Sourcefire VRT Update for Sourcefire 3D System

Date: 2015-02-26

This SRU number: 2015-02-25-001
Previous SRU number: 2015-02-23-001

Applies to:

This SEU number: 1257
Previous SEU: 1256

Applies to:

This is the complete list of rules modified in SRU 2015-02-25-001 and SEU 1257.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
11489SERVER-WEBAPPnobody accessoffoffoff
12180PUA-P2PBitTorrent announce requestoffoffoff
13827SERVER-WEBAPPPHP xmlrpc.php post attemptoffoffoff
113816SERVER-WEBAPPPHP xmlrpc.php command injection attemptoffoffoff
113817SERVER-WEBAPPPHP xmlrpc.php command injection attemptoffoffoff
113818SERVER-WEBAPPPHP alternate xmlrpc.php command injection attemptoffoffoff
118492BLACKLISTDNS request for known malware domain ilo.brenz.pl - Win.Trojan.Ramnitoffoffoff
118986FILE-PDFAdobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attemptoffoffdrop
118987FILE-PDFAdobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attemptoffoffdrop
119049MALWARE-CNCWin.Trojan.Gigade variant outbound connectionoffoffoff
119854DELETEDMALWARE-CNC Win.Trojan.Sality.AM variant outbound connection
119855DELETEDMALWARE-CNC Win.Trojan.Sality.AM variant outbound connection
119964MALWARE-CNCWin.Trojan.Sality variant outbound connectionoffdropdrop
120020MALWARE-CNCWin.Trojan.MalwareDoctor variant outbound connectionoffoffoff
124255DELETEDMALWARE-CNC Sality logo.gif URLs
125019OS-OTHERCisco Nexus OS software command injection attemptoffoffoff
125020OS-OTHERCisco Nexus OS software command injection attemptoffoffoff
125627MALWARE-CNCWin.Trojan.Reventon variant outbound communicationoffdropdrop
125809DELETEDMALWARE-CNC Sality logos.gif URLs
126310SERVER-MYSQLMySQL/MariaDB Server geometry query linestring object integer overflow attemptoffoffoff
127236SERVER-OTHERCitrix XenApp password buffer overflow attemptoffoffoff
128534FILE-OTHERApple Quicktime TeXML description attribute overflow attemptoffoffdrop
128535FILE-OTHERApple Quicktime TeXML description attribute overflow attemptoffoffdrop
128536FILE-OTHERApple Quicktime TeXML description attribute overflow attemptoffoffdrop
128537FILE-OTHERApple Quicktime TeXML description attribute overflow attemptoffoffdrop
129865MALWARE-CNCWin.Trojan.Pirminay variant outbound connectionoffdropdrop
130073MALWARE-CNCWin.Trojan.Kuluoz variant outbound connectionoffdropdrop
130288MALWARE-CNCWin.Trojan.Glupteba.M initial outbound connectionoffdropdrop
130336MALWARE-CNCLinux.Trojan.Calfbot outbound connectionoffoffoff
130483MALWARE-CNCWin.Trojan.Zbot/Bublik outbound connectionoffdropdrop
130484MALWARE-CNCWin.Trojan.Zbot/Bublik outbound connectionoffdropdrop
130548MALWARE-CNCWin.Trojan.Zeus variant outbound connectionoffdropdrop
130566MALWARE-CNCLinux.Trojan.Elknot outbound connectionoffoffdrop
130570MALWARE-CNCLinux.Trojan.Elknot outbound connectionoffoffoff
130900MALWARE-CNCWin.Trojan.Tuhao variant outbound connectionoffdropdrop
130914MALWARE-CNCWin.Trojan.Tuhao variant outbound connectionoffdropdrop
130915MALWARE-CNCWin.Trojan.SpySmall variant outbound connectionoffdropdrop
130919MALWARE-CNCWin.Trojan.Bancos variant outbound connectionoffdropdrop
130925MALWARE-CNCWin.Trojan.Hd backdoor outbound connectionoffoffdrop
130938MALWARE-CNCLinux.Trojan.Roopre outbound connectionoffdropdrop
130985MALWARE-CNCWin.Trojan.Vonriamt outbound communicationoffdropdrop
131020MALWARE-CNCWin.Trojan.Bancos variant outbound connectionoffdropdrop
131033MALWARE-CNCWin.Trojan.Cryptodefence variant outbound connectionoffdropdrop
131053MALWARE-CNCWin.Trojan.MadnessPro outbound connectionoffdropdrop
131070MALWARE-CNCWin.Rootkit.Necurs outbound connectionoffdropdrop
131084MALWARE-CNCWin.Trojan.Zbot variant outbound connectionoffdropdrop
131113MALWARE-CNCWin.Trojan.Bancos variant outbound connectionoffdropdrop
131114MALWARE-CNCWin.Trojan.Rfusclient outbound connectionoffdropdrop
131223MALWARE-CNCWin.Trojan.CryptoWall variant outbound connectionoffdropdrop
131240MALWARE-CNCWin.Trojan.Dosoloid variant outbound connectionoffdropdrop
131241MALWARE-CNCWin.Trojan.Dosoloid variant outbound connectionoffdropdrop
131242MALWARE-CNCWin.Trojan.Utishaf variant outbound connectionoffdropdrop
131244MALWARE-CNCWin.Trojan.Kuluoz outbound connectionoffoffdrop
131261MALWARE-CNCWin.Trojan.Symmi outbound connectionoffoffoff
131295MALWARE-CNCWin.Trojan.Zusy variant outbound connectionoffdropdrop
131303MALWARE-CNCWin.Trojan.Hadeki variant outbound connectionoffdropdrop
131314MALWARE-CNCWin.Trojan.Daikou variant outbound connectionoffdropdrop
131315MALWARE-CNCWin.Trojan.MSIL variant outbound connectionoffdropdrop
131316MALWARE-CNCWin.Trojan.Matsnu variant outbound connectionoffdropdrop
131317MALWARE-CNCWin.Trojan.Orbot variant outbound connectionoffdropdrop
131344MALWARE-CNCWin.Trojan.Levyatan variant outbound connectionoffdropdrop
131355MALWARE-CNCWin.Trojan.Bicololo outbound connectionoffdropdrop
131450MALWARE-CNCWin.Trojan.CryptoWall outbound connectionoffdropdrop
131452MALWARE-CNCWin.Trojan.Symmi variant outbound connectionoffdropdrop
131458MALWARE-CNCWin.Trojan.SDBot variant outbound connectionoffdropdrop
131527DELETEDMALWARE-CNC Win.Trojan.Ramnit variant outbound detected
131528DELETEDMALWARE-CNC Win.Trojan.Ramnit variant outbound detected
131593MALWARE-CNCAndr.Trojan.SMSSend outbound connectiondropdropdrop
131644MALWARE-CNCAndr.Trojan.Scarelocker outbound connectiondropdropdrop
131717MALWARE-CNCWin.Trojan.Ragua variant outbound connectionoffdropdrop
131808MALWARE-CNCLinux.Trojan.IptabLex outbound connectionoffdropdrop
131820MALWARE-CNCWin.Trojan.Darkcomet outbound keepalive signal sentoffdropdrop
131824MALWARE-CNCWin.Trojan.Graftor variant outbound connectionoffdropdrop
131827MALWARE-CNCWin.Trojan.Delf variant outbound connectionoffdropdrop
131835MALWARE-CNCWin.Trojan.Yesudac variant outbound connectionoffdropdrop
131836MALWARE-CNCWin.Trojan.MSIL.Seribe variant outbound connectionoffdropdrop
131837MALWARE-CNCWin.Trojan.Retgate variant outbound connectionoffdropdrop
131895MALWARE-CNCWin.Trojan.Toupi variant outbound connectionoffdropdrop
131896MALWARE-CNCWin.Trojan.Magnetor vairant outbound connectionoffdropdrop
131907MALWARE-CNCWin.Trojan.MSIL.Honerep variant outbound connectionoffdropdrop
131911MALWARE-CNCWin.Trojan.MSIL.Gareme variant outbound connectionoffdropdrop
131924MALWARE-CNCWin.Trojan.Symmi variant outbound connectionoffdropdrop
131928MALWARE-CNCLinux.Trojan.Jynxkit outbound communicationoffdropdrop
131941MALWARE-CNCWin.Trojan-Downloader.Pedrp variant outbound connectionoffdropdrop
131957MALWARE-CNCWin.Backdoor.MSIL.Torct variant outbound connectionoffdropdrop
131973MALWARE-CNCWin.Trojan.Chebri variant outbound connectionoffdropdrop
131974MALWARE-CNCWin.Trojan.Zegorg variant outbound connectionoffdropdrop
132002MALWARE-CNCWin.Worm.Zorenium variant outbound connectionoffdropdrop
132011MALWARE-CNCLinux.Backdoor.Flooder outbound connectionoffdropdrop
132012MALWARE-CNCLinux.Backdoor.Flooder outbound connectionoffdropdrop
132013MALWARE-CNCLinux.Worm.Darlloz variant outbound connectionoffdropdrop
132015MALWARE-CNCWin.Backdoor.Zeus variant outbound connectionoffdropdrop
132018MALWARE-CNCWin.Backdoor.Hupigon.NYK variant outbound connectionoffdropdrop
132020MALWARE-CNCWin.Backdoor.Krompt variant outbound connectionoffdropdrop
132023MALWARE-CNCWin.Trojan.Sinpid variant outbound connectionoffdropdrop
132028MALWARE-CNCWin.Backdoor.Klabcon variant outbound connectionoffdropdrop
132034MALWARE-CNCWin.Trojan.Larefervt variant outbound connectionoffdropdrop
132035MALWARE-CNCWin.Trojan.Boleteiro variant outbound connectionoffdropdrop
132036MALWARE-CNCWin.Trojan.Somoca vaniant outbound connectionoffdropdrop
132037MALWARE-CNCWin.Trojan.Somoca vaniant outbound connectionoffdropdrop
132040MALWARE-CNCLinux.Backdoor.Ganiw variant outbound connectionoffdropdrop
132048MALWARE-CNCWin.Trojan.Lecpetex variant outbound connectionoffdropdrop
132050MALWARE-CNCWin.Trojan.MSIL.Larosden variant outbound connectionoffdropdrop
132058MALWARE-CNCWin.Backdoor.Masatekar variant outbound connectionoffdropdrop
132061MALWARE-CNCWin.Trojan-Downloader.Nekill variant outbound connectionoffdropdrop
132066MALWARE-CNCWin.Trojan.Asprox outbound connectionoffdropdrop
132067MALWARE-CNCWin.Trojan.Asprox outbound connectionoffdropdrop
132070MALWARE-CNCWin.Trojan.Dalgan variant outbound connectionoffoffoff
132071MALWARE-CNCWin.Backdoor.Zapchast variant outbound connectionoffdropdrop
132073MALWARE-CNCWin.Trojan.Zemot outbound connectionoffdropdrop
132075MALWARE-CNCWin.Trojan.Small variant outbound connectionoffdropdrop
132086MALWARE-CNCWin.Backdoor.Corkow variant outbound connectionoffdropdrop
132090MALWARE-CNCWin.Trojan.Saaglup variant outbound connectionoffdropdrop
132091MALWARE-CNCWin.Backdoor.PcertStealer variant outbound connectionoffdropdrop
132093MALWARE-CNCWin.Trojan.Banker variant outbound connectionoffdropdrop
132096MALWARE-CNCWin.Trojan.Puver variant outbound connectionoffdropdrop
132121MALWARE-CNCWin.Trojan.Kryptik variant outbound connectionoffdropdrop
132123MALWARE-CNCWin.Trojan.Zbot variant outbound connectionoffdropdrop
132130MALWARE-CNCWin.Trojan.Bancos variant outbound connectionoffdropdrop
132195MALWARE-CNCWin.Trojan.Palebot variant outbound connectionoffdropdrop
132222MALWARE-CNCWin.Backdoor.MSIL.Liroospu variant outbound connectionoffdropdrop
132225MALWARE-CNCWin.Trojan.Cryptowall variant outbound connectionoffdropdrop
132293MALWARE-CNCWin.Trojan.Acanas variant outbound connectionoffdropdrop
132310MALWARE-CNCWin.Trojan.Farfi variant outbound connectionoffdropdrop
132334MALWARE-CNCWin.Trojan.Stantinko variant outbound connectionoffdropdrop
132338MALWARE-CNCWin.Trojan.Ropest variant outbound connectionoffdropdrop
132357MALWARE-CNCWin.Trojan.Akaza variant outbound connectionoffdropdrop
132367MALWARE-CNCWin.Trojan.GameOverZeus variant outbound connectionoffoffdrop
132372MALWARE-CNCWin.Trojan.Drepitt variant outbound connectionoffdropdrop
132373MALWARE-CNCWin.Trojan.Broonject variant outbound connectionoffdropdrop
132374MALWARE-CNCWin.Trojan.Androm variant outbound connectionoffdropdrop
132379MALWARE-CNCWin.Trojan.Baccamun variant outbound connectionoffdropdrop
132394MALWARE-CNCWin.Trojan.Orcarat variant outbound connectionoffdropdrop
132395MALWARE-CNCWin.Trojan.Orcarat variant outbound connectionoffdropdrop
132396MALWARE-CNCWin.Trojan.Orcarat variant outbound connectionoffdropdrop
132397MALWARE-CNCWin.Trojan.Orcarat variant outbound connectionoffdropdrop
132401MALWARE-CNCWin.Backdoor.Kivars outbound connectionoffdropdrop
132469MALWARE-CNCWin.Trojan.Bankeiya outbound connectionoffdropdrop
132486MALWARE-CNCWin.Backdoor.Exadog outbound connectionoffdropdrop
132487MALWARE-CNCWin.Backdoor.Exadog variant outbound connectionoffdropdrop
132506MALWARE-CNCWin.Trojan.Secdeskinf outbound connectionoffdropdrop
132510MALWARE-CNCLinux.Trojan.PiltabeA outbound connectionoffdropdrop
132513MALWARE-CNCPCRat variant outbound connectionoffdropdrop
132556MALWARE-CNCWin.Trojan.Bayoboiz outbound connectionoffdropdrop
132557MALWARE-CNCWin.Trojan.Bayoboiz outbound connectionoffdropdrop
132583MALWARE-CNCWin.Trojan.Bayoboiz outbound connectionoffdropdrop
132584MALWARE-CNCWin.Trojan.Symmi variant outbound connectionoffdropdrop
132599MALWARE-CNCWin.Backdoor.Mysayad outbound connectionoffdropdrop
132604MALWARE-CNCWin.Backdoor.Mysayad file wipe attemptoffdropdrop
132605MALWARE-CNCWin.Worm.Jenxcus variant outbound connectionoffdropdrop
132606MALWARE-CNCWin.Worm.Jenxcus variant outbound connectionoffdropdrop
132621MALWARE-CNCWin.Trojan.Regin outbound connectionoffoffdrop
132622MALWARE-CNCWin.Trojan.Regin outbound connectionoffdropdrop
132623MALWARE-CNCWin.Trojan.Regin outbound connectionoffdropdrop
132624MALWARE-CNCWin.Trojan.Regin outbound connectionoffdropdrop
132670MALWARE-CNCWin.Dropper.Ch variant outbound connectionoffdropdrop
132677MALWARE-CNCWin.Trojan.Dridex variant outbound connectionoffdropdrop
132678MALWARE-CNCWin.Trojan.Dridex variant outbound connectionoffdropdrop
132770MALWARE-CNCWin.Trojan.WOWCheckC Attempted CNC on non-standard HTTP Portsoffdropdrop
132791MALWARE-CNCWin.Virus.Ransomlock outbound connectionoffdropdrop
132823MALWARE-CNCWin.Trojan.Darkhotel outbound connectionoffdropdrop
132825MALWARE-CNCWin.Trojan.Darkhotel outbound connectionoffdropdrop
132852MALWARE-CNCWin.Trojan.Poolfiend variant outbound connectionoffdropdrop
132853MALWARE-CNCWin.Trojan.Poolfiend variant outbound connectionoffdropdrop
132892MALWARE-CNCWin.Trojan.TorLocker variant outbound connectionoffdropdrop
132893MALWARE-CNCWin.Trojan.Finforst outbound connectionoffdropdrop
132956MALWARE-CNCWin.Trojan.Bladabindi variant outbound connectionoffdropdrop
132976MALWARE-CNCWin.Trojan.Kuluos variant outbound connectionoffdropdrop
132977MALWARE-CNCWin.Trojan.Kuluos variant outbound connectionoffdropdrop
132987MALWARE-CNCWin.Trojan.Graftor outbound connectionoffdropdrop
132988MALWARE-CNCWin.Trojan.Graftor outbound connectionoffdropdrop
132989MALWARE-CNCWin.Trojan.Graftor outbound connectionoffdropdrop
132990MALWARE-CNCWin.Trojan.Toopu outbound connectionoffdropdrop
133054MALWARE-CNCWin.Trojan.Joanap outbound connectionoffoffdrop
133081MALWARE-CNCOnionDuke variant outbound connectionoffdropdrop
133084MALWARE-CNCWin.Trojan.Tosct variant outbound connectionoffdropdrop
133152MALWARE-CNCWin.Trojan.Nurjax.A outbound connectionoffdropdrop
133153MALWARE-CNCWin.Trojan.Heur variant outbound connectionoffdropdrop
133200MALWARE-CNCWin.Trojan.Pisces variant outbound connectionoffdropdrop
133211MALWARE-CNCWin.Trojan.Upatre variant outbound connectionoffdropdrop
133219MALWARE-CNCWin.Trojan.Gamarue variant outbound connectionoffdropdrop
133227MALWARE-CNCWin.Trojan.HawkEye Keylogger exfiltration attempt - clipboard and screenshotoffdropdrop
133228MALWARE-CNCWin.Kovter variant outbound connectionoffdropdrop
133282MALWARE-CNCWin.Trojan.Upatre variant outbound connectionoffdropdrop
133305MALWARE-CNCWin.Trojan.Foxy variant outbound connectionoffdropdrop
133431MALWARE-CNCCryptowall 3.0 variant outbound connectionoffdropdrop
133432MALWARE-CNCCryptowall 3.0 variant outbound connectionoffdropdrop
133433MALWARE-CNCCryptowall 3.0 variant outbound connectionoffdropdrop
133434MALWARE-CNCCryptowall 3.0 variant outbound connectionoffdropdrop
133435MALWARE-CNCCryptowall 3.0 variant outbound connectionoffdropdrop
133443MALWARE-CNCWin.Trojan.Gefetroe variant outbound connectionoffdropdrop
133444MALWARE-CNCWin.Trojan.Gefetroe variant outbound connectionoffdropdrop
133450MALWARE-CNCWin.Trojan.FileEncoder variant outbound connectionoffdropdrop
133453MALWARE-CNCWin.Trojan.FileEncoder variant outbound connectionoffdropdrop
133457MALWARE-CNCWin.Trojan.Symmi variant outbound connectionoffdropdrop
133547MALWARE-CNCWin.Trojan.Turla outbound connectionoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
11145SERVER-WEBAPProot accessoffoffoff
119389PROTOCOL-VOIPREGISTER floodoffoffoff
121669PROTOCOL-VOIPDigium Asterisk expires header denial of service attemptoffoffoff