosoft ASP.NET null byte injection attemptoffoffoff
131915MALWARE-CNCWIN.Trojan.Ziyazo variant outbound connectionoffdropdrop
131916MALWARE-CNCWIN.Trojan.Ziyazo variant outbound connectionoffdropdrop
131917BLACKLISTDNS request for known malware domain vampire123.zapto.org - Win.Trojan.Disfaoffdropdrop
131918BLACKLISTDNS request for known malware domain enemydont.net - Win.Trojan.Symmioffdropdrop
131919BLACKLISTDNS request for known malware domain saltsecond.net - Win.Trojan.Symmioffdropdrop
131920BLACKLISTDNS request for known malware domain sellsmall.net - Win.Trojan.Symmioffdropdrop
131921BLACKLISTDNS request for known malware domain southblood.net - Win.Trojan.Symmioffdropdrop
131922BLACKLISTDNS request for known malware domain wheelreply.net - Win.Trojan.Symmioffdropdrop
131923MALWARE-CNCWin.Trojan.Symmi variant HTTP response attemptoffdropdrop
131924MALWARE-CNCWin.Trojan.Symmi variant outbound connection attemptoffdropdrop
131925MALWARE-CNCLinux.Trojan.Jynxkit outbound communicationoffdropdrop
131926FILE-OFFICEMicrosoft Windows common controls MSCOMCTL.OCX buffer overflow attemptoffdropdrop
131927FILE-OFFICEMicrosoft Windows common controls MSCOMCTL.OCX buffer overflow attemptoffdropdrop

Updated Rules:

Updated rules can be found at this link.