Sourcefire VRT Update for Sourcefire 3D System

Date: 2014-11-24

This SRU number: 2014-11-24-001
Previous SRU number: 2014-11-20-001

Applies to:

This SEU number: 1210
Previous SEU: 1209

Applies to:

This is the complete list of rules added in SRU 2014-11-24-001 and SEU 1210.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
132598MALWARE-CNCWin.Backdoor.Mysayad file wipe attemptoffdropdrop
132599MALWARE-CNCWin.Backdoor.Mysayad outbound connection attemptoffdropdrop
132600MALWARE-CNCWin.Backdoor.Mysayad file wipe attemptoffdropdrop
132601SERVER-OTHERHikvision DVR RTSP request buffer overflow attemptoffoffoff
132604MALWARE-CNCWin.Backdoor.Mysayad file wipe attemptoffdropdrop
132605MALWARE-CNCWin.Worm.Jenxcus variant outbound connection attemptoffdropdrop
132606MALWARE-CNCWin.Worm.Jenxcus variant outbound connection attemptoffdropdrop
132607MALWARE-CNCWin.Trojan.Sodebral HTTP Response attemptoffdropdrop
132608MALWARE-CNCWin.Trojan.Sodebral HTTP Response attemptoffdropdrop
132609MALWARE-CNCWin.Trojan.NetWiredRC variant registration messageoffdropdrop
132610MALWARE-CNCWin.Trojan.NetWiredRC variant keepaliveoffdropdrop
132611SERVER-WEBAPPphpMemcachedAdmin path traversal attemptoffoffdrop
132612BLACKLISTDNS request for known malware domain cechire.comoffdropdrop
132613MALWARE-CNCWin.Trojan.NetWiredRC variant keepaliveoffdropdrop
132614MALWARE-CNCWin.Trojan.NetWiredRC variant keepaliveoffdropdrop
132615OS-WINDOWSMicrosoft Windows search protocol remote command injection attemptoffoffoff
132619FILE-OTHERMostGear EasyLanFolderShare serial key overflow attemptoffoffoff
132620FILE-OTHERMostGear EasyLanFolderShare serial key overflow attemptoffoffoff
132621MALWARE-CNCWin.Trojan.Regin outbound connection attemptoffdropdrop
132622MALWARE-CNCWin.Trojan.Regin outbound connection attemptoffdropdrop
132623MALWARE-CNCWin.Trojan.Regin outbound connection attemptoffdropdrop
132624MALWARE-CNCWin.Trojan.Regin outbound connection attemptoffdropdrop
132625FILE-OFFICEMicrosoft Office Excel DV record buffer overflow attemptoffoffdrop
132626BROWSER-PLUGINSAdobe Flash broker privilege escalation file creation attemptoffdropdrop
132627BROWSER-PLUGINSAdobe Flash broker privilege escalation file creation attemptoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
132602POLICY-OTHERManageEngine Eventlog Analyzer credential disclosure attemptoffoffoff
132603POLICY-OTHERManageEngine Eventlog Analyzer information disclosure attemptoffoffoff
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
132616FILE-IDENTIFYMicrosoft Windows Registry file attachment detectedoffoffoff
132617FILE-IDENTIFYMicrosoft Windows Registry file attachment detectedoffoffoff
132618FILE-IDENTIFYMicrosoft Windows Registry file download requestoffoffoff

Updated Rules:

Updated rules can be found at this link.