* Talos combines our security experts from TRAC, SecApps, and VRT teams.
This SRU number: 2015-05-06-001
Previous SRU number: 2015-05-05-001
Applies to:
This SEU number: 1292
Previous SEU: 1291
Applies to:
This is the complete list of rules modified in SRU 2015-05-06-001 and SEU 1292.
The format of the file is:
GID - SID - Rule Group - Rule Message - Policy State
The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.
The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.
Note: Unless stated explicitly, the rules are for the series of products listed above.
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 569 | PROTOCOL-RPC | snmpXdmi overflow attempt TCP | off | off | off |
1 | 610 | PROTOCOL-SERVICES | rsh root | off | off | off |
1 | 648 | INDICATOR-SHELLCODE | x86 NOOP | off | off | off |
1 | 654 | SERVER-MAIL | RCPT TO overflow | off | off | off |
1 | 974 | SERVER-IIS | Microsoft Windows IIS directory traversal attempt | off | off | off |
1 | 1325 | INDICATOR-SHELLCODE | ssh CRC32 overflow filler | off | off | off |
1 | 1390 | INDICATOR-SHELLCODE | x86 inc ebx NOOP | off | off | off |
1 | 1634 | PROTOCOL-POP | PASS overflow attempt | off | off | off |
1 | 1644 | SERVER-WEBAPP | test-cgi attempt | off | off | off |
1 | 1734 | PROTOCOL-FTP | USER overflow attempt | off | off | off |
1 | 1762 | SERVER-WEBAPP | phf arbitrary command execution attempt | off | off | off |
1 | 1842 | PROTOCOL-IMAP | login buffer overflow attempt | off | off | off |
1 | 1866 | PROTOCOL-POP | USER overflow attempt | off | off | off |
1 | 1941 | PROTOCOL-TFTP | GET filename overflow attempt | off | off | off |
1 | 1972 | PROTOCOL-FTP | PASS overflow attempt | off | off | off |
1 | 1973 | PROTOCOL-FTP | MKD overflow attempt | off | off | off |
1 | 1975 | PROTOCOL-FTP | DELE overflow attempt | off | off | drop |
1 | 1976 | PROTOCOL-FTP | RMD overflow attempt | off | off | off |
1 | 2045 | PROTOCOL-RPC | snmpXdmi overflow attempt UDP | off | off | off |
1 | 2123 | INDICATOR-COMPROMISE | Microsoft cmd.exe banner | off | off | off |
1 | 2389 | PROTOCOL-FTP | RNTO overflow attempt | off | off | off |
1 | 2392 | PROTOCOL-FTP | RETR overflow attempt | off | off | off |
1 | 2438 | FILE-MULTIMEDIA | RealNetworks RealPlayer playlist file URL overflow attempt | off | off | off |
1 | 2439 | FILE-MULTIMEDIA | RealNetworks RealPlayer playlist http URL overflow attempt | off | off | off |
1 | 2440 | FILE-MULTIMEDIA | RealNetworks RealPlayer playlist rtsp URL overflow attempt | off | off | off |
1 | 2508 | OS-WINDOWS | DCERPC NCACN-IP-TCP lsass DsRolerUpgradeDownlevelServer overflow attempt | off | off | off |
1 | 2611 | SERVER-ORACLE | LINK metadata buffer overflow attempt | off | off | off |
1 | 3073 | PROTOCOL-IMAP | SUBSCRIBE literal overflow attempt | off | off | off |
1 | 3074 | PROTOCOL-IMAP | SUBSCRIBE overflow attempt | off | off | off |
1 | 3079 | BROWSER-IE | Microsoft Internet Explorer ANI file parsing buffer overflow attempt | off | off | off |
1 | 3084 | SERVER-OTHER | Veritas backup overflow attempt | off | off | off |
1 | 3087 | SERVER-IIS | w3who.dll buffer overflow attempt | off | off | off |
1 | 3114 | OS-WINDOWS | DCERPC NCACN-IP-TCP llsrpc LlsrConnect overflow attempt | off | off | off |
1 | 3457 | SERVER-OTHER | Arkeia backup client type 77 overflow attempt | off | off | off |
1 | 3461 | SERVER-MAIL | Content-Type overflow attempt | off | off | off |
1 | 3473 | FILE-MULTIMEDIA | RealNetworks RealPlayer SMIL file overflow attempt | off | off | off |
1 | 3517 | SERVER-OTHER | Computer Associates license PUTOLF overflow attempt | off | off | off |
1 | 3520 | SERVER-OTHER | Computer Associates license GCR NETWORK overflow attempt | off | off | off |
1 | 3522 | SERVER-OTHER | Computer Associates license GETCONFIG server overflow attempt | off | off | off |
1 | 3533 | PROTOCOL-TELNET | client LINEMODE SLC overflow attempt | off | off | off |
1 | 3534 | FILE-IMAGE | Mozilla GIF single packet heap overflow - NETSCAPE2.0 | off | off | off |
1 | 3537 | PROTOCOL-TELNET | client ENV OPT escape overflow attempt | off | off | off |
1 | 3550 | BROWSER-IE | Microsoft Internet Explorer HTML http/https scheme hostname overflow attempt | off | off | off |
1 | 3552 | OS-WINDOWS | Microsoft Windows OLE32 MSHTA masquerade attempt | off | off | off |
1 | 3590 | OS-WINDOWS | DCERPC NCACN-IP-TCP mqqm QMDeleteObject overflow attempt | off | off | off |
1 | 3632 | FILE-IMAGE | Microsoft Windows Bitmap width integer overflow attempt | off | off | off |
1 | 3658 | SERVER-OTHER | ARCserve universal backup agent option 1000 little endian buffer overflow attempt | off | off | off |
1 | 3679 | INDICATOR-OBFUSCATION | Multiple Products IFRAME src javascript code execution | off | off | off |
1 | 3686 | BROWSER-IE | Microsoft Internet Explorer Content Advisor memory corruption attempt | off | off | off |
1 | 3693 | SERVER-WEBAPP | IBM WebSphere j_security_check overflow attempt | off | off | off |
1 | 3695 | SERVER-OTHER | Veritas Backup Agent password overflow attempt | off | off | off |
1 | 3814 | BROWSER-IE | Microsoft Internet Explorer javaprxy.dll COM access | off | off | off |
1 | 3818 | PROTOCOL-TFTP | PUT transfer mode overflow attempt | off | off | off |
1 | 3820 | FILE-IDENTIFY | Microsoft Windows CHM file magic detected | off | off | off |
1 | 3823 | FILE-MULTIMEDIA | RealNetworks RealPlayer realtext file bad version buffer overflow attempt | off | off | off |
1 | 3824 | SERVER-MAIL | AUTH user overflow attempt | off | off | off |
1 | 4127 | SERVER-OTHER | Novell eDirectory Server iMonitor overflow attempt | off | off | off |
1 | 4131 | SERVER-OTHER | SHOUTcast URI format string attempt | off | off | off |
1 | 4135 | BROWSER-IE | Microsoft Internet Explorer JPEG rendering buffer overflow attempt | off | off | off |
1 | 4142 | SERVER-ORACLE | reports servlet command execution attempt | off | off | off |
1 | 4148 | BROWSER-PLUGINS | Microsoft Internet Explorer DHTML Editing ActiveX clsid access | off | off | off |
1 | 4155 | BROWSER-PLUGINS | Microsoft Internet Explorer htmlfile ActiveX object access attempt | off | drop | drop |
1 | 4170 | BROWSER-PLUGINS | Microsoft Office 2000 and 2002 Web Components Data Source Control ActiveX clsid access | off | off | off |
1 | 4177 | BROWSER-PLUGINS | Microsoft Office Web Components OWC.Spreadsheet.9 ActiveX clsid access attempt | off | off | off |
1 | 4196 | FILE-IDENTIFY | CBO CBL CBM file transfer attempt | off | off | off |
1 | 4637 | SERVER-OTHER | MailEnable HTTPMail buffer overflow attempt | off | off | off |
1 | 4642 | SERVER-ORACLE | sys.pbsde.init buffer overflow attempt | off | off | off |
1 | 4643 | OS-WINDOWS | Microsoft Windows malformed shortcut file buffer overflow attempt | off | off | off |
1 | 4644 | OS-WINDOWS | Microsoft Windows malformed shortcut file with comment buffer overflow attempt | off | off | off |
1 | 4647 | BROWSER-IE | Microsoft Internet Explorer javascript onload overflow attempt | off | off | off |
1 | 4677 | SERVER-ORACLE | Enterprise Manager Application Server Control GET parameter overflow attempt | off | off | off |
1 | 4681 | SERVER-WEBAPP | Symantec Antivirus admin scan interface negative Content-Length attempt | off | off | off |
1 | 4899 | BROWSER-PLUGINS | Microsoft Internet Explorer ISupportErrorInfo Interface ActiveX object access | off | off | off |
1 | 4916 | BROWSER-IE | Microsoft Internet Explorer javascript onload document.write obfuscation overflow attempt | off | off | off |
1 | 4917 | BROWSER-IE | Microsoft Internet Explorer javascript onload prompt obfuscation overflow attempt | off | off | off |
1 | 4985 | SERVER-WEBAPP | Twiki rdiff rev command injection attempt | off | off | off |
1 | 5318 | FILE-MULTIMEDIA | Microsoft Windows wmf file arbitrary code execution attempt | off | off | off |
1 | 5710 | OS-WINDOWS | Microsoft Windows Media Player Plugin for Non-IE browsers buffer overflow attempt | off | off | off |
1 | 5712 | FILE-IMAGE | Microsoft Windows Media Player invalid data offset bitmap heap overflow attempt | off | off | off |
1 | 6009 | BROWSER-PLUGINS | Microsoft Windows RDS.Dataspace ActiveX object access | off | off | off |
1 | 6011 | SERVER-OTHER | VERITAS NetBackup vnetd buffer overflow attempt | off | off | off |
1 | 6405 | SERVER-OTHER | Veritas NetBackup Volume Manager overflow attempt | off | off | off |
1 | 6414 | SERVER-WEBAPP | Novell GroupWise Messenger Accept-Language header buffer overflow attempt | off | off | off |
1 | 6419 | OS-WINDOWS | DCERPC NCACN-IP-TCP msdtc BuildContextW invalid uuid size attempt | off | off | off |
1 | 6420 | OS-WINDOWS | DCERPC NCADG-IP-UDP msdtc BuildContextW invalid uuid size attempt | off | off | off |
1 | 6431 | OS-WINDOWS | DCERPC NCACN-IP-TCP msdtc BuildContextW invalid second uuid size attempt | off | off | off |
1 | 6432 | OS-WINDOWS | DCERPC NCADG-IP-UDP msdtc BuildContextW invalid second uuid size attempt | off | off | off |
1 | 6471 | SERVER-OTHER | RealVNC password authentication bypass attempt | off | off | off |
1 | 6504 | FILE-OTHER | Sophos Anti-Virus CAB file overflow attempt | off | off | off |
1 | 6505 | FILE-IMAGE | Apple QuickTime fpx file SectNumMiniFAT overflow attempt | off | off | off |
1 | 6506 | FILE-MULTIMEDIA | Apple QuickTime udta atom overflow attempt | off | off | off |
1 | 6509 | BROWSER-IE | Microsoft Internet Explorer mhtml uri href buffer overflow attempt | off | off | off |
1 | 6512 | SERVER-OTHER | symantec antivirus realtime virusscan overflow attempt | off | off | off |
1 | 6584 | OS-WINDOWS | DCERPC NCACN-IP-TCP rras RasRpcSubmitRequest overflow attempt | off | off | off |
1 | 6689 | FILE-IMAGE | Microsoft Windows Media Player Malformed PNG detected cHRM overflow attempt | off | off | off |
1 | 6692 | FILE-IMAGE | Microsoft Windows Media Player Malformed PNG detected sRGB overflow attempt | off | off | off |
1 | 6695 | FILE-IMAGE | Microsoft Windows Media Player Malformed PNG detected tRNS overflow attempt | off | off | off |
1 | 7002 | FILE-OFFICE | Microsoft Office Excel url unicode overflow attempt | off | off | drop |
1 | 7004 | BROWSER-PLUGINS | Microsoft Windows Internet.HHCtrl.1 ActiveX function call access | off | off | off |
1 | 7009 | BROWSER-PLUGINS | Microsoft Windows DirectAnimation.StructuredGraphicsControl ActiveX function call access | off | off | off |
1 | 7020 | BROWSER-IE | Microsoft Internet Explorer isComponentInstalled function buffer overflow | off | off | off |
1 | 7025 | FILE-OFFICE | Microsoft Office Excel url unicode overflow attempt | off | off | off |
1 | 7026 | BROWSER-PLUGINS | Microsoft Windows RDS.Dataspace ActiveX function call access | off | off | off |
1 | 7027 | SERVER-IIS | Microsoft Office FrontPage server extensions 2002 cross site scripting attempt | off | off | off |
1 | 7048 | FILE-OFFICE | Microsoft Office Excel object record overflow attempt | off | off | off |
1 | 7197 | FILE-OFFICE | Microsoft Office Excel MSO.DLL malformed string parsing single byte buffer over attempt | off | off | off |
1 | 7202 | FILE-OFFICE | Microsoft Office Word document summary information string overflow attempt | off | off | off |
1 | 7203 | FILE-OFFICE | Microsoft Office Word information string overflow attempt | off | off | off |
1 | 7204 | FILE-OFFICE | Microsoft Office Excel object ftCmo overflow attempt | off | off | off |
1 | 7205 | FILE-OFFICE | Microsoft Office Excel FngGroupCount record overflow attempt | off | off | off |
1 | 7209 | OS-WINDOWS | DCERPC NCACN-IP-TCP srvsvc NetrPathCanonicalize overflow attempt | drop | drop | drop |
1 | 7435 | BROWSER-PLUGINS | Microsoft Internet Explorer Dynamic Casts ActiveX clsid access | off | off | off |
1 | 7864 | BROWSER-PLUGINS | McSubMgr ActiveX CLSID access | off | off | off |
1 | 7872 | BROWSER-PLUGINS | Microsoft Office Spreadsheet 10.0 ActiveX clsid access | off | off | off |
1 | 7876 | BROWSER-PLUGINS | Microsoft Office Data Source Control 10.0 ActiveX clsid access | off | off | off |
1 | 7904 | BROWSER-PLUGINS | Microsoft Internet Explorer CDL Asychronous Pluggable Protocol Handler ActiveX clsid access | off | off | off |
1 | 7985 | BROWSER-PLUGINS | Microsoft Windows Explorer WebViewFolderIcon.WebViewFolderIcon.1 ActiveX clsid access | off | off | off |
1 | 8053 | BROWSER-PLUGINS | DirectAnimation.PathControl ActiveX clsid access | off | off | off |
1 | 8055 | BROWSER-PLUGINS | DirectAnimation.PathControl ActiveX function call access | off | off | off |
1 | 8058 | BROWSER-FIREFOX | Mozilla javascript navigator object access | off | off | off |
1 | 8059 | SERVER-ORACLE | SYS.KUPW-WORKER sql injection attempt | off | off | off |
1 | 8063 | BROWSER-PLUGINS | Microsoft Internet Explorer ADODB.Stream ActiveX function call access | off | off | off |
1 | 8068 | BROWSER-PLUGINS | Microsoft Windows Scripting Host Shell ActiveX function call access | off | off | off |
1 | 8085 | SERVER-WEBAPP | HP OpenView Network Node Manager connectedNodes.ovpl command injection attempt | off | off | off |
1 | 8086 | SERVER-WEBAPP | HP OpenView Network Node Manager cdpView.ovpl command injection attempt | off | off | off |
1 | 8087 | SERVER-WEBAPP | HP OpenView Network Node Manager freeIPaddrs.ovpl command injection attempt | off | off | off |
1 | 8088 | SERVER-WEBAPP | HP OpenView Network Node Manager connectedNodes.ovpl command injection attempt | off | off | off |
1 | 8089 | SERVER-WEBAPP | HP OpenView Network Node Manager cdpView.ovpl command injection attempt | off | off | off |
1 | 8090 | SERVER-WEBAPP | HP OpenView Network Node Manager freeIPaddrs.ovpl command injection attempt | off | off | off |
1 | 8091 | FILE-MULTIMEDIA | RealNetworks RealPlayer error message format string vulnerability attempt | off | off | off |
1 | 8369 | BROWSER-PLUGINS | Microsoft Internet Explorer WMIScriptUtils.WMIObjectBroker2.1 ActiveX clsid access | off | off | off |
1 | 8414 | FILE-OFFICE | Microsoft Office GIF image descriptor memory corruption attempt | off | off | off |
1 | 8416 | OS-WINDOWS | Microsoft Windows Vector Markup Language fill method overflow attempt | off | off | off |
1 | 8419 | BROWSER-PLUGINS | Microsoft Windows Explorer WebViewFolderIcon.WebViewFolderIcon.1 ActiveX function call | off | off | off |
1 | 8426 | SERVER-OTHER | SSLv3 openssl get shared ciphers overflow attempt | off | off | off |
1 | 8428 | SERVER-OTHER | SSLv2 openssl get shared ciphers overflow attempt | off | off | off |
1 | 8441 | SERVER-WEBAPP | McAfee header buffer overflow attempt | off | off | off |
1 | 8443 | BROWSER-FIREFOX | Mozilla regular expression heap corruption attempt | off | off | off |
1 | 8446 | POLICY-OTHER | IPv6 packets encapsulated in IPv4 | off | off | off |
1 | 8448 | FILE-OFFICE | Microsoft Office Excel colinfo XF record overflow attempt | off | off | off |
1 | 8480 | PROTOCOL-FTP | PORT overflow attempt | off | off | off |
1 | 8541 | SERVER-ORACLE | sdo_cs.transform_layer buffer overflow attempt | off | off | off |
1 | 8711 | SERVER-WEBAPP | Novell eDirectory HTTP redirection buffer overflow attempt | off | off | off |
1 | 8723 | BROWSER-PLUGINS | Microsoft Office Data Source Control 11.0 ActiveX clsid access | off | off | off |
1 | 8727 | BROWSER-PLUGINS | Microsoft Internet Explorer XMLHTTP 4.0 ActiveX clsid access | off | off | off |
1 | 8738 | BROWSER-PLUGINS | Macrovision InstallShield Update Service ActiveX clsid access | off | off | off |
1 | 8741 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAFontStyle.1 ActiveX clsid access | off | off | off |
1 | 8743 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAFontStyle.1 ActiveX function call access | off | off | off |
1 | 8744 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAEvent.1 ActiveX clsid access | off | off | off |
1 | 8746 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAEvent.1 ActiveX function call access | off | off | off |
1 | 8747 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAEndStyle.1 ActiveX clsid access | off | off | off |
1 | 8749 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAEndStyle.1 ActiveX function call access | off | off | off |
1 | 8750 | BROWSER-PLUGINS | Microsoft Internet Explorer LM.LMBehaviorFactory.1 ActiveX clsid access | off | off | off |
1 | 8752 | BROWSER-PLUGINS | Microsoft Internet Explorer LM.LMBehaviorFactory.1 ActiveX function call access | off | off | off |
1 | 8753 | BROWSER-PLUGINS | Microsoft Internet Explorer LM.AutoEffectBvr.1 ActiveX clsid access | off | off | off |
1 | 8755 | BROWSER-PLUGINS | Microsoft Internet Explorer LM.AutoEffectBvr.1 ActiveX function call access | off | off | off |
1 | 8756 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.SpriteControl ActiveX clsid access | off | off | off |
1 | 8758 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.SpriteControl ActiveX function call access | off | off | off |
1 | 8759 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.SequencerControl ActiveX clsid access | off | off | off |
1 | 8761 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.SequencerControl ActiveX function call access | off | off | off |
1 | 8762 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.Sequence ActiveX clsid access | off | off | off |
1 | 8764 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.Sequence ActiveX function call access | off | off | off |
1 | 8765 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAView.1 ActiveX clsid access | off | off | off |
1 | 8767 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAView.1 ActiveX function call access | off | off | off |
1 | 8768 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAVector3.1 ActiveX clsid access | off | off | off |
1 | 8770 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAVector3.1 ActiveX function call access | off | off | off |
1 | 8771 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAVector2.1 ActiveX clsid access | off | off | off |
1 | 8773 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAVector2.1 ActiveX function call access | off | off | off |
1 | 8774 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAUserData.1 ActiveX clsid access | off | off | off |
1 | 8776 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAUserData.1 ActiveX function call access | off | off | off |
1 | 8777 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DATransform3.1 ActiveX clsid access | off | off | off |
1 | 8779 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DATransform3.1 ActiveX function call access | off | off | off |
1 | 8780 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DATransform2.1 ActiveX clsid access | off | off | off |
1 | 8782 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DATransform2.1 ActiveX function call access | off | off | off |
1 | 8783 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAString.1 ActiveX clsid access | off | off | off |
1 | 8785 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAString.1 ActiveX function call access | off | off | off |
1 | 8786 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DASound.1 ActiveX clsid access | off | off | off |
1 | 8788 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DASound.1 ActiveX function call access | off | off | off |
1 | 8789 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAPoint3.1 ActiveX clsid access | off | off | off |
1 | 8791 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAPoint3.1 ActiveX function call access | off | off | off |
1 | 8792 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAPoint2.1 ActiveX clsid access | off | off | off |
1 | 8794 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAPoint2.1 ActiveX function call access | off | off | off |
1 | 8795 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAPath2.1 ActiveX clsid access | off | off | off |
1 | 8797 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAPath2.1 ActiveX function call access | off | off | off |
1 | 8798 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAPair.1 ActiveX clsid access | off | off | off |
1 | 8800 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAPair.1 ActiveX function call access | off | off | off |
1 | 8801 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DANumber.1 ActiveX clsid access | off | off | off |
1 | 8803 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DANumber.1 ActiveX function call access | off | off | off |
1 | 8804 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAMontage.1 ActiveX clsid access | off | off | off |
1 | 8806 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAMontage.1 ActiveX function call access | off | off | off |
1 | 8807 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAMicrophone.1 ActiveX clsid access | off | off | off |
1 | 8809 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAMicrophone.1 ActiveX function call access | off | off | off |
1 | 8810 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAMatte.1 ActiveX clsid access | off | off | off |
1 | 8812 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAMatte.1 ActiveX function call access | off | off | off |
1 | 8813 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DALineStyle.1 ActiveX clsid access | off | off | off |
1 | 8815 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DALineStyle.1 ActiveX function call access | off | off | off |
1 | 8816 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAJoinStyle.1 ActiveX clsid access | off | off | off |
1 | 8818 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAJoinStyle.1 ActiveX function call access | off | off | off |
1 | 8819 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAImage.1 ActiveX clsid access | off | off | off |
1 | 8821 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAImage.1 ActiveX function call access | off | off | off |
1 | 8822 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAGeometry.1 ActiveX clsid access | off | off | off |
1 | 8824 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAGeometry.1 ActiveX function call access | off | off | off |
1 | 8825 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DADashStyle.1 ActiveX clsid access | off | off | off |
1 | 8827 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DADashStyle.1 ActiveX function call access | off | off | off |
1 | 8828 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAColor.1 ActiveX clsid access | off | off | off |
1 | 8830 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAColor.1 ActiveX function call access | off | off | off |
1 | 8831 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DACamera.1 ActiveX clsid access | off | off | off |
1 | 8833 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DACamera.1 ActiveX function call access | off | off | off |
1 | 8834 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DABoolean.1 ActiveX clsid access | off | off | off |
1 | 8836 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DABoolean.1 ActiveX function call access | off | off | off |
1 | 8837 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DABbox3.1 ActiveX clsid access | off | off | off |
1 | 8839 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DABbox3.1 ActiveX function call access | off | off | off |
1 | 8840 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DABbox2.1 ActiveX clsid access | off | off | off |
1 | 8842 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DABbox2.1 ActiveX function call access | off | off | off |
1 | 8843 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAArray.1 ActiveX clsid access | off | off | off |
1 | 8845 | BROWSER-PLUGINS | Microsoft Internet Explorer DirectAnimation.DAArray.1 ActiveX function call access | off | off | off |
1 | 9027 | OS-WINDOWS | DCERPC NCACN-IP-TCP wkssvc NetrJoinDomain2 overflow attempt | off | off | off |
1 | 9129 | BROWSER-PLUGINS | WinZip FileView 6.1 ActiveX clsid access | off | off | off |
1 | 9430 | FILE-MULTIMEDIA | Apple QuickTime Movie link file URI security bypass attempt | off | off | off |
1 | 9431 | FILE-OFFICE | Microsoft Office Outlook Express NNTP response overflow attempt | off | off | off |
1 | 9434 | FILE-OTHER | Ultravox-Max-Msg header integer overflow attempt | off | off | off |
1 | 9626 | BROWSER-PLUGINS | AcroPDF.PDF ActiveX clsid access | off | off | off |
1 | 9629 | BROWSER-PLUGINS | Citrix.ICAClient ActiveX clsid access | off | off | off |
1 | 9632 | SERVER-OTHER | Tivoli Storage Manager command request buffer overflow attempt | off | off | off |
1 | 9633 | SERVER-OTHER | Computer Associates Product Discovery Service type 9B remote buffer overflow attempt TCP | off | off | off |
1 | 9637 | FILE-OTHER | Adobe Download Manger dm.ini stack overflow attempt | off | off | off |
1 | 9638 | PROTOCOL-TFTP | PUT Microsoft RIS filename overwrite attempt | off | off | off |
1 | 9640 | BROWSER-PLUGINS | Microsoft Windows ADODB.Connection ActiveX function call access | off | off | off |
1 | 9813 | SERVER-OTHER | Symantec NetBackup connect_options buffer overflow attempt | off | off | off |
1 | 9814 | BROWSER-PLUGINS | ICQPhone.SipxPhoneManager ActiveX clsid access | off | off | off |
1 | 9816 | BROWSER-PLUGINS | ICQPhone.SipxPhoneManager ActiveX function call access | off | off | off |
1 | 9823 | FILE-MULTIMEDIA | Apple QuickTime RTSP URI overflow attempt | off | off | off |
1 | 9841 | SERVER-MAIL | Microsoft Office Outlook VEVENT overflow attempt | off | off | off |
1 | 9843 | FILE-PDF | Adobe Acrobat Plugin JavaScript parameter double free attempt | off | off | off |
1 | 9849 | OS-WINDOWS | Microsoft Windows Vector Markup Language recolorinfo tag numcolors parameter buffer overflow attempt | off | off | off |
1 | 10015 | BROWSER-PLUGINS | Oracle ORADC ActiveX clsid access | off | off | off |
1 | 10030 | NETBIOS | DCERPC NCACN-IP-TCP brightstor QSIGetQueuePath_Function_45 overflow attempt | off | off | off |
1 | 10036 | NETBIOS | DCERPC NCACN-IP-TCP brightstor ASRemotePFC overflow attempt | off | off | off |
1 | 10050 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc2 ASDBLoginToComputer overflow attempt | off | off | off |
1 | 10117 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc GetGCBHandleFromGroupName overflow attempt | off | off | off |
1 | 10126 | FILE-IMAGE | Apple QuickTime JPEG Huffman Table integer underflow attempt | off | off | off |
1 | 10187 | SERVER-OTHER | HP Mercury Loadrunner command line buffer overflow | off | off | off |
1 | 10192 | BROWSER-PLUGINS | RealNetworks RealPlayer Ierpplug.dll ActiveX clsid access | off | off | drop |
1 | 10193 | BROWSER-PLUGINS | RealNetworks RealPlayer Ierpplug.dll ActiveX function call access | off | off | drop |
1 | 10194 | BROWSER-PLUGINS | RealNetworks RealPlayer Ierpplug.dll ActiveX function call access | off | off | drop |
1 | 10393 | BROWSER-PLUGINS | Symantec SupportSoft SmartIssue ActiveX clsid access | off | off | off |
1 | 10407 | SERVER-OTHER | Helix Server LoadTestPassword buffer overflow attempt | off | off | off |
1 | 10475 | OS-WINDOWS | Microsoft Windows UPnP notification type overflow attempt | off | off | off |
1 | 10504 | INDICATOR-SHELLCODE | unescape encoded shellcode | off | off | off |
1 | 10505 | INDICATOR-SHELLCODE | unescape encoded shellcode | off | off | off |
1 | 10900 | OS-WINDOWS | DCERPC NCACN-IP-TCP dns R_DnssrvEnumRecords overflow attempt | off | off | off |
1 | 10998 | SERVER-OTHER | Novell GroupWise WebAccess authentication overflow | off | off | off |
1 | 11000 | SERVER-ORACLE | dbms_snap_internal.delete_refresh_operations buffer overflow attempt | off | off | off |
1 | 11176 | BROWSER-PLUGINS | Microsoft Office PowerPoint Viewer ActiveX clsid access | off | off | off |
1 | 11180 | FILE-MULTIMEDIA | Apple QuickTime movie ftyp buffer underflow | off | off | off |
1 | 11181 | BROWSER-PLUGINS | Microsoft Office Excel Viewer ActiveX clsid access | off | off | off |
1 | 11187 | BROWSER-PLUGINS | Microsoft Office Word Viewer ActiveX clsid access | off | off | off |
1 | 11192 | FILE-EXECUTABLE | download of executable content | off | off | off |
1 | 11199 | BROWSER-PLUGINS | Microsoft Office Viewer ActiveX clsid access | off | off | off |
1 | 11204 | SERVER-ORACLE | Oracle Database DBMS_AQADM_SYS package GRANT_TYPE_ACCESS procedure SQL injection attempt | off | off | off |
1 | 11228 | BROWSER-PLUGINS | Microsoft Input Method Editor 3 ActiveX clsid access | off | off | off |
1 | 11258 | FILE-OFFICE | Microsoft Office Excel Malformed Named Graph Information unicode overflow attempt | off | off | off |
1 | 11267 | FILE-IMAGE | Adobe Photoshop PNG file handling stack buffer overflow attempt | off | off | off |
1 | 11290 | FILE-OFFICE | Microsoft Office Excel malformed named graph information ascii overflow attempt | off | off | off |
1 | 11442 | NETBIOS | DCERPC NCACN-IP-TCP lsarpc LsarAddPrivilegesToAccount overflow attempt | off | off | off |
1 | 11670 | SERVER-OTHER | Symantec Discovery logging buffer overflow | off | off | off |
1 | 11679 | SERVER-APACHE | Apache mod_rewrite buffer overflow attempt | off | off | off |
1 | 11680 | SERVER-WEBAPP | Oracle Java web proxy sockd buffer overflow attempt | off | off | off |
1 | 11687 | SERVER-APACHE | Apache SSI error page cross-site scripting attempt | off | off | off |
1 | 11822 | BROWSER-PLUGINS | Yahoo Webcam Upload ActiveX clsid access | off | off | off |
1 | 11826 | BROWSER-PLUGINS | Microsoft Voice Control Recognition ActiveX clsid access | off | off | off |
1 | 11830 | BROWSER-PLUGINS | Microsoft Direct Speech Recognition ActiveX clsid access | off | off | off |
1 | 11835 | FILE-IDENTIFY | Visio file magic detected | off | off | off |
1 | 11838 | OS-WINDOWS | Microsoft Windows API res buffer overflow attempt | off | off | off |
1 | 11947 | OS-WINDOWS | Microsoft Windows schannel security package | off | off | off |
1 | 11966 | BROWSER-IE | Microsoft Internet Explorer CSS tag memory corruption attempt | off | off | off |
1 | 12027 | SQL | Ingres Database uuid_from_char buffer overflow attempt | off | drop | drop |
1 | 12046 | PROTOCOL-RPC | MIT Kerberos kadmind RPC Library unix authentication buffer overflow attempt | off | off | off |
1 | 12069 | OS-WINDOWS | Microsoft Windows Active Directory Crafted LDAP ModifyRequest | off | off | off |
1 | 12070 | FILE-OFFICE | Microsoft Office Excel malformed version field | off | off | off |
1 | 12075 | PROTOCOL-RPC | MIT Kerberos kadmind rpc library uninitialized pointer arbitrary code execution attempt | off | off | off |
1 | 12078 | SERVER-OTHER | CA BrightStor LGServer Heap buffer overflow | off | off | off |
1 | 12081 | SERVER-OTHER | BakBone NetVault server heap overflow attempt | off | off | off |
1 | 12099 | FILE-OFFICE | Microsoft Office Excel rtWindow1 record handling arbitrary code execution attempt | off | off | off |
1 | 12100 | NETBIOS | DCERPC NCACN-IP-TCP ca-alert function 16,23 overflow attempt | off | off | off |
1 | 12183 | FILE-FLASH | Adobe FLV long string script data buffer overflow attempt | off | off | off |
1 | 12184 | FILE-OFFICE | Microsoft Office Excel workbook workspace designation handling arbitrary code execution attempt | off | off | off |
1 | 12193 | BROWSER-PLUGINS | Yahoo Widgets Engine ActiveX clsid access | off | off | off |
1 | 12197 | SERVER-OTHER | CA message queuing server buffer overflow attempt | off | off | off |
1 | 12198 | OS-WINDOWS | Microsoft Windows getbulk request attempt | off | off | off |
1 | 12202 | SERVER-OTHER | Ingres long message heap buffer overflow attempt | off | off | off |
1 | 12203 | BROWSER-PLUGINS | VMWare Vielib.dll ActiveX clsid access | off | off | off |
1 | 12213 | SERVER-MAIL | Ipswitch IMail search date command buffer overflow attempt | off | off | off |
1 | 12216 | SERVER-OTHER | Borland interbase Create Request opcode string length buffer overflow attempt | off | off | off |
1 | 12218 | SERVER-OTHER | Borland interbase string length buffer overflow attempt | off | off | off |
1 | 12219 | FILE-MULTIMEDIA | RealNetworks RealPlayer SMIL wallclock parsing buffer overflow | off | off | off |
1 | 12222 | SERVER-OTHER | Squid proxy long WCCP packet | off | off | off |
1 | 12223 | SERVER-OTHER | Novell WebAdmin long user name | off | off | off |
1 | 12250 | BROWSER-PLUGINS | Symantec NavComUI AxSysListView32OAA ActiveX clsid access | off | off | off |
1 | 12256 | FILE-OFFICE | Microsoft Office Excel malformed FBI record buffer overflow attempt | off | off | off |
1 | 12269 | BROWSER-PLUGINS | Microsoft Visual Basic 6 TLIApplication ActiveX clsid access | off | off | off |
1 | 12279 | OS-WINDOWS | Microsoft XML substringData integer overflow attempt | off | off | off |
1 | 12280 | BROWSER-IE | Microsoft Internet Explorer VML source file memory corruption attempt | off | off | off |
1 | 12284 | FILE-OFFICE | Microsoft Office Excel rtWnDesk record memory corruption exploit attempt | off | off | off |
1 | 12286 | FILE-OTHER | PCRE character class heap buffer overflow attempt | off | off | off |
1 | 12335 | NETBIOS | DCERPC NCACN-IP-TCP trend-serverprotect Trent_req_num_30010 overflow attempt | off | off | off |
1 | 12358 | SERVER-OTHER | Helix DNA Server RTSP require tag heap overflow attempt | off | off | off |
1 | 12392 | SERVER-MAIL | GNU Mailutils request tag format string vulnerability attempt | off | off | off |
1 | 12424 | PROTOCOL-RPC | MIT Kerberos kadmind rpc RPCSEC_GSS buffer overflow attempt | off | off | off |
1 | 12448 | BROWSER-PLUGINS | Microsoft Windows Agent Control ActiveX clsid access | off | off | off |
1 | 12459 | BROWSER-PLUGINS | Microsoft Windows Visual Studio 6 PDWizard.ocx ActiveX clsid access attempt | off | off | off |
1 | 12472 | BROWSER-PLUGINS | Oracle Java Web Start ActiveX clsid access | off | off | off |
1 | 12592 | SERVER-MAIL | Recipient arbitrary command injection attempt | off | off | off |
1 | 12596 | SERVER-OTHER | CA BrightStor LGServer username buffer overflow attempt | off | off | off |
1 | 12614 | BROWSER-PLUGINS | Microsoft Windows MFC Library ActiveX function call access | off | off | off |
1 | 12618 | FILE-OTHER | Microsoft Visual Basic VBP file reference overflow attempt | off | off | off |
1 | 12629 | SERVER-WEBAPP | Microsoft Office SharePoint cross site scripting attempt | off | off | off |
1 | 12630 | INDICATOR-SHELLCODE | unescape unicode encoded shellcode | off | off | off |
1 | 12665 | SERVER-OTHER | CA BrightStor LGSever username buffer overflow attempt | off | off | off |
1 | 12666 | SERVER-OTHER | HP OpenView OVTrace buffer overflow attempt | off | off | off |
1 | 12667 | SERVER-OTHER | CA BrightStor ARCServer malicious fileupload attempt | off | off | off |
1 | 12685 | SERVER-OTHER | IBM Tivoli Storage Manger Express CAD Host buffer overflow | off | off | off |
1 | 12688 | OS-WINDOWS | Microsoft Windows ShellExecute and IE7 url handling code execution attempt | off | off | off |
1 | 12706 | SERVER-MAIL | IBM Lotus Notes MIF viewer statement data overflow | off | off | off |
1 | 12707 | FILE-MULTIMEDIA | RealNetworks RealPlayer lyrics heap overflow attempt | off | off | off |
1 | 12713 | SERVER-ORACLE | pitrig_dropmetadata buffer overflow attempt | off | off | off |
1 | 12728 | FILE-MULTIMEDIA | RealNetworks SMIL wallclock stack overflow attempt | off | off | off |
1 | 12729 | BROWSER-PLUGINS | AOL Radio AmpX ActiveX clsid access | off | off | off |
1 | 12741 | SERVER-OTHER | Apple Quicktime TCP RTSP sdp type buffer overflow attempt | off | off | off |
1 | 12743 | FILE-MULTIMEDIA | FLAC libFLAC picture description metadata buffer overflow attempt | off | off | off |
1 | 12744 | FILE-MULTIMEDIA | FLAC libFLAC VORBIS string buffer overflow attempt | off | off | off |
1 | 12745 | FILE-MULTIMEDIA | FLAC libFLAC picture metadata buffer overflow attempt | off | off | off |
1 | 12746 | FILE-MULTIMEDIA | Apple QuickTime STSD atom overflow attempt | off | off | off |
1 | 12757 | FILE-IMAGE | Apple QuickTime uncompressed PICT stack overflow attempt | off | off | off |
1 | 12766 | BROWSER-PLUGINS | RealNetworks RealPlayer RMOC3260.DLL ActiveX clsid access | off | off | drop |
1 | 12767 | BROWSER-PLUGINS | RealNetworks RealPlayer RMOC3260.DLL ActiveX function call access | off | off | drop |
1 | 12770 | BROWSER-PLUGINS | Microsoft Windows obfuscated RDS.Dataspace ActiveX exploit attempt | off | off | off |
1 | 12784 | SERVER-OTHER | CA ARCserve LGServer stack buffer overflow attempt | off | off | off |
1 | 12785 | SERVER-OTHER | CA ARCserve LGServer stack buffer overflow attempt | off | off | off |
1 | 12786 | SERVER-OTHER | CA ARCserve LGServer stack buffer overflow attempt | off | off | off |
1 | 12798 | INDICATOR-SHELLCODE | base64 x86 NOOP | off | off | off |
1 | 12799 | INDICATOR-SHELLCODE | base64 x86 NOOP | off | off | off |
1 | 12800 | INDICATOR-SHELLCODE | base64 x86 NOOP | off | off | off |
1 | 12802 | INDICATOR-SHELLCODE | base64 x86 NOOP | off | off | off |
1 | 12904 | SERVER-OTHER | Veritas NetBackup vmd shared library buffer overflow attempt | off | off | off |
1 | 12940 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc2 CA call 269 overflow attempt | off | off | off |
1 | 12971 | FILE-MULTIMEDIA | Microsoft Windows DirectX directshow wav file overflow attempt | off | off | off |
1 | 12977 | OS-WINDOWS | DCERPC NCACN-IP-TCP mqqm QMCreateObjectInternal overflow attempt | off | off | off |
1 | 12978 | OS-WINDOWS | DCERPC NCADG-IP-UDP mqqm QMCreateObjectInternal overflow attempt | off | off | off |
1 | 12983 | FILE-MULTIMEDIA | Microsoft Windows DirectX SAMI file CRawParser buffer overflow attempt | off | off | off |
1 | 13161 | SERVER-OTHER | HP OpenView CGI parameter buffer overflow attempt | off | off | off |
1 | 13210 | OS-WINDOWS | DCERPC NCACN-IP-TCP mqqm QMObjectPathToObjectFormat overflow attempt | off | off | off |
1 | 13211 | OS-WINDOWS | DCERPC NCADG-IP-UDP mqqm QMObjectPathToObjectFormat overflow attempt | off | off | off |
1 | 13219 | BROWSER-PLUGINS | HP Software Update RulesEngine.dll ActiveX clsid access | off | off | off |
1 | 13221 | SERVER-OTHER | Motorola Timbuktu crafted login request buffer overflow attempt | off | off | off |
1 | 13224 | BROWSER-PLUGINS | Yahoo Toolbar YShortcut ActiveX clsid access | off | off | off |
1 | 13249 | PROTOCOL-DNS | dns response for rfc1918 10/8 address detected | off | off | off |
1 | 13258 | BROWSER-PLUGINS | IBM Lotus Domino Web Access 6 ActiveX clsid access | off | off | off |
1 | 13260 | BROWSER-PLUGINS | IBM Lotus Domino Web Access 6 ActiveX function call access | off | off | off |
1 | 13262 | BROWSER-PLUGINS | IBM Lotus Domino Web Access 7 ActiveX clsid access | off | off | off |
1 | 13264 | BROWSER-PLUGINS | IBM Lotus Domino Web Access 7 ActiveX function call access | off | off | off |
1 | 13288 | OS-WINDOWS | Microsoft Windows remote kernel tcp/ip icmp vulnerability exploit attempt | off | off | off |
1 | 13291 | SERVER-SAMBA | Samba send_mailslot buffer overflow attempt | off | off | off |
1 | 13292 | PUA-OTHER | Skype skype4com URI handler memory corruption attempt | off | off | off |
1 | 13293 | FILE-MULTIMEDIA | Apple QuickTime panorama atoms buffer overflow attempt | off | off | off |
1 | 13294 | BROWSER-PLUGINS | Microsoft Rich TextBox ActiveX clsid access | off | off | off |
1 | 13296 | BROWSER-PLUGINS | Microsoft Rich TextBox ActiveX clsid access | off | off | off |
1 | 13300 | FILE-FLASH | Adobe Flash Player embedded JPG image height overflow attempt | off | off | off |
1 | 13302 | SERVER-APACHE | Apache mod_imagemap cross site scripting attempt | off | off | off |
1 | 13303 | BROWSER-PLUGINS | Microsoft Visual FoxPro 2 ActiveX clsid access | off | off | off |
1 | 13317 | FILE-MULTIMEDIA | 3ivx MP4 file parsing nam buffer overflow attempt | off | off | off |
1 | 13321 | BROWSER-PLUGINS | Microsoft Package and Deployment Wizard ActiveX clsid access | off | off | off |
1 | 13356 | SQL | SAP MaxDB shell command injection attempt | off | drop | drop |
1 | 13361 | FILE-OTHER | ClamAV MEW PE file integer overflow attempt | off | off | off |
1 | 13363 | SERVER-OTHER | Cisco Unified Communications Manager heap overflow attempt | off | off | off |
1 | 13364 | SERVER-MAIL | Novell GroupWise client IMG SRC buffer overflow | off | off | off |
1 | 13365 | SERVER-OTHER | Trend Micro ServerProtect TMregChange buffer overflow attempt | off | off | off |
1 | 13366 | SERVER-ORACLE | Oracle database SYS.LT.FINDRICSET SQL injection attempt | off | off | off |
1 | 13419 | BROWSER-PLUGINS | Facebook Photo Uploader ActiveX clsid access | off | off | off |
1 | 13449 | OS-WINDOWS | Microsoft Windows vbscript/jscript scripting engine end buffer overflow attempt | off | off | off |
1 | 13455 | BROWSER-IE | Microsoft Internet Explorer DXLUTBuilder ActiveX function call access | off | off | off |
1 | 13457 | BROWSER-PLUGINS | Microsoft Windows Forms 2.0 ActiveX clsid access | off | off | off |
1 | 13466 | FILE-OFFICE | Microsoft Works file converter file section length headers memory corruption attempt | off | off | off |
1 | 13470 | FILE-OFFICE | Microsoft Office Publisher memory corruption attempt | off | off | off |
1 | 13472 | FILE-OFFICE | Microsoft Works invalid chunk size | off | off | off |
1 | 13513 | SQL | generic sql insert injection attempt - GET parameter | off | off | drop |
1 | 13516 | FILE-MULTIMEDIA | Apple QuickTime HTTP error response buffer overflow | off | off | off |
1 | 13517 | FILE-MULTIMEDIA | Apple Quicktime malformed idsc atom | off | off | off |
1 | 13519 | SERVER-OTHER | Citrix MetaFrame IMA buffer overflow attempt | off | off | off |
1 | 13520 | SERVER-OTHER | Nullsoft Winamp Ultravox streaming malicious metadata | off | off | off |
1 | 13522 | SERVER-OTHER | Firebird Database Server username handling buffer overflow | off | off | off |
1 | 13523 | BROWSER-PLUGINS | Novell iPrint ActiveX clsid access | drop | drop | drop |
1 | 13525 | BROWSER-PLUGINS | Novell iPrint ActiveX function call access | drop | drop | drop |
1 | 13539 | BROWSER-PLUGINS | Symantec Backup Exec ActiveX clsid access | off | off | off |
1 | 13551 | SERVER-ORACLE | Oracle XDB.XDB_PITRIG_PKG sql injection attempt | off | off | off |
1 | 13552 | SERVER-OTHER | Symantec VERITAS Storage Foundation Suite buffer overflow attempt | off | off | off |
1 | 13553 | SERVER-OTHER | Sybase SQL Anywhere Mobilink username string buffer overflow | off | off | off |
1 | 13569 | FILE-OFFICE | Microsoft Office Excel macro validation arbitrary code execution attempt | off | off | off |
1 | 13570 | FILE-OFFICE | Microsoft Office Excel cf record arbitrary code excecution attempt | off | off | off |
1 | 13571 | FILE-OFFICE | Microsoft Office Excel dval record arbitrary code excecution attempt | off | off | off |
1 | 13572 | FILE-OFFICE | Microsoft Office PowerPoint malformed shapeid arbitrary code execution attempt | off | off | off |
1 | 13603 | BROWSER-PLUGINS | RealNetworks RealPlayer Download Handler ActiveX function call access | off | off | off |
1 | 13619 | OS-WINDOWS | Microsoft Windows getBulkRequest memory corruption attempt | off | off | off |
1 | 13621 | BROWSER-PLUGINS | CA BrightStor ListCtrl ActiveX clsid access | off | off | off |
1 | 13631 | SERVER-OTHER | McAfee ePolicy Orchestrator Framework Services log handling format string attempt | off | off | off |
1 | 13656 | SERVER-WEBAPP | Cisco Secure Access Control Server UCP Application CSuserCGI.exe buffer overflow attempt | off | off | off |
1 | 13663 | SERVER-MAIL | Alt-N MDaemon IMAP Server FETCH command buffer overflow attempt | off | off | off |
1 | 13664 | PROTOCOL-VOIP | Remote-Party-ID header hexadecimal characters in IP address field | off | off | off |
1 | 13665 | FILE-OFFICE | Microsoft Office Visio DXF file invalid memory allocation exploit attempt | off | off | off |
1 | 13672 | BROWSER-PLUGINS | Microsoft Windows Help 2.0 Contents Control 2 ActiveX clsid access | off | off | off |
1 | 13677 | BROWSER-IE | Microsoft Internet Explorer data stream memory corruption attempt | off | off | off |
1 | 13693 | PROTOCOL-VOIP | Attribute header rtpmap field invalid payload type | off | off | off |
1 | 13696 | POLICY-OTHER | TOR proxy connection initiation | off | off | off |
1 | 13714 | SERVER-MYSQL | yaSSL SSLv3 Client Hello Message Cipher Specs Buffer Overflow attempt | off | off | off |
1 | 13715 | SERVER-WEBAPP | HP OpenView Network Node Manager HTTP handling buffer overflow attempt | off | off | off |
1 | 13734 | BROWSER-PLUGINS | HP eSupportDiagnostics 10 ActiveX clsid access | off | off | off |
1 | 13800 | SERVER-OTHER | ARCServe LGServer service data overflow attempt | off | off | off |
1 | 13807 | FILE-IMAGE | Microsoft Windows metafile SetPaletteEntries heap overflow attempt | off | off | off |
1 | 13819 | SERVER-WEBAPP | IBM Lotus Domino Web Server Accept-Language header buffer overflow attempt | off | off | off |
1 | 13820 | FILE-FLASH | Adobe Flash Player SWF scene and label data memory corruption attempt | off | off | off |
1 | 13838 | BROWSER-FIREFOX | Mozilla Firefox IFRAME style change handling code execution | off | off | off |
1 | 13843 | SERVER-OTHER | MaxDB WebDBM get buffer overflow | off | off | off |
1 | 13846 | SERVER-OTHER | Veritas Backup Agent password overflow attempt | off | off | off |
1 | 13865 | FILE-IMAGE | BMP image handler buffer overflow attempt | off | off | off |
1 | 13893 | FILE-OTHER | Microsoft malformed saved search heap corruption attempt | off | off | off |
1 | 13901 | NETBIOS | SMB server response heap overflow attempt | off | off | off |
1 | 13902 | SERVER-OTHER | IBM Lotus Sametime multiplexer stack buffer overflow attempt | off | off | off |
1 | 13905 | BROWSER-PLUGINS | Microsoft Access Snapshot Viewer ActiveX function call access | off | off | off |
1 | 13913 | BROWSER-PLUGINS | AcroPDF.PDF ActiveX function call access | off | off | off |
1 | 13916 | SERVER-WEBAPP | Alt-N SecurityGateway username buffer overflow attempt | off | off | off |
1 | 13917 | FILE-MULTIMEDIA | Apple QuickTime MOV file string handling integer overflow attempt | off | off | off |
1 | 13919 | FILE-MULTIMEDIA | Apple QuickTime MOV file string handling integer overflow attempt | off | off | off |
1 | 13920 | FILE-MULTIMEDIA | Apple QuickTime Obji Atom parsing stack buffer overflow attempt | off | off | off |
1 | 13925 | PROTOCOL-FTP | Computer Associates eTrust Secure Content Manager PASV stack overflow attempt | off | off | off |
1 | 13926 | SERVER-OTHER | Novell Groupwise HTTP response message parsing overflow | off | off | off |
1 | 13927 | PROTOCOL-TFTP | Open TFTP Server log generation buffer overflow attempt | off | off | off |
1 | 13928 | SERVER-WEBAPP | Adobe RoboHelp r0 SQL injection attempt | off | off | off |
1 | 13929 | SERVER-WEBAPP | Adobe RoboHelp rx SQL injection attempt | off | off | off |
1 | 13950 | FILE-JAVA | Oracle Java Web Start JNLP attribute buffer overflow attempt | off | off | off |
1 | 13971 | FILE-OFFICE | Microsoft Office PowerPoint TxMasterStyle10Atom atom numLevels buffer overflow attempt | off | off | off |
1 | 13972 | FILE-OFFICE | Microsoft Office Excel country record arbitrary code execution attempt | off | off | off |
1 | 13980 | BROWSER-IE | Microsoft Internet Explorer http status response memory corruption vulnerability | off | off | off |
1 | 13981 | FILE-OFFICE | Microsoft Office Excel malformed chart arbitrary code execution attempt | off | off | off |
1 | 14013 | BROWSER-PLUGINS | Cisco WebEx Meeting Manager atucfobj ActiveX clsid access | off | off | off |
1 | 14015 | BROWSER-PLUGINS | Cisco WebEx Meeting Manager atucfobj ActiveX function call access | off | off | off |
1 | 14021 | BROWSER-PLUGINS | Microsoft Visual Studio Msmask32 ActiveX clsid access | off | off | off |
1 | 14025 | BROWSER-PLUGINS | Computer Associates gui_cm_ctrls ActiveX clsid access | off | off | off |
1 | 14033 | BROWSER-PLUGINS | Orbit Downloader ActiveX clsid access | off | off | off |
1 | 14035 | BROWSER-PLUGINS | Orbit Downloader ActiveX function call access | off | off | off |
1 | 14037 | BROWSER-PLUGINS | Novell iPrint ActiveX clsid access | off | drop | drop |
1 | 14038 | BROWSER-PLUGINS | Novell iPrint ActiveX function call access | off | drop | drop |
1 | 14039 | FILE-OTHER | GNOME Project libxslt RC4 key string buffer overflow attempt | off | off | off |
1 | 14255 | BROWSER-PLUGINS | Microsoft Windows Media Encoder 9 ActiveX clsid access | off | off | off |
1 | 14261 | OS-WINDOWS | Microsoft Windows GDI VML gradient size heap overflow attempt | off | off | off |
1 | 14262 | FILE-OFFICE | Microsoft Office OneNote iframe caller exploit attempt | off | off | off |
1 | 14611 | BROWSER-PLUGINS | VMWare VMCtl Class ActiveX clsid access | off | off | off |
1 | 14641 | FILE-OFFICE | Microsoft Office Excel invalid FRTWrapper record buffer overflow attempt | off | off | off |
1 | 14642 | FILE-OFFICE | Microsoft Office Excel file with embedded ActiveX control | off | off | off |
1 | 14643 | BROWSER-IE | Microsoft Internet Explorer location and location.href cross domain security bypass vulnerability | off | off | off |
1 | 14644 | BROWSER-IE | Microsoft Internet Explorer cross domain unfocusable HTML element | off | off | off |
1 | 14645 | BROWSER-IE | Microsoft Internet Explorer cross domain setExpression exploit attempt | off | off | off |
1 | 14657 | BROWSER-IE | Microsoft Internet Explorer cross domain componentFromPoint memory corruption attempt | off | off | off |
1 | 14725 | OS-WINDOWS | DCERPC NCACN-IP-TCP mqqm QMGetRemoteQueueName overflow attempt | off | off | off |
1 | 14748 | BROWSER-PLUGINS | Autodesk LiveUpdate ActiveX clsid access | off | off | off |
1 | 14756 | BROWSER-PLUGINS | Microsoft SQL Server 2000 Client Components ActiveX clsid access | off | off | off |
1 | 14760 | BROWSER-PLUGINS | iseemedia LPViewer ActiveX clsid access | off | off | off |
1 | 14764 | BROWSER-PLUGINS | Macrovision InstallShield Update Service Agent ActiveX clsid access attempt | off | off | off |
1 | 14768 | SERVER-OTHER | Symantec Veritas Storage Scheduler Service NULL Session auth bypass attempt | off | off | off |
1 | 14769 | SERVER-OTHER | DATAC RealWin SCADA System buffer overflow attempt | drop | drop | drop |
1 | 14770 | PROTOCOL-FTP | Ipswitch WS_FTP client format string attempt | off | off | off |
1 | 14771 | SERVER-APACHE | BEA WebLogic Apache Oracle connector Transfer-Encoding buffer overflow attempt | off | off | off |
1 | 14782 | OS-WINDOWS | DCERPC NCACN-IP-TCP srvsvc NetrpPathCanonicalize path canonicalization stack overflow attempt | drop | drop | drop |
1 | 14900 | NETBIOS | DCERPC NCACN-IP-TCP netdfs NetrDfsEnum overflow attempt | off | off | off |
1 | 14986 | INDICATOR-SHELLCODE | x86 fldz get eip shellcode | off | off | off |
1 | 14989 | SERVER-WEBAPP | Novell eDirectory SOAP Accept Language header overflow attempt | off | off | off |
1 | 14991 | SQL | IBM DB2 Universal Database xmlquery buffer overflow attempt | off | drop | drop |
1 | 14992 | SERVER-WEBAPP | Openwsman HTTP basic authentication buffer overflow attempt | off | off | off |
1 | 15014 | FILE-PDF | Adobe Acrobat Reader util.printf buffer overflow attempt | off | off | off |
1 | 15015 | OS-WINDOWS | DCERPC NCACN-IP-TCP wkssvc NetrUseAdd/NetrUseGetInfo/NetrUseDel overflow attempt | off | off | off |
1 | 15078 | SERVER-OTHER | HP Openview Network Node Manager OValarmsrv buffer overflow attempt | off | off | off |
1 | 15081 | FILE-JAVA | Oracle Java Web Start xml encoding buffer overflow attempt | off | off | off |
1 | 15082 | FILE-OFFICE | Microsoft Office Word rtf malformed dpcallout buffer overflow attempt | off | off | off |
1 | 15098 | BROWSER-PLUGINS | Microsoft Windows Visual Basic FlexGrid ActiveX function call access | off | off | off |
1 | 15100 | BROWSER-PLUGINS | Microsoft Windows Visual Basic Hierarchical FlexGrid ActiveX clsid access | off | off | off |
1 | 15104 | FILE-MULTIMEDIA | Microsoft Windows Visual Basic 6.0 malformed AVI buffer overflow attempt | off | off | off |
1 | 15105 | FILE-IMAGE | Microsoft GDI WMF file parsing integer overflow attempt | off | off | off |
1 | 15107 | FILE-OFFICE | Microsoft Office Word .rtf file stylesheet buffer overflow attempt | off | off | off |
1 | 15108 | SERVER-WEBAPP | Microsoft Office SharePoint Server elevation of privilege exploit attempt | off | off | off |
1 | 15114 | BROWSER-IE | Microsoft Internet Explorer embed src buffer overflow attempt | off | off | off |
1 | 15116 | OS-WINDOWS | Microsoft Windows search protocol remote command injection attempt | off | off | off |
1 | 15122 | BROWSER-PLUGINS | Microsoft Internet Explorer Shell.Explorer 2 ActiveX clsid access | off | off | off |
1 | 15126 | BROWSER-IE | Microsoft Internet Explorer nested tag memory corruption attempt | off | off | off |
1 | 15143 | SERVER-MSSQL | sp_replwritetovarbin unicode vulnerable function attempt | off | off | off |
1 | 15145 | SERVER-OTHER | Apple CUPS TrueColor PNG filter overly large image height integer overflow attempt | off | off | off |
1 | 15147 | BROWSER-IE | Microsoft Internet Explorer malformed iframe buffer overflow attempt | off | off | off |
1 | 15153 | PUA-OTHER | Jive Software Openfire Jabber Server setup Authentication bypass attempt | off | off | off |
1 | 15157 | FILE-MULTIMEDIA | VideoLAN VLC Media Player XSPF memory corruption attempt | off | off | off |
1 | 15163 | FILE-OFFICE | Microsoft Office Visio Object Header Buffer Overflow attempt | off | off | off |
1 | 15164 | BROWSER-FIREFOX | Mozilla Products SVG Layout Engine Index Parameter memory corruption attempt | off | off | off |
1 | 15166 | FILE-MULTIMEDIA | VideoLAN VLC Media Player RealText buffer overflow attempt | off | off | off |
1 | 15188 | SERVER-OTHER | Multiple vendors CUPS HPGL filter remote code execution attempt | off | off | off |
1 | 15190 | SERVER-WEBAPP | Youngzsoft CCProxy CONNECT Request buffer overflow attempt | off | off | off |
1 | 15192 | BROWSER-PLUGINS | SizerOne ActiveX clsid access | off | off | off |
1 | 15230 | BROWSER-PLUGINS | Microsoft Office Viewer 2 ActiveX clsid access | off | off | off |
1 | 15236 | FILE-IMAGE | ACD Systems ACDSee XPM file format overflow attempt | off | off | off |
1 | 15238 | FILE-MULTIMEDIA | Apple QuickTime for Java toQTPointer function memory corruption attempt | off | off | off |
1 | 15241 | FILE-MULTIMEDIA | VideoLAN VLC real.c ReadRealIndex real demuxer integer overflow attempt | off | off | off |
1 | 15243 | BROWSER-PLUGINS | AXIS Camera ActiveX clsid access | off | off | off |
1 | 15255 | SERVER-ORACLE | Secure Backup msgid 0x901 username field overflow attempt | off | off | off |
1 | 15258 | SERVER-ORACLE | Secure Backup login.php variable based command injection attempt | off | off | off |
1 | 15261 | SERVER-ORACLE | Secure Backup exec_qr command injection attempt | off | off | off |
1 | 15262 | SERVER-ORACLE | Secure Backup POST exec_qr command injection attempt | off | off | off |
1 | 15264 | SERVER-WEBAPP | Oracle TimesTen In-Memory Database evtdump CGI module format string exploit attempt | off | off | off |
1 | 15266 | BROWSER-PLUGINS | MW6 Technologies Barcode ActiveX clsid access | off | off | off |
1 | 15304 | BROWSER-IE | Microsoft Internet Explorer object clone deletion memory corruption attempt | off | off | off |
1 | 15305 | BROWSER-IE | Microsoft Internet Explorer dynamic style update memory corruption attempt | off | off | off |
1 | 15306 | FILE-EXECUTABLE | Portable Executable binary file magic detected | off | off | off |
1 | 15311 | BROWSER-PLUGINS | Research In Motion AxLoader ActiveX clsid access | off | off | off |
1 | 15357 | FILE-PDF | Adobe Acrobat Reader JBIG2 remote code execution attempt | off | off | off |
1 | 15364 | SERVER-OTHER | Ganglia Meta Daemon process_path stack buffer overflow attempt | off | off | off |
1 | 15367 | FILE-OFFICE | Microsoft Office Outlook web access script injection attempt | off | off | off |
1 | 15382 | SERVER-OTHER | X.Org X Font Server QueryXBitmaps and QueryXExtents Handlers integer overflow attempt | off | off | off |
1 | 15383 | BROWSER-FIREFOX | Mozilla Firefox XBL Event Handler Tags Removal memory corruption attempt | off | off | off |
1 | 15384 | FILE-MULTIMEDIA | Apple QuickTime pict image poly structure memory corruption attempt | off | off | off |
1 | 15386 | OS-WINDOWS | Microsoft Windows wpad dynamic update request | off | off | off |
1 | 15428 | BROWSER-FIREFOX | Mozilla Firefox SVG data processing memory corruption attempt | off | off | off |
1 | 15431 | BROWSER-FIREFOX | Mozilla Firefox 3 xsl parsing heap overflow attempt | off | off | off |
1 | 15434 | SERVER-WEBAPP | HP OpenView Network Node Manager OvOSLocale parameter buffer overflow attempt | off | off | off |
1 | 15436 | SERVER-OTHER | IBM Tivoli Storage Manager Express Backup counter heap corruption attempt | off | off | off |
1 | 15445 | SERVER-ORACLE | Application Server BPEL module cross site scripting attempt | off | off | off |
1 | 15446 | SERVER-WEBAPP | Novell eDirectory management console Accept-Language buffer overflow attempt | off | off | off |
1 | 15462 | BROWSER-OTHER | Multiple web browsers HTTP chunked transfer-encoding memory corruption attempt | off | off | off |
1 | 15466 | FILE-OFFICE | Microsoft Office WordPad WordPerfect 6.x converter buffer overflow attempt | off | off | off |
1 | 15467 | FILE-OFFICE | Microsoft Office WordPad and Office Text Converters PlcPcd aCP buffer overflow attempt | off | off | off |
1 | 15468 | BROWSER-IE | Apple Safari-Internet Explorer SearchPath blended threat dll request | off | off | off |
1 | 15472 | FILE-MULTIMEDIA | Multiple MP3 player PLS buffer overflow attempt | off | off | off |
1 | 15473 | FILE-MULTIMEDIA | Multiple media players M3U playlist file handling buffer overflow attempt | off | off | off |
1 | 15478 | FILE-FLASH | Adobe Flash Player invalid object reference code execution attempt | off | off | off |
1 | 15484 | PROTOCOL-IMAP | CRAM-MD5 authentication method buffer overflow attempt | off | off | off |
1 | 15485 | SERVER-MAIL | IBM Lotus Notes DOC attachment viewer buffer overflow | off | off | off |
1 | 15489 | PUA-OTHER | Cerulean Studios Trillian image filename handling XML tag overflow attempt | off | off | off |
1 | 15490 | OS-LINUX | Linux SCTP malformed forward-tsn chunk arbitrary code execution attempt | off | off | off |
1 | 15492 | FILE-PDF | Adobe Acrobat Reader spell.customDictionaryOpen exploit attempt | off | off | off |
1 | 15493 | FILE-PDF | Adobe Acrobat Reader getAnnots exploit attempt | off | off | off |
1 | 15499 | FILE-OFFICE | Microsoft Office PowerPoint PP7 Component buffer overflow attempt | off | off | off |
1 | 15500 | FILE-OFFICE | Microsoft Office PowerPoint LinkedSlide memory corruption | off | off | off |
1 | 15504 | FILE-OFFICE | Microsoft Office PowerPoint Download of version 4.0 file | off | off | off |
1 | 15505 | FILE-OFFICE | Microsoft Office PowerPoint HashCode10Atom memory corruption attempt | off | off | off |
1 | 15506 | FILE-OFFICE | Microsoft Office PowerPoint CurrentUserAtom remote code execution attempt | off | off | off |
1 | 15510 | SERVER-OTHER | Trend Micro OfficeScan Server cgiRecvFile overflow attempt | off | off | off |
1 | 15511 | SERVER-APACHE | Oracle WebLogic Apache Connector buffer overflow attempt | off | off | off |
1 | 15514 | SERVER-OTHER | Multiple Vendors NTP Daemon Autokey stack buffer overflow attempt | off | off | off |
1 | 15515 | SERVER-ORACLE | Oracle Database Server RollbackWorkspace SQL injection attempt | off | off | off |
1 | 15517 | FILE-MULTIMEDIA | Microsoft Windows AVI DirectShow QuickTime parsing overflow attempt | off | off | off |
1 | 15527 | OS-WINDOWS | Microsoft Windows Active Directory LDAP denial of service attempt | off | off | off |
1 | 15539 | FILE-OFFICE | Microsoft Office Excel Formula record remote code execution attempt | off | off | off |
1 | 15540 | BROWSER-IE | Microsoft Internet Explorer DOM memory corruption attempt | off | off | off |
1 | 15541 | FILE-OFFICE | Microsoft Office Excel SST record remote code execution attempt | off | off | off |
1 | 15542 | FILE-OFFICE | Microsoft Office Excel Qsir and Qsif record remote code execution attempt | off | off | off |
1 | 15555 | SERVER-OTHER | Symantec Alert Management System Intel Alert Originator Service buffer overflow attempt | off | off | off |
1 | 15559 | FILE-MULTIMEDIA | Apple QuickTime movie file clipping region handling heap buffer overflow attempt | off | off | off |
1 | 15571 | SERVER-OTHER | RealNetworks Helix Server RTSP SETUP stack buffer overflow attempt | off | off | off |
1 | 15573 | SERVER-OTHER | RealNetworks Helix Server RTSP SET_PARAMETER heap buffer overflow attempt | off | off | off |
1 | 15638 | BROWSER-PLUGINS | Microsoft Video 32 ActiveX clsid access | off | off | off |
1 | 15670 | BROWSER-PLUGINS | Microsoft Video 6 ActiveX clsid access | off | off | off |
1 | 15672 | BROWSER-PLUGINS | Microsoft Video 7 ActiveX clsid access | off | off | off |
1 | 15681 | FILE-OFFICE | Microsoft Office Publisher 2007 file format arbitrary code execution attempt | off | off | off |
1 | 15682 | FILE-MULTIMEDIA | Microsoft Windows DirectShow QuickTime file stsc atom parsing heap corruption attempt | off | off | off |
1 | 15685 | BROWSER-PLUGINS | Microsoft Office Web Components 10 Spreadsheet ActiveX clsid access | off | off | off |
1 | 15693 | FILE-OTHER | Microsoft Windows Embedded Open Type Font malformed name table overflow attempt | off | off | off |
1 | 15694 | FILE-OTHER | Microsoft Windows Embedded Open Type Font malformed name table integer overflow attempt | off | off | off |
1 | 15698 | INDICATOR-SHELLCODE | Possible generic javascript heap spray attempt | off | off | off |
1 | 15707 | FILE-MULTIMEDIA | Apple iTunes ITPC protocol handler stack buffer overflow attempt | off | off | off |
1 | 15708 | SERVER-OTHER | Unisys Business Information Server stack buffer overflow attempt | off | off | off |
1 | 15709 | FILE-PDF | Adobe Acrobat Reader FlateDecode integer overflow attempt | off | off | off |
1 | 15711 | PUA-OTHER | mIRC PRIVMSG message processing overflow attempt | off | off | off |
1 | 15722 | SERVER-ORACLE | Oracle database server Workspace Manager multiple SQL injection attempt | off | off | off |
1 | 15723 | SERVER-ORACLE | Oracle database server CompressWorkspaceTree SQL injection attempt | off | off | off |
1 | 15724 | SERVER-ORACLE | Oracle database server MergeWorkspace SQL injection attempt | off | off | off |
1 | 15725 | SERVER-ORACLE | Oracle database server RemoveWorkspace SQL injection attempt | off | off | off |
1 | 15727 | FILE-PDF | attempted download of a PDF with embedded Flash | off | off | drop |
1 | 15731 | BROWSER-IE | Microsoft Internet Explorer javascript deleted reference arbitrary code execution attempt | off | off | off |
1 | 15732 | BROWSER-IE | Microsoft Internet Explorer CSS handling memory corruption attempt | off | off | off |
1 | 15733 | BROWSER-IE | Microsoft Internet Explorer empty table tag memory corruption attempt | off | off | off |
1 | 15850 | OS-WINDOWS | Remote Desktop orderType remote code execution attempt | off | off | off |
1 | 15854 | FILE-MULTIMEDIA | Microsoft Windows AVIFile media file processing memory corruption attempt | off | off | off |
1 | 15858 | BROWSER-PLUGINS | Microsoft Office Web Components Spreadsheet ActiveX clsid access | off | off | off |
1 | 15861 | BROWSER-PLUGINS | Microsoft Windows Remote Desktop Client ActiveX clsid access | off | off | off |
1 | 15863 | BROWSER-PLUGINS | Microsoft Windows Remote Desktop Client ActiveX function call access | off | off | off |
1 | 15866 | FILE-OTHER | libxml2 file processing long entity overflow attempt | off | off | off |
1 | 15867 | FILE-PDF | Adobe Acrobat Reader PDF font processing memory corruption attempt | off | off | off |
1 | 15868 | SQL | Borland InterBase username buffer overflow | off | off | drop |
1 | 15869 | FILE-FLASH | Adobe Flash Player ASnative command execution attempt | off | off | off |
1 | 15871 | FILE-MULTIMEDIA | FFmpeg 4xm processing memory corruption attempt | off | off | off |
1 | 15872 | BROWSER-FIREFOX | Mozilla Firefox defineSetter function pointer memory corruption attempt | off | off | off |
1 | 15901 | FILE-MULTIMEDIA | Nullsoft Winamp AIFF parsing heap buffer overflow attempt | off | off | off |
1 | 15902 | INDICATOR-SHELLCODE | x86 win2k-2k3 decoder base shellcode | off | off | off |
1 | 15908 | SERVER-WEBAPP | Trend Micro OfficeScan multiple CGI modules HTTP form processing buffer overflow attempt | off | off | off |
1 | 15909 | FILE-MULTIMEDIA | Apple QuickTime VR Track Header Atom heap corruption attempt | off | off | off |
1 | 15910 | BROWSER-IE | Microsoft Internet Explorer getElementById object corruption attempt | off | off | off |
1 | 15930 | OS-WINDOWS | Microsoft Windows SMB malformed process ID high field remote code execution attempt | off | off | off |
1 | 15934 | PROTOCOL-DNS | dns response for rfc1918 172.16/12 address detected | off | off | off |
1 | 15940 | FILE-MULTIMEDIA | RealNetworks RealPlayer Multiple Products RA file processing overflow attempt | off | off | off |
1 | 15941 | SERVER-OTHER | Squid Proxy TRACE request remote DoS attempt | off | off | off |
1 | 15942 | SERVER-OTHER | CA Multiple Products Console Server login credentials handling overflow attempt | off | off | off |
1 | 15946 | FILE-OTHER | Microsoft Windows Vista Feed Headlines Gagdet code execution attempt | off | off | off |
1 | 15947 | FILE-OFFICE | Microsoft Office Outlook Web Access Cross-Site Scripting attempt | off | off | off |
1 | 15948 | SERVER-OTHER | CA License Software invalid command overflow attempt | off | off | off |
1 | 15950 | SERVER-OTHER | McAfee LHA Type-2 file handling overflow attempt | off | off | off |
1 | 15951 | SERVER-MYSQL | MaxDB Webtool GET command overflow attempt | off | off | off |
1 | 15955 | SERVER-ORACLE | Application Server 9i Webcache file corruption attempt | off | off | off |
1 | 15956 | SERVER-ORACLE | http Server mod_access restriction bypass attempt | off | off | off |
1 | 15958 | SERVER-OTHER | Novell ZENworks Remote Management overflow attempt | off | off | off |
1 | 15962 | SERVER-WEBAPP | Sybase EAServer WebConsole overflow attempt | off | off | off |
1 | 15990 | SERVER-WEBAPP | Multiple Vendor server file disclosure attempt | off | off | off |
1 | 15993 | FILE-FLASH | Adobe Flash Player ActionScript intrf_count integer overflow attempt | off | off | off |
1 | 15995 | FILE-MULTIMEDIA | Microsoft Windows DirectX malformed avi file mjpeg compression arbitrary code execution attempt | off | off | off |
1 | 15997 | BROWSER-FIREFOX | Mozilla Firefox JIT escape function memory corruption attempt | off | off | off |
1 | 15998 | SERVER-OTHER | HP OpenView Client Configuration Manager Radia Notify Daemon code execution attempt | off | off | off |
1 | 15999 | BROWSER-FIREFOX | Mozilla products frame comment objects manipulation memory corruption attempt | off | off | off |
1 | 16000 | FILE-IMAGE | Sun Microsystems Java gif handling memory corruption attempt | off | off | off |
1 | 16001 | FILE-IMAGE | Apple QuickDraw PICT images ARGB records handling memory corruption attempt | off | off | off |
1 | 16004 | FILE-OTHER | Apple Mac OS X installer package filename format string vulnerability | off | off | off |
1 | 16005 | BROWSER-FIREFOX | Mozilla browsers JavaScript argument passing code execution attempt | off | off | off |
1 | 16006 | FILE-MULTIMEDIA | Apple QuickTime color table id memory corruption attempt | off | off | off |
1 | 16007 | BROWSER-IE | Microsoft Internet Explorer colgroup tag uninitialized memory exploit attempt | off | off | off |
1 | 16009 | BROWSER-FIREFOX | Mozilla products overflow event handling memory corruption attempt | off | off | off |
1 | 16011 | BROWSER-IE | Microsoft Internet Explorer CSS property method handling memory corruption attempt | off | off | off |
1 | 16013 | SERVER-OTHER | IBM solidDB logging function format string exploit attempt | off | off | off |
1 | 16016 | OS-WINDOWS | Microsoft client for netware overflow attempt | off | off | off |
1 | 16017 | SERVER-OTHER | IBM Lotus Domino LDAP server invalid DN message buffer overflow attempt | off | off | off |
1 | 16018 | SERVER-OTHER | HP OpenView network node manager buffer overflow | off | off | off |
1 | 16019 | SERVER-OTHER | Novell Distributed Print Services integer overflow attempt | off | off | off |
1 | 16021 | SERVER-APACHE | Apache http Server mod_tcl format string attempt | off | off | off |
1 | 16022 | FILE-EXECUTABLE | Microsoft Windows Vista Windows mail file execution attempt | off | off | off |
1 | 16027 | FILE-MULTIMEDIA | Nullsoft Winamp midi file header overflow attempt | off | off | off |
1 | 16029 | OS-WINDOWS | Microsoft Windows DNS client ATMA buffer overrun attempt | off | off | off |
1 | 16030 | OS-WINDOWS | Microsoft Windows DNS client TXT buffer overrun attempt | off | off | off |
1 | 16031 | BROWSER-IE | Microsoft Internet Explorer nested object tag memory corruption attempt | off | off | off |
1 | 16032 | BROWSER-IE | Microsoft Internet Explorer HTML Decoding memory corruption attempt | off | off | off |
1 | 16033 | BROWSER-IE | Microsoft Internet Explorer compressed content attempt | off | off | off |
1 | 16035 | BROWSER-IE | Microsoft Internet Explorer createTextRange code execution attempt | off | off | off |
1 | 16036 | BROWSER-FIREFOX | Mozilla Products QueryInterface method memory corruption attempt | off | off | off |
1 | 16037 | BROWSER-FIREFOX | Mozilla products graphics and XML features integer overflows attempt | off | off | off |
1 | 16041 | FILE-MULTIMEDIA | Apple QuickTime FLIC animation file buffer overflow attempt | off | off | off |
1 | 16042 | BROWSER-FIREFOX | Mozilla browsers CSS moz-binding cross domain scripting attempt | off | off | off |
1 | 16045 | BROWSER-IE | Microsoft Internet Explorer cross domain information disclosure attempt | off | off | off |
1 | 16046 | FILE-MULTIMEDIA | RealNetworks RealPlayer RealMedia file format processing heap corruption attempt | off | off | off |
1 | 16047 | BROWSER-FIREFOX | Mozilla Firefox layout frame constructor memory corruption attempt | off | off | off |
1 | 16049 | SERVER-OTHER | GNU Radius SQL accounting format string exploit attempt | off | off | off |
1 | 16054 | FILE-IMAGE | Apple QuickTime bitmap multiple header overflow | off | off | off |
1 | 16055 | FILE-MULTIMEDIA | Apple iTunes AAC file handling integer overflow attempt | off | off | off |
1 | 16058 | SERVER-SAMBA | Samba WINS Server Name Registration handling stack buffer overflow attempt | off | off | off |
1 | 16059 | FILE-OFFICE | Microsoft Office Excel malformed file format parsing code execution attempt | off | off | off |
1 | 16063 | BROWSER-IE | Microsoft Internet Explorer isindex buffer overflow attempt | off | off | off |
1 | 16065 | BROWSER-IE | Microsoft Internet Explorer location.replace memory corruption attempt | off | off | off |
1 | 16067 | BROWSER-IE | Microsoft Internet Explorer DOM object cache management memory corruption attempt | off | off | off |
1 | 16069 | SERVER-OTHER | IBM Informix server argument processing overflow attempt | off | off | off |
1 | 16070 | FILE-OTHER | X.org PCF parsing buffer overflow attempt | off | off | off |
1 | 16072 | SERVER-OTHER | CUPS server query metacharacter buffer overflow attempt | off | off | off |
1 | 16075 | SQL | Suspicious SQL ansi_padding option | off | off | drop |
1 | 16079 | SERVER-WEBAPP | uselang code injection | off | off | off |
1 | 16089 | OS-WINDOWS | Microsoft Windows embedded web font handling buffer overflow attempt | off | off | off |
1 | 16090 | BROWSER-PLUGINS | Microsoft Core XML core services XMLHTTP control open method code execution attempt | off | off | off |
1 | 16142 | BROWSER-FIREFOX | Mozilla Firefox PKCS11 module installation code execution attempt | off | off | off |
1 | 16145 | BROWSER-WEBKIT | Apple Safari Webkit floating point buffer overflow attempt | off | off | off |
1 | 16148 | FILE-MULTIMEDIA | Apple QuickTime and iTunes heap memory corruption attempt | off | off | off |
1 | 16169 | BROWSER-IE | Microsoft Internet Explorer dynamic style update memory corruption attempt | off | off | off |
1 | 16187 | OS-WINDOWS | Microsoft Windows DirectShow MJPEG arbitrary code execution attempt | off | off | off |
1 | 16188 | FILE-OFFICE | Microsoft Office PowerPoint bad text header txttype attempt | off | drop | drop |
1 | 16189 | SERVER-ORACLE | Database REPCAT_RPC.VALIDATE_REMOTE_RC SQL injection attempt | off | off | off |
1 | 16190 | SERVER-ORACLE | Oracle Secure Backup Administration server property_box.php command injection attempt | off | off | off |
1 | 16192 | SERVER-ORACLE | Secure Backup Administration server authentication bypass attempt | off | off | off |
1 | 16195 | SERVER-WEBAPP | HTTP request content-length heap buffer overflow attempt | off | off | off |
1 | 16200 | BROWSER-FIREFOX | Mozilla Firefox command line URL shell command injection attempt | off | off | off |
1 | 16201 | SERVER-MAIL | Ipswitch Collaboration Suite SMTP format string exploit attempt | off | off | off |
1 | 16204 | SERVER-OTHER | HP OpenView Network Node Manager ovlaunch host field overflow attempt | off | off | off |
1 | 16207 | SERVER-WEBAPP | MIT Kerberos V% KAdminD klog_vsyslog server overflow attempt | off | off | off |
1 | 16208 | SERVER-MSSQL | Microsoft SQL Server Distributed Management Objects overflow attempt | off | off | off |
1 | 16213 | SERVER-OTHER | Red Hat Directory Server Accept-Language HTTP header parsing buffer overflow attempt | off | off | off |
1 | 16215 | SERVER-ORACLE | Oracle Application Server Portal cross site scripting attempt | off | off | off |
1 | 16216 | SERVER-OTHER | IBM Tivoli Provisioning Manager long URI request buffer overflow attempt | off | off | off |
1 | 16217 | SERVER-OTHER | OpenView Network Node Manager ovalarmsrv opcode 45 integer overflow attempt | off | off | off |
1 | 16231 | FILE-PDF | Microsoft Windows kernel-mode drivers core font parsing integer overflow attempt | off | off | off |
1 | 16283 | SERVER-WEBAPP | Borland StarTeam Multicast Service buffer overflow attempt | off | off | off |
1 | 16284 | BROWSER-FIREFOX | Mozilla Firefox ClearTextRun exploit attempt | off | off | off |
1 | 16288 | FILE-JAVA | Oracle Java Runtime AWT setDiffICM stack buffer overflow attempt | off | off | off |
1 | 16291 | BROWSER-FIREFOX | Mozilla Network Security Services regexp heap overflow attempt | off | off | off |
1 | 16292 | BROWSER-FIREFOX | Mozilla CSS value counter overflow attempt | off | off | off |
1 | 16295 | FILE-OTHER | Kaspersky antivirus library heap buffer overflow - without optional fields | off | off | off |
1 | 16300 | BROWSER-IE | Microsoft Internet Explorer HTML DOM invalid DHTML comment creation attempt | off | off | off |
1 | 16301 | BROWSER-IE | Microsoft Internet Explorer HTML DOM invalid DHTML textnode creation attempt | off | off | off |
1 | 16310 | BROWSER-IE | Microsoft Internet Explorer 6/7 outerHTML invalid reference arbitrary code execution attempt | off | off | off |
1 | 16311 | BROWSER-IE | Microsoft Internet Explorer 6/7 single line outerHTML invalid reference arbitrary code execution attempt | off | off | off |
1 | 16318 | FILE-OFFICE | Microsoft Office Visio invalid ho tag attempt | off | off | off |
1 | 16319 | BROWSER-IE | Apple Safari-Internet Explorer SearchPath blended threat attempt | off | off | off |
1 | 16331 | FILE-FLASH | Adobe Flash Player JPEG parsing heap overflow attempt | off | off | off |
1 | 16332 | SERVER-OTHER | Symantec System Center Alert Management System untrusted command execution attempt | off | off | off |
1 | 16333 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 16334 | FILE-PDF | Adobe Acrobat Reader compressed media.newPlayer memory corruption attempt | off | off | off |
1 | 16339 | BROWSER-IE | Microsoft Internet Explorer object clone deletion memory corruption attempt - obfuscated | off | off | off |
1 | 16342 | FILE-MULTIMEDIA | Microsoft Windows AVIFile truncated media file processing memory corruption attempt | off | off | off |
1 | 16344 | BROWSER-FIREFOX | Mozilla Firefox top-level script object offset calculation memory corruption attempt | off | off | off |
1 | 16353 | FILE-MULTIMEDIA | FFmpeg OGV file format memory corruption attempt | off | off | drop |
1 | 16359 | FILE-OTHER | Adobe Illustrator DSC comment overflow attempt | off | off | off |
1 | 16360 | FILE-MULTIMEDIA | Apple QuickTime Image Description Atom sign extension memory corruption attempt | off | off | off |
1 | 16367 | BROWSER-IE | Microsoft Internet Explorer invalid object access memory corruption attempt | off | off | drop |
1 | 16369 | BROWSER-IE | Microsoft Internet Explorer deleted object access memory corruption attempt - public exploit | off | off | drop |
1 | 16371 | BROWSER-PLUGINS | NOS Microsystems Adobe atl_getcom ActiveX clsid access | off | off | drop |
1 | 16376 | BROWSER-IE | Microsoft Internet Explorer CTableLayout memory corruption attempt | off | off | off |
1 | 16378 | BROWSER-IE | Microsoft Internet Explorer deleted object cells reference memory corruption vulnerability | off | off | drop |
1 | 16382 | BROWSER-IE | Microsoft Internet Explorer HTML+TIME animatemotion property memory corruption attempt | off | off | off |
1 | 16383 | SERVER-ORACLE | MDSYS drop table trigger injection attempt | off | off | off |
1 | 16392 | SERVER-WEBAPP | Oracle Java System Web Server 7.0u7 authorization digest heap overflow | off | off | off |
1 | 16393 | SERVER-OTHER | PostgreSQL bit substring buffer overflow attempt | off | off | off |
1 | 16409 | FILE-OFFICE | Microsoft Office PowerPoint improper filename remote code execution attempt | off | off | alert |
1 | 16411 | FILE-OFFICE | Microsoft Office PowerPoint out of bounds value remote code execution attempt | off | off | drop |
1 | 16412 | FILE-OFFICE | Microsoft Office PowerPoint invalid TextByteAtom remote code execution attempt | off | off | drop |
1 | 16414 | OS-WINDOWS | Microsoft Windows Shell Handler remote code execution attempt | off | off | drop |
1 | 16416 | FILE-OFFICE | Microsoft Office Excel Malformed MSODrawing Record attempt | off | off | drop |
1 | 16417 | OS-WINDOWS | SMB Negotiate Protocol Response overflow attempt | off | off | drop |
1 | 16419 | BROWSER-PLUGINS | Microsoft Windows Data Analyzer 3.5 ActiveX clsid access | off | off | drop |
1 | 16421 | FILE-OFFICE | Microsoft Office PowerPoint out of bounds value remote code execution attempt | off | off | drop |
1 | 16422 | FILE-IMAGE | Microsoft Windows Paint JPEG with malformed SOFx field | off | off | drop |
1 | 16423 | BROWSER-IE | Microsoft Internet Explorer 7/8 execute local file in Internet zone redirect attempt | off | off | drop |
1 | 16424 | BROWSER-PLUGINS | Microsoft Windows Script Host Shell Object ActiveX clsid access | off | off | off |
1 | 16428 | FILE-OFFICE | Microsoft Office Outlook Express and Windows Mail NNTP handling buffer overflow attempt | off | off | off |
1 | 16438 | SERVER-ORACLE | WebLogic Server Node Manager arbitrary command execution attempt | off | off | drop |
1 | 16444 | SERVER-OTHER | HP StorageWorks storage mirroring double take service code execution attempt | off | off | off |
1 | 16452 | BROWSER-IE | Microsoft Internet Explorer .hlp samba share download attempt | off | off | off |
1 | 16461 | FILE-OFFICE | Microsoft Office Excel EntExU2 write access violation attempt | off | off | drop |
1 | 16462 | FILE-OFFICE | Microsoft Office Excel BIFF8 formulas from records parsing code execution attempt | off | off | drop |
1 | 16463 | FILE-OFFICE | Microsoft Office Excel BIFF5 formulas from records parsing code execution attempt | off | off | drop |
1 | 16464 | FILE-OFFICE | Microsoft Office Excel ContinueFRT12 heap overflow attempt | off | off | drop |
1 | 16465 | FILE-OFFICE | Microsoft Office Excel ContinueFRT12 and MDXSet heap overflow attempt | off | off | drop |
1 | 16466 | FILE-OFFICE | Microsoft Office Excel uninitialized stack variable code execution attempt | off | off | drop |
1 | 16467 | FILE-OFFICE | Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt 1 | off | off | drop |
1 | 16468 | FILE-OFFICE | Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt 2 | off | off | drop |
1 | 16469 | FILE-OFFICE | Microsoft Office Excel DbOrParamQry.fOdbcConn parsing remote code execution attempt | off | off | drop |
1 | 16470 | FILE-OFFICE | Microsoft Office Excel DbOrParamQry.fWeb parsing remote code execution attempt | off | off | drop |
1 | 16471 | FILE-OFFICE | Microsoft Office Excel DbOrParamQry.fWeb parsing remote code execution attempt | off | off | drop |
1 | 16481 | BROWSER-OTHER | Opera Content-Length header integer overflow attempt | off | off | off |
1 | 16482 | BROWSER-IE | Microsoft Internet Explorer userdata behavior memory corruption attempt | off | off | drop |
1 | 16490 | FILE-PDF | Adobe Acrobat Reader malformed TIFF remote code execution attempt | off | off | drop |
1 | 16492 | BROWSER-WEBKIT | Apple Safari inline text box use after free attempt | off | off | drop |
1 | 16501 | BROWSER-FIREFOX | Mozilla Firefox WOFF font processing integer overflow attempt - TrueType | off | off | drop |
1 | 16502 | BROWSER-FIREFOX | Mozilla Firefox WOFF font processing integer overflow attempt - CFF-based | off | off | drop |
1 | 16503 | BROWSER-IE | Microsoft Internet Explorer event handling remote code execution attempt | off | off | drop |
1 | 16506 | BROWSER-IE | Microsoft Internet Explorer innerHTML against incomplete element heap corruption attempt | off | off | drop |
1 | 16507 | BROWSER-IE | Microsoft Internet Explorer onreadystatechange memory corruption attempt | off | off | drop |
1 | 16508 | BROWSER-IE | Microsoft Internet Explorer 8 non-IE8 compatibility mode htmltime remote code execution attempt | off | off | drop |
1 | 16510 | BROWSER-PLUGINS | Microsoft Internet Explorer Tabular Control ActiveX overflow by CLSID | off | off | drop |
1 | 16511 | BROWSER-PLUGINS | Microsoft Internet Explorer Tabular Control ActiveX overflow by ProgID | off | off | drop |
1 | 16512 | BROWSER-IE | Microsoft Internet Explorer malformed span/div html document heap corruption attempt | off | off | drop |
1 | 16514 | PUA-OTHER | Trillian AIM XML tag handling heap buffer overflow attempt | off | off | off |
1 | 16515 | SERVER-MAIL | Novell Groupwise Internet Agent RCPT command overflow attempt | off | off | off |
1 | 16516 | SERVER-ORACLE | Database sys.olapimpl_t package odcitablestart overflow attempt | off | off | off |
1 | 16517 | FILE-OTHER | Free Download Manager .torrent parsing comment overflow attempt | off | off | off |
1 | 16518 | FILE-OTHER | Free Download Manager .torrent parsing announce overflow attempt | off | off | off |
1 | 16519 | FILE-OTHER | Free Download Manager .torrent parsing name overflow attempt | off | off | off |
1 | 16520 | FILE-OTHER | Free Download Manager .torrent parsing path overflow attempt | off | off | off |
1 | 16522 | SERVER-OTHER | Novell QuickFinder server cross-site-scripting attempt | off | off | off |
1 | 16524 | PROTOCOL-FTP | ProFTPD username sql injection attempt | off | off | off |
1 | 16537 | BROWSER-PLUGINS | Microsoft Windows Media Player ActiveX unknow compression algorithm use arbitrary code execution attempt | off | off | drop |
1 | 16540 | OS-WINDOWS | SMB2 client NetBufferList NULL entry remote code execution attempt | off | off | drop |
1 | 16541 | OS-WINDOWS | Microsoft Windows Media Service stack overflow attempt | off | off | drop |
1 | 16542 | FILE-OFFICE | Microsoft Office Publisher 2007 and earlier stack buffer overflow attempt | off | off | drop |
1 | 16543 | FILE-MULTIMEDIA | Microsoft Windows Media Player codec code execution attempt | off | off | drop |
1 | 16545 | FILE-PDF | Adobe Acrobat Reader malformed Richmedia annotation exploit attempt | off | off | drop |
1 | 16549 | FILE-OTHER | Oracle JRE Java Platform SE and Java Deployment Toolkit plugins code execution attempt - npruntime-scriptable-plugin | off | off | drop |
1 | 16554 | FILE-PDF | Adobe Acrobat Reader javascript getIcon method buffer overflow attempt | off | off | off |
1 | 16555 | SERVER-WEBAPP | HP Openview Network Node Manager OvAcceptLang overflow attempt | off | off | off |
1 | 16560 | SERVER-WEBAPP | Microsoft Office SharePoint XSS attempt | off | off | off |
1 | 16574 | BROWSER-PLUGINS | obfuscated ActiveX object instantiation via fromCharCode | off | off | off |
1 | 16576 | SERVER-OTHER | RealNetworks Helix AgentX receive_agentx stack buffer overflow attempt | off | off | drop |
1 | 16589 | BROWSER-PLUGINS | iseemedia LPViewer ActiveX function call access | off | off | off |
1 | 16593 | FILE-OFFICE | Microsoft VBE6.dll stack corruption attempt | off | off | drop |
1 | 16595 | SERVER-MAIL | Microsoft Windows Mail remote code execution attempt | off | off | drop |
1 | 16596 | BROWSER-WEBKIT | Apple Safari information disclosure and remote code execution attempt | off | off | off |
1 | 16597 | SERVER-MAIL | Novell GroupWise Internet Agent Email address processing buffer overflow attempt | off | off | off |
1 | 16603 | FILE-PDF | Adobe Acrobat Reader Linux malformed U3D mesh deceleration block exploit attempt | off | off | drop |
1 | 16605 | BROWSER-IE | Microsoft Internet Explorer nested SPAN tag memory corruption attempt | off | off | off |
1 | 16606 | SERVER-ORACLE | BEA WebLogic Server Plug-ins Certificate overflow attempt | off | off | off |
1 | 16631 | BROWSER-WEBKIT | Apple Safari image use after remove attempt | off | off | drop |
1 | 16632 | BROWSER-WEBKIT | Apple Safari image use after reparent attempt | off | off | drop |
1 | 16633 | FILE-PDF | Adobe Acrobat Reader File containing Flash use-after-free attack attempt | off | off | drop |
1 | 16634 | FILE-FLASH | Adobe Flash use-after-free attack attempt | off | off | drop |
1 | 16635 | BROWSER-PLUGINS | Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access | off | off | drop |
1 | 16637 | BROWSER-IE | Microsoft Internet Explorer security zone restriction bypass attempt | off | off | off |
1 | 16638 | FILE-OFFICE | Microsoft Office Excel OBJ record stack buffer overflow attempt | off | off | drop |
1 | 16639 | FILE-OFFICE | Microsoft Office Excel OBJ record stack buffer overflow attempt - with macro | off | off | drop |
1 | 16640 | FILE-OFFICE | Microsoft Office Excel OBJ record stack buffer overflow attempt - with linkFmla | off | off | drop |
1 | 16641 | FILE-OFFICE | Microsoft Office Excel OBJ record stack buffer overflow attempt - with macro and linkFmla | off | off | drop |
1 | 16642 | POLICY-OTHER | file URI scheme attempt | off | off | off |
1 | 16643 | FILE-OFFICE | Microsoft Office Excel Chart Sheet Substream memory corruption attempt | off | off | drop |
1 | 16644 | FILE-OFFICE | Microsoft Office Excel WOpt record memory corruption attempt | off | off | drop |
1 | 16645 | FILE-OFFICE | Microsoft Office Excel SxView record memory pointer corruption attempt | off | off | drop |
1 | 16646 | FILE-OFFICE | Microsoft Office Excel RealTimeData record stack buffer overflow attempt | off | off | drop |
1 | 16647 | FILE-OFFICE | Microsoft Office Excel RealTimeData record heap memory corruption attempt - 2 | off | off | drop |
1 | 16648 | FILE-OFFICE | Microsoft Office Excel RealTimeData record heap memory corruption attempt - 1 | off | off | drop |
1 | 16650 | FILE-OFFICE | Microsoft Office Excel ExternName record stack buffer overflow attempt - 1 | off | off | drop |
1 | 16651 | FILE-OFFICE | Microsoft Office Excel ExternName record stack buffer overflow attempt - 2 | off | off | drop |
1 | 16652 | FILE-OFFICE | Microsoft Office Excel ExternName record stack buffer overflow attempt - 3 | off | off | drop |
1 | 16653 | FILE-OFFICE | Microsoft Office Excel ExternName record stack buffer overflow attempt - 4 | off | off | drop |
1 | 16654 | FILE-OFFICE | Microsoft Office Excel Publisher record heap buffer overflow attempt | off | drop | drop |
1 | 16656 | FILE-OFFICE | Microsoft Office Excel BIFF5 ExternSheet record stack overflow attempt | off | off | drop |
1 | 16657 | FILE-OFFICE | Microsoft Office Excel DBQueryExt record memory corruption attempt | off | off | drop |
1 | 16659 | BROWSER-IE | Microsoft Internet Explorer style sheet array memory corruption attempt | off | drop | drop |
1 | 16661 | FILE-MULTIMEDIA | Microsoft Windows DirectX quartz.dll MJPEG content processing memory corruption attempt | off | off | drop |
1 | 16664 | FILE-PDF | Adobe Acrobat Reader authplay.dll vulnerability exploit attempt | off | off | drop |
1 | 16665 | OS-WINDOWS | Microsoft Windows Help Centre escape sequence XSS attempt | off | off | drop |
1 | 16666 | BROWSER-WEBKIT | Apple Safari window.parent.close unspecified remote code execution vulnerability | off | off | off |
1 | 16667 | BROWSER-CHROME | Google Chrome GURL cross origin bypass attempt | off | off | drop |
1 | 16668 | BROWSER-CHROME | Google Chrome GURL cross origin bypass attempt | off | off | drop |
1 | 16671 | BROWSER-PLUGINS | IBM Lotus Domino Web Access ActiveX exploit attempt | off | off | off |
1 | 16672 | BROWSER-PLUGINS | Symantec Backup Exec ActiveX control buffer overflow attempt | off | off | off |
1 | 16673 | FILE-OTHER | Adobe Shockwave DIR file PAMI chunk code execution attempt | off | off | drop |
1 | 16674 | SERVER-WEBAPP | HP OpenView CGI parameter buffer overflow attempt | drop | drop | drop |
1 | 16675 | BROWSER-PLUGINS | CA BrightStor ListCtrl ActiveX control access | off | off | off |
1 | 16676 | FILE-PDF | Adobe Acrobat Reader malformed FlateDecode colors declaration | off | off | off |
1 | 16677 | FILE-PDF | Adobe Acrobat Reader malformed FlateDecode colors declaration | off | off | off |
1 | 16683 | FILE-MULTIMEDIA | Nullsoft Winamp CAF file processing integer overflow attempt | off | off | off |
1 | 16685 | SERVER-OTHER | IBM Tivoli Storage Manager Client dsmagent.exe NodeName length buffer overflow attempt | off | off | off |
1 | 16688 | SERVER-OTHER | iscsi target format string code execution attempt | off | off | off |
1 | 16703 | SERVER-MYSQL | Database COM_FIELD_LIST Buffer Overflow attempt | off | off | off |
1 | 16705 | PROTOCOL-RPC | Oracle Solaris sadmind UDP array size buffer overflow attempt | off | off | off |
1 | 16706 | PROTOCOL-RPC | Oracle Solaris sadmind TCP array size buffer overflow attempt | off | off | off |
1 | 16710 | SERVER-OTHER | Oracle BEA Weblogic server console-help.portal cross-site scripting attempt | off | off | off |
1 | 16716 | FILE-IMAGE | Oracle Java Web Start Splashscreen PNG processing buffer overflow attempt | off | off | off |
1 | 16717 | SERVER-ORACLE | Oracle Secure Enterprise Search search_p_groups cross-site scripting attempt | off | off | off |
1 | 16719 | FILE-OTHER | CA multiple product AV engine CAB header parsing stack overflow attempt | off | off | off |
1 | 16720 | FILE-MULTIMEDIA | VideoLAN VLC Media Player TY processing buffer overflow attempt | off | off | off |
1 | 16721 | FILE-OTHER | Orbital Viewer .orb stack buffer overflow attempt | off | off | drop |
1 | 16722 | SERVER-ORACLE | Oracle Database Server DBMS_CDC_PUBLISH.DROP_CHANGE_SOURCE procedure SQL injection attempt | off | off | off |
1 | 16723 | SERVER-ORACLE | Oracle Database Server DBMS_CDC_PUBLISH.ALTER_CHANGE_SOURCE procedure SQL injection attempt | off | off | off |
1 | 16724 | OS-LINUX | Linux kernel sctp_process_unk_param SCTPChunkInit buffer overflow attempt | off | off | off |
1 | 16746 | BROWSER-PLUGINS | IBM Access Support ActiveX clsid access | off | off | off |
1 | 16752 | FILE-MULTIMEDIA | VideoLAN VLC Media Player SMB module Win32AddConnection buffer overflow attempt | off | off | off |
1 | 16753 | SERVER-WEBAPP | VideoLAN VLC Media Player SMB module Win32AddConnection buffer overflow attempt | off | off | off |
1 | 16763 | NETBIOS | SMB Timbuktu Pro overflow WriteAndX attempt | off | off | off |
1 | 16765 | NETBIOS | SMB Timbuktu Pro overflow WriteAndX unicode attempt | off | off | off |
1 | 16772 | BROWSER-PLUGINS | EMC Captiva QuickScan Pro ActiveX clsid access | off | drop | drop |
1 | 16788 | SERVER-OTHER | RealVNC VNC Server ClientCutText message memory corruption attempt | off | off | off |
1 | 16796 | PROTOCOL-RPC | Oracle Solaris sadmind UDP data length integer overflow attempt | off | off | off |
1 | 16797 | PROTOCOL-RPC | Oracle Solaris sadmind TCP data length integer overflow attempt | off | off | off |
1 | 16800 | FILE-OFFICE | Microsoft Office Excel FRTWrapper record buffer overflow attempt | off | off | off |
1 | 17034 | FILE-OFFICE | Microsoft Office Outlook AttachMethods local file execution attempt | off | off | drop |
1 | 17035 | FILE-OFFICE | Microsoft Office Outlook AttachMethods local file execution attempt | off | off | drop |
1 | 17036 | FILE-OFFICE | Microsoft Office Outlook AttachMethods local file execution attempt | off | off | drop |
1 | 17037 | BROWSER-PLUGINS | Microsoft Office Access multiple control instantiation memory corruption attempt | off | off | off |
1 | 17038 | FILE-OFFICE | Microsoft Office Access ACCWIZ library release after free attempt - 1 | off | off | drop |
1 | 17039 | FILE-OFFICE | Microsoft Office Access ACCWIZ library release after free attempt - 2 | off | off | drop |
1 | 17042 | FILE-OTHER | Microsoft LNK shortcut arbitrary dll load attempt | off | off | drop |
1 | 17045 | SERVER-OTHER | CA ARCserve Backup for Laptops and Desktops LGServer handshake buffer overflow attempt | off | off | off |
1 | 17046 | SERVER-OTHER | CA ARCserve Backup for Laptops and Desktops LGServer handshake buffer overflow attempt | off | off | off |
1 | 17051 | BROWSER-PLUGINS | Symantec AppStream Client LaunchObj ActiveX clsid access | off | off | off |
1 | 17056 | NETBIOS | Novell NetIdentity Agent XTIERRPCPIPE remote code execution attempt | off | off | off |
1 | 17057 | NETBIOS | Novell Client NetIdentity Agent remote arbitrary pointer dereference code execution attempt | off | off | off |
1 | 17092 | BROWSER-PLUGINS | Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX clsid access | off | off | off |
1 | 17094 | BROWSER-PLUGINS | Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX function call access | off | off | off |
1 | 17103 | SERVER-IIS | IIS 5.1 alternate data stream authentication bypass attempt | off | off | off |
1 | 17107 | SERVER-APACHE | Apache Tomcat JK Web Server Connector long URL stack overflow attempt - 1 | off | off | off |
1 | 17111 | INDICATOR-OBFUSCATION | known JavaScript obfuscation routine | off | off | off |
1 | 17114 | OS-WINDOWS | Microsoft SilverLight ImageSource remote code execution attempt | off | off | drop |
1 | 17117 | FILE-MULTIMEDIA | Microsoft Windows MPEG Layer-3 audio heap corruption attempt | off | off | drop |
1 | 17119 | FILE-OFFICE | Microsoft Office Word sprmCMajority SPRM overflow attempt | off | off | drop |
1 | 17120 | FILE-OFFICE | Microsoft Office Word rich text format unexpected field type memory corruption attempt 1 | off | off | drop |
1 | 17121 | FILE-OFFICE | Microsoft Office Word rich text format unexpected field type memory corruption attempt 2 | off | off | drop |
1 | 17122 | FILE-OFFICE | Microsoft Office Word rich text format unexpected field type memory corruption attempt 3 | off | off | drop |
1 | 17123 | FILE-OFFICE | Microsoft Office Word rich text format invalid field size memory corruption attempt | off | off | drop |
1 | 17124 | FILE-OFFICE | Microsoft Office Word malformed table record memory corruption attempt | off | off | drop |
1 | 17128 | FILE-MULTIMEDIA | Cinepak Codec VIDC decompression remote code execution attempt | off | off | drop |
1 | 17130 | BROWSER-IE | Microsoft Internet Explorer boundElements arbitrary code execution | off | off | drop |
1 | 17134 | FILE-OFFICE | Microsoft Office Excel pivot item index boundary corruption attempt | off | off | drop |
1 | 17135 | FILE-MULTIMEDIA | Microsoft Windows Movie Maker string size overflow attempt | off | off | drop |
1 | 17138 | SERVER-OTHER | iSCSI target multiple implementations iSNS stack buffer overflow attempt | off | off | off |
1 | 17139 | SERVER-OTHER | Symantec Alert Management System HNDLRSVC arbitrary command execution attempt | off | off | off |
1 | 17140 | SERVER-WEBAPP | OpenView Network Node Manager cookie buffer overflow attempt | off | off | drop |
1 | 17143 | FILE-IMAGE | Adobe Photoshop CS4 ABR file processing buffer overflow attempt - 1 | off | off | drop |
1 | 17144 | FILE-IMAGE | Adobe Photoshop CS4 ABR file processing buffer overflow attempt - 2 | off | off | drop |
1 | 17145 | FILE-IMAGE | Adobe Photoshop CS4 ASL file processing buffer overflow attempt | off | off | drop |
1 | 17146 | FILE-IMAGE | Adobe Photoshop CS4 GRD file processing buffer overflow attempt | off | off | drop |
1 | 17147 | FILE-IMAGE | Adobe Photoshop CS4 ABR file processing buffer overflow attempt | off | off | drop |
1 | 17148 | FILE-MULTIMEDIA | VideoLAN VLC renamed zip file handling code execution attempt - 1 | off | off | off |
1 | 17149 | FILE-MULTIMEDIA | VideoLAN VLC renamed zip file handling code execution attempt - 2 | off | off | off |
1 | 17150 | FILE-MULTIMEDIA | VideoLAN VLC renamed zip file handling code execution attempt - 3 | off | off | off |
1 | 17153 | BROWSER-FIREFOX | Mozilla Firefox plugin parameter array dangling pointer exploit attempt - 1 | off | off | drop |
1 | 17154 | BROWSER-FIREFOX | Mozilla Firefox plugin parameter array dangling pointer exploit attempt - 2 | off | off | drop |
1 | 17155 | SERVER-OTHER | Multiple vendors OPIE off-by-one stack buffer overflow attempt | off | off | drop |
1 | 17156 | SERVER-APACHE | HP Performance Manager Apache Tomcat policy bypass attempt | off | off | off |
1 | 17157 | SERVER-WEBAPP | HP Intelligent Management Center database credentials information disclosure attempt - 1 | off | off | off |
1 | 17158 | SERVER-WEBAPP | HP Intelligent Management Center database credentials information disclosure attempt - 2 | off | off | off |
1 | 17159 | SERVER-WEBAPP | HP Intelligent Management Center database credentials information disclosure attempt - 3 | off | off | off |
1 | 17160 | BROWSER-PLUGINS | Liquid XML Studio LtXmlComHelp8.dll ActiveX OpenFile buffer overflow attempt | off | off | off |
1 | 17161 | BROWSER-PLUGINS | Liquid XML Studio ActiveX clsid access | off | off | off |
1 | 17163 | BROWSER-PLUGINS | Liquid XML Studio ActiveX function call access | off | off | off |
1 | 17165 | BROWSER-OTHER | Opera browser document writing uninitialized memory access attempt | off | off | drop |
1 | 17166 | BROWSER-FIREFOX | Mozilla multiple products JavaScript string replace buffer overflow attempt | off | off | off |
1 | 17179 | FILE-OTHER | Adobe Director file pamm record exploit attempt | off | off | drop |
1 | 17191 | FILE-OTHER | Adobe Director remote code execution attempt | off | off | drop |
1 | 17194 | FILE-OTHER | Adobe Director file tSAC tag exploit attempt | off | off | drop |
1 | 17202 | FILE-OTHER | Adobe Director file file Shockwave 3D overflow attempt | off | off | drop |
1 | 17205 | PROTOCOL-RPC | Multiple vendors librpc.dll stack buffer overflow attempt - udp | off | off | drop |
1 | 17206 | PROTOCOL-RPC | Multiple vendors librpc.dll stack buffer overflow attempt - tcp | off | off | drop |
1 | 17207 | SERVER-OTHER | IBM Cognos Server backdoor account remote code execution attempt | off | off | off |
1 | 17209 | SQL | IBM DB2 DATABASE SERVER SQL REPEAT Buffer Overflow | off | drop | drop |
1 | 17210 | FILE-EXECUTABLE | Microsoft Windows executable file load from SMB share attempt | off | off | off |
1 | 17211 | FILE-MULTIMEDIA | Apple QuickTime marshaled punk remote code execution | off | off | drop |
1 | 17212 | BROWSER-FIREFOX | Mozilla Firefox JavaScript eval arbitrary code execution attempt | off | off | off |
1 | 17214 | FILE-PDF | Adobe Acrobat Reader libtiff TIFFFetchShortPair stack buffer overflow attempt | off | off | drop |
1 | 17215 | FILE-PDF | Adobe Acrobat Reader libtiff TIFFFetchShortPair stack buffer overflow attempt | off | off | drop |
1 | 17219 | BROWSER-FIREFOX | Mozilla Firefox domain name handling buffer overflow attempt | off | off | off |
1 | 17224 | SERVER-MAIL | McAfee WebShield SMTP bounce message format string attempt | off | off | off |
1 | 17227 | FILE-OFFICE | Microsoft Office Excel sheet name memory corruption attempt | off | off | off |
1 | 17231 | FILE-IMAGE | Microsoft Kodak Imaging small offset malformed tiff - little-endian | off | off | off |
1 | 17232 | FILE-IMAGE | Microsoft Kodak Imaging large offset malformed tiff - big-endian | off | off | off |
1 | 17233 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 17236 | BROWSER-FIREFOX | Mozilla Firefox nsPropertyTable PropertyList memory corruption attempt | off | off | off |
1 | 17238 | FILE-OTHER | ACD Systems ACDSee Products XBM file handling buffer overflow attempt | off | off | off |
1 | 17239 | SERVER-MAIL | Multiple IMAP server CREATE command buffer overflow attempt | off | drop | drop |
1 | 17243 | SERVER-OTHER | MIT Kerberos V5 krb5_recvauth double free attempt | off | off | off |
1 | 17244 | FILE-OTHER | Antivirus ACE file handling buffer overflow attempt | off | off | off |
1 | 17245 | BROWSER-FIREFOX | Mozilla Firefox image dragging exploit attempt | off | off | off |
1 | 17250 | FILE-OFFICE | Microsoft Windows WordPad sprmTSetBrc SPRM overflow attempt | off | off | off |
1 | 17252 | OS-WINDOWS | Microsoft Windows Print Spooler arbitrary file write attempt | off | off | drop |
1 | 17256 | OS-WINDOWS | Microsoft Windows uniscribe fonts parsing memory corruption attempt | off | off | drop |
1 | 17258 | BROWSER-FIREFOX | Mozilla Firefox XUL tree element code execution attempt | off | off | off |
1 | 17260 | BROWSER-FIREFOX | Mozilla Firefox Javascript contentWindow in an iframe exploit attempt | off | off | off |
1 | 17261 | BROWSER-IE | Microsoft Internet Explorer createTextRange code execution attempt | off | off | off |
1 | 17264 | SERVER-ORACLE | Permission declaration exploit attempt | off | off | off |
1 | 17265 | BROWSER-FIREFOX | Mozilla Firefox plugin access control bypass attempt | off | off | off |
1 | 17266 | FILE-OTHER | Multiple vendor malformed ZIP archive Antivirus detection bypass attempt | off | off | off |
1 | 17268 | BROWSER-FIREFOX | Mozilla Firefox sidebar panel arbitrary code execution attempt | off | off | off |
1 | 17270 | SERVER-ORACLE | DBMS_METADATA Package SQL Injection attempt | off | off | off |
1 | 17271 | FILE-OFFICE | Microsoft Windows Web View script injection attempt | off | off | off |
1 | 17273 | SERVER-OTHER | MIT Kerberos V5 KDC krb5_unparse_name overflow attempt | off | off | off |
1 | 17274 | SERVER-OTHER | MIT Kerberos V5 KDC krb5_unparse_name overflow attempt | off | off | off |
1 | 17276 | FILE-OTHER | Multiple vendor Antivirus magic byte detection evasion attempt | off | off | off |
1 | 17279 | SERVER-WEBAPP | Ipswitch WhatsUp Small Business directory traversal attempt | off | off | off |
1 | 17281 | FILE-OTHER | Panda Antivirus ZOO archive decompression buffer overflow attempt | off | off | off |
1 | 17282 | SERVER-OTHER | Panda Antivirus ZOO archive decompression buffer overflow attempt | off | off | off |
1 | 17283 | SERVER-MAIL | Mercury Mail Transport System buffer overflow attempt | off | off | off |
1 | 17284 | FILE-OFFICE | Microsoft Office malformed routing slip code execution attempt | off | off | off |
1 | 17285 | FILE-OFFICE | Microsoft Office PowerPoint PPT file parsing memory corruption attempt | off | off | off |
1 | 17286 | FILE-OTHER | Microsoft Visual Basic for Applications document properties overflow attempt | off | off | off |
1 | 17289 | FILE-OTHER | GNU gzip LZH decompression make_table overflow attempt | off | off | off |
1 | 17291 | INDICATOR-OBFUSCATION | base64-encoded uri data object found | off | off | off |
1 | 17292 | FILE-OFFICE | Microsoft Office PowerPoint malformed data record code execution attempt | off | off | off |
1 | 17293 | SERVER-ORACLE | sdo_lrs.convert_to_lrs_layer buffer overflow attempt | off | off | off |
1 | 17295 | SERVER-WEBAPP | Trend Micro OfficeScan Console authentication buffer overflow attempt | off | off | off |
1 | 17298 | SERVER-OTHER | IBM Tivoli Monitoring Express Universal Agent Buffer Overflow | off | off | off |
1 | 17301 | FILE-OFFICE | Microsoft Office Word TextBox sub-document memory corruption attempt | off | off | off |
1 | 17303 | BROWSER-IE | Microsoft Internet Explorer clone object memory corruption attempt | off | off | off |
1 | 17304 | FILE-OFFICE | Microsoft Works file converter file section header index table stack overflow attempt | off | off | off |
1 | 17305 | FILE-OTHER | ClamAV libclamav PE file handling integer overflow attempt | off | off | off |
1 | 17307 | SERVER-MSSQL | Microsoft SQL Server INSERT Statement Buffer Overflow attempt | off | off | off |
1 | 17308 | FILE-OFFICE | Microsoft Office Word SmartTag record code execution attempt | off | off | off |
1 | 17309 | FILE-OTHER | CoolPlayer Playlist File Handling Buffer Overflow | off | off | off |
1 | 17310 | FILE-OFFICE | Microsoft Office PowerPoint Viewer memory allocation code execution attempt | off | off | off |
1 | 17312 | BROWSER-IE | Microsoft Internet Explorer CSS import cross-domain restriction bypass attempt | off | off | off |
1 | 17315 | FILE-OFFICE | OpenOffice OLE file stream buffer overflow attempt | off | off | off |
1 | 17317 | SERVER-OTHER | OpenSSH sshd identical blocks DoS attempt | off | off | off |
1 | 17318 | FILE-OFFICE | Microsoft Office PowerPoint MCAtom remote code execution attempt | off | off | off |
1 | 17321 | NETBIOS | DCERPC NCACN-IP-TCP spoolss EnumPrinters name overflow attempt | off | off | off |
1 | 17322 | INDICATOR-SHELLCODE | x86 OS agnostic fnstenv geteip dword xor decoder | off | off | off |
1 | 17324 | INDICATOR-SHELLCODE | x86 Linux reverse connect shellcode | off | off | off |
1 | 17325 | INDICATOR-SHELLCODE | x86 OS agnostic alpha numeric upper case decoder variant | off | off | off |
1 | 17326 | SERVER-OTHER | Citrix Program Neighborhood Client buffer overflow attempt | off | off | off |
1 | 17328 | SERVER-MAIL | Qualcomm WorldMail IMAP Literal Token Parsing Buffer Overflow | off | off | off |
1 | 17329 | PROTOCOL-FTP | EPRT overflow attempt | off | off | off |
1 | 17330 | FILE-IMAGE | Microsoft Windows GRE WMF Handling Memory Read Exception attempt | off | off | off |
1 | 17331 | SERVER-MAIL | IBM Lotus Notes HTML Speed Reader Long URL buffer overflow attempt | off | off | off |
1 | 17333 | SERVER-MAIL | Lotus Notes Attachment Viewer UUE file buffer overflow attempt | off | off | off |
1 | 17334 | FILE-FLASH | RealNetworks RealPlayer SWF flash file buffer overflow attempt | off | off | off |
1 | 17335 | INDICATOR-SHELLCODE | x86 OS agnostic fnstenv geteip byte xor decoder | off | off | off |
1 | 17336 | INDICATOR-SHELLCODE | x86 OS agnostic call geteip byte xor decoder | off | off | off |
1 | 17337 | INDICATOR-SHELLCODE | x86 Microsoft Win32 export table enumeration variant | off | off | off |
1 | 17338 | INDICATOR-SHELLCODE | x86 Microsoft Windows 32-bit SEH get EIP technique | off | off | off |
1 | 17339 | INDICATOR-SHELLCODE | x86 generic OS alpha numeric mixed case decoder | off | off | off |
1 | 17340 | INDICATOR-SHELLCODE | x86 OS agnostic alpha numeric upper case decoder | off | off | off |
1 | 17341 | INDICATOR-SHELLCODE | x86 OS agnostic alpha UTF8 tolower avoidance decoder | off | off | off |
1 | 17342 | INDICATOR-SHELLCODE | x86 OS agnostic unicode mixed case decoder | off | off | off |
1 | 17343 | INDICATOR-SHELLCODE | x86 OS agnostic unicode upper case decoder | off | off | off |
1 | 17344 | INDICATOR-SHELLCODE | x86 OS agnostic xor dword decoder | off | off | off |
1 | 17345 | INDICATOR-SHELLCODE | x86 OS agnostic dword additive feedback decoder | off | off | off |
1 | 17347 | OS-WINDOWS | Microsoft Windows Color Management Module buffer overflow attempt | off | off | off |
1 | 17350 | SERVER-ORACLE | Application Server Forms Arbitrary System Command Execution Attempt | off | off | off |
1 | 17351 | FILE-OTHER | Nullsoft Winamp ID3v2 Tag Handling Buffer Overflow attempt | off | off | off |
1 | 17352 | FILE-OTHER | ClamAV CHM File Handling Integer Overflow attempt | off | off | off |
1 | 17356 | FILE-OTHER | NOD32 Anti-Virus ARJ Archive Handling Buffer Overflow attempt | off | off | off |
1 | 17357 | PUA-OTHER | AOL GAIM AIM-ICQ Protocol Handling buffer overflow attempt | off | off | off |
1 | 17358 | FILE-EXECUTABLE | ClamAV UPX File Handling Buffer Overflow attempt | off | off | off |
1 | 17360 | BROWSER-FIREFOX | Mozilla Firefox XBM image processing buffer overflow attempt | off | off | off |
1 | 17361 | FILE-PDF | Adobe Acrobat Reader PDF Catalog Handling denial of service attempt | off | off | off |
1 | 17362 | FILE-OFFICE | Microsoft Office Excel IMDATA buffer overflow attempt | off | off | off |
1 | 17363 | FILE-OTHER | Apple OSX Finder DMG volume name memory corruption attempt | off | off | off |
1 | 17365 | FILE-OTHER | Microsoft Windows Help Workshop CNT Help contents buffer overflow attempt | off | off | off |
1 | 17366 | FILE-OTHER | Microsoft Help Workshop HPJ OPTIONS section buffer overflow attempt | off | off | off |
1 | 17368 | FILE-OFFICE | Microsoft Office Word document stream handling code execution attempt | off | off | off |
1 | 17369 | SERVER-MAIL | MailEnable service APPEND command handling buffer overflow attempt | off | off | off |
1 | 17372 | FILE-MULTIMEDIA | Apple QuickTime udta atom parsing heap overflow vulnerability | off | off | off |
1 | 17373 | FILE-MULTIMEDIA | Apple QuickTime panorama atoms buffer overflow attempt | off | off | off |
1 | 17376 | SERVER-WEBAPP | IBM Lotus Expeditor cai URI handler command execution attempt | off | off | off |
1 | 17377 | FILE-OFFICE | Microsoft Office Excel Malformed Filter Records Handling Code Execution attempt | off | off | off |
1 | 17378 | BROWSER-FIREFOX | Mozilla Firefox Animated PNG Processing integer overflow attempt | off | off | off |
1 | 17381 | FILE-MULTIMEDIA | Apple QuickTime PDAT Atom parsing buffer overflow attempt | off | off | off |
1 | 17382 | FILE-OTHER | Microsoft Project Invalid Memory Pointer Code Execution attempt | off | off | off |
1 | 17383 | FILE-OFFICE | Microsoft Office Publisher Object Handler Validation Code Execution attempted | off | off | off |
1 | 17389 | BROWSER-FIREFOX | Mozilla Firefox DOMNodeRemoved attack attempt | off | off | off |
1 | 17391 | SERVER-APACHE | Apache Tomcat UNIX platform backslash directory traversal | off | off | off |
1 | 17392 | INDICATOR-SHELLCODE | JavaScript var shellcode | off | off | off |
1 | 17393 | INDICATOR-SHELLCODE | JavaScript var heapspray | off | off | off |
1 | 17395 | FILE-IMAGE | Oracle Java Web Start Splashscreen GIF decoding buffer overflow attempt | off | off | off |
1 | 17397 | SERVER-OTHER | VNCViewer Authenticate buffer overflow attempt | off | off | off |
1 | 17398 | BROWSER-FIREFOX | Mozilla Firefox Javascript array.splice memory corruption attempt | off | off | off |
1 | 17399 | BROWSER-FIREFOX | Mozilla Firefox Javascript array.splice memory corruption attempt | off | off | off |
1 | 17401 | BROWSER-IE | Microsoft Internet Explorer nested tag memory corruption attempt - unescaped | off | off | off |
1 | 17402 | BROWSER-IE | Microsoft Internet Explorer nested tag memory corruption attempt | off | off | off |
1 | 17403 | FILE-OFFICE | OpenOffice RTF File parsing heap buffer overflow attempt | off | off | off |
1 | 17404 | FILE-OFFICE | Microsoft Office Word Converter XST structure buffer overflow attempt | off | off | off |
1 | 17408 | OS-WINDOWS | Microsoft Windows DirectX Targa image file heap overflow attempt | off | off | off |
1 | 17409 | BROWSER-FIREFOX | Mozilla Products IDN Spoofing Vulnerability Attempt | off | off | off |
1 | 17410 | OS-WINDOWS | Generic HyperLink buffer overflow attempt | off | off | off |
1 | 17411 | BROWSER-IE | Microsoft Internet Explorer CDF cross-domain scripting attempt | off | off | off |
1 | 17412 | SERVER-MYSQL | create function mysql.func arbitrary library injection attempt | off | off | off |
1 | 17414 | BROWSER-FIREFOX | Mozilla Firefox Javascript Engine Information Disclosure attempt | off | off | off |
1 | 17418 | SERVER-ORACLE | Oracle connection established | off | off | off |
1 | 17419 | SERVER-ORACLE | Oracle database SQL compiler read-only join auth bypass attempt | off | off | off |
1 | 17420 | SERVER-WEBAPP | Citrix Program Neighborhood Agent Arbitrary Shortcut Creation attempt | off | off | off |
1 | 17421 | FILE-OFFICE | Microsoft OLE automation string manipulation overflow attempt | off | off | off |
1 | 17422 | BROWSER-FIREFOX | Mozilla Firefox defineSetter function pointer memory corruption attempt | off | off | off |
1 | 17423 | SERVER-WEBAPP | Citrix Program Neighborhood Agent Buffer Overflow attempt | off | off | off |
1 | 17424 | BROWSER-FIREFOX | Mozilla Firefox IconURL Arbitrary Javascript Execution attempt | off | off | off |
1 | 17425 | BROWSER-PLUGINS | RealNetworks RealPlayer ActiveX Import playlist name buffer overflow attempt | off | off | off |
1 | 17427 | SERVER-ORACLE | Oracle database DBMS_Scheduler privilege escalation attempt | off | off | off |
1 | 17430 | FILE-PDF | BitDefender Antivirus PDF processing memory corruption attempt | off | off | off |
1 | 17433 | OS-SOLARIS | Oracle Solaris DHCP Client Arbitrary Code Execution attempt | off | off | off |
1 | 17434 | BROWSER-FIREFOX | Mozilla Firefox Unicode sequence handling stack corruption attempt | off | off | off |
1 | 17442 | FILE-OTHER | Microsoft Windows download of .lnk file that executes cmd.exe detected | off | off | off |
1 | 17443 | FILE-MULTIMEDIA | Microsoft DirectShow AVI decoder buffer overflow attempt | off | off | off |
1 | 17444 | BROWSER-FIREFOX | Mozilla Firefox 3 xsl parsing heap overflow attempt | off | off | off |
1 | 17449 | SERVER-WEBAPP | Novell ZENworks patch management SQL injection attempt | off | off | off |
1 | 17450 | SERVER-WEBAPP | CommuniGate Systems CommuniGate Pro LDAP Server buffer overflow attempt | off | off | off |
1 | 17457 | FILE-FLASH | Adobe Flash ActionDefineFunction memory access exploit attempt | off | off | off |
1 | 17458 | FILE-OTHER | BitDefender Internet Security script code execution attempt | off | off | off |
1 | 17461 | FILE-OTHER | RealNetworks RealPlayer zipped skin file buffer overflow attempt | off | off | off |
1 | 17462 | BROWSER-IE | Microsoft Internet Explorer marquee object handling memory corruption attempt | off | off | off |
1 | 17463 | BROWSER-IE | Microsoft Internet Explorer File Download Dialog Box Manipulation | off | off | off |
1 | 17466 | BROWSER-PLUGINS | IBM Lotus Domino Web Access 7 ActiveX exploit attempt | off | off | off |
1 | 17469 | FILE-MULTIMEDIA | Mplayer Real Demuxer stream_read heap overflow attempt | off | off | off |
1 | 17470 | FILE-MULTIMEDIA | Apple QuickTime STSD JPEG atom heap corruption attempt | off | off | off |
1 | 17481 | SERVER-MAIL | Microsoft Windows Exchange and Outlook TNEF Decoding Integer Overflow attempt | off | off | off |
1 | 17482 | BROWSER-FIREFOX | Mozilla NNTP URL Handling Buffer Overflow attempt | off | off | off |
1 | 17486 | SERVER-WEBAPP | Trend Micro Control Manager Chunked overflow attempt | off | off | off |
1 | 17488 | FILE-OFFICE | Microsoft Office Excel Malformed Range Code Execution attempt | off | off | off |
1 | 17490 | FILE-OTHER | Microsoft Windows itss.dll CHM File Handling Heap Corruption attempt | off | off | off |
1 | 17491 | FILE-OFFICE | Microsoft Office Word mso.dll LsCreateLine memory corruption attempt | off | off | off |
1 | 17492 | FILE-OFFICE | Microsoft Office Excel Malformed SELECTION Record Code Execution attempt | off | off | off |
1 | 17493 | FILE-OTHER | ClamAV UPX FileHandling Heap overflow attempt | off | off | off |
1 | 17496 | FILE-OFFICE | Microsoft Office PowerPoint malformed NamedShows record code execution attempt | off | off | off |
1 | 17497 | FILE-OFFICE | Microsoft Office PowerPoint malformed NamedShows record code execution attempt | off | off | off |
1 | 17504 | SERVER-OTHER | Novell ZENworks Asset Management buffer overflow attempt | off | off | off |
1 | 17506 | FILE-OFFICE | Microsoft Office Word formatted disk pages table memory corruption attempt | off | off | off |
1 | 17511 | FILE-OFFICE | Microsoft Office Excel malformed Graphic Code Execution | off | off | off |
1 | 17515 | BROWSER-IE | Microsoft Internet Explorer Script Action Handler buffer overflow attempt | off | off | off |
1 | 17517 | FILE-OFFICE | Microsoft Office Excel Malformed Record Code Execution attempt | off | off | off |
1 | 17519 | BROWSER-FIREFOX | Mozilla Firefox UTF-8 URL Handling Stack Buffer Overflow | off | off | off |
1 | 17521 | SERVER-OTHER | GoodTech SSH Server SFTP processing buffer overflow attempt | off | off | off |
1 | 17522 | FILE-JAVA | Oracle Java Runtime Environment Pack200 Decompression Integer Overflow | off | off | off |
1 | 17523 | FILE-MULTIMEDIA | Apple QuickTime H.264 Movie File Buffer Overflow | off | off | off |
1 | 17524 | SERVER-OTHER | Fujitsu SystemcastWizard Lite PXEService UDP Handling Buffer Overflow | off | off | off |
1 | 17525 | SERVER-IIS | Microsoft Windows IIS 5.0 WebDav Request Directory Security Bypass | off | off | off |
1 | 17526 | FILE-PDF | Adobe Acrobat and Adobe Acrobat Reader U3D RHAdobeMeta buffer overflow attempt | off | off | off |
1 | 17527 | FILE-MULTIMEDIA | VideoLAN VLC Media Player MP4_BoxDumpStructure Buffer Overflow | off | off | off |
1 | 17528 | SERVER-WEBAPP | nginx URI parsing buffer overflow attempt | off | off | off |
1 | 17529 | SERVER-WEBAPP | Adobe RoboHelp Server Arbitrary File Upload and Execute | off | off | off |
1 | 17530 | SERVER-OTHER | HP OpenView Storage Data Protector Stack Buffer Overflow | off | off | off |
1 | 17531 | FILE-MULTIMEDIA | Apple QuickTime MOV file JVTCompEncodeFrame heap overflow attempt | off | off | off |
1 | 17532 | FILE-OFFICE | Micrsoft Office Excel TXO and OBJ Records Parsing Stack Memory Corruption | off | off | off |
1 | 17535 | SERVER-OTHER | Apple CUPS Text to PostScript Filter Integer Overflow attempt | off | off | off |
1 | 17536 | SERVER-WEBAPP | generic server HTTP Auth Header buffer overflow attempt | off | off | off |
1 | 17538 | FILE-OFFICE | Microsoft Office Excel unspecified memory corruption attempt | off | off | off |
1 | 17541 | FILE-OTHER | Avast Antivirus Engine Remote LHA buffer overflow attempt | off | off | off |
1 | 17542 | FILE-OFFICE | Microsoft Office Excel MalformedPalete Record Memory Corruption attempt | off | off | off |
1 | 17543 | FILE-OFFICE | Microsoft Office Excel Column record handling memory corruption attempt | off | off | off |
1 | 17545 | BROWSER-PLUGINS | Lotus Domino Web Access ActiveX Controls buffer overflow attempt | off | off | off |
1 | 17548 | FILE-MULTIMEDIA | Apple QuickTime SMIL File Handling Integer Overflow attempt | off | off | off |
1 | 17550 | FILE-OFFICE | Microsoft Office Word Font Parsing Buffer Overflow attempt | off | off | off |
1 | 17551 | PUA-OTHER | Microsoft MSN Messenger and Windows Live Messenger Code Execution attempt | off | off | off |
1 | 17553 | FILE-OTHER | Adobe Pagemaker Font Name Buffer Overflow attempt | off | off | off |
1 | 17555 | BROWSER-PLUGINS | Macrovision InstallShield Update Service ActiveX exploit attempt | off | off | off |
1 | 17557 | BROWSER-PLUGINS | Novell iPrint ActiveX operation parameter overflow | off | off | off |
1 | 17558 | FILE-IMAGE | CUPS Gif Decoding Routine Buffer Overflow attempt | off | off | off |
1 | 17559 | FILE-OTHER | IBM Lotus Notes Applix Graphics Parsing Buffer Overflow | off | off | off |
1 | 17560 | FILE-OFFICE | Microsoft Office Word global array index heap overflow attempt | off | off | off |
1 | 17561 | FILE-MULTIMEDIA | RealNetworks RealPlayer IVR Overly Long Filename Code Execution attempt | off | off | off |
1 | 17563 | FILE-JAVA | Oracle Java Runtime Environment JAR File Processing Stack Buffer Overflow | off | off | off |
1 | 17564 | SERVER-IIS | WebDAV Request Directory Security Bypass attempt | off | off | off |
1 | 17565 | FILE-OFFICE | Microsoft Office PowerPoint PP7 File Handling Memory Corruption attempt | off | off | off |
1 | 17566 | BROWSER-IE | Microsoft Internet Explorer span tag memory corruption attempt | off | off | off |
1 | 17567 | SERVER-OTHER | LANDesk Management Suite Alerting Service buffer overflow attempt | off | off | off |
1 | 17569 | SERVER-OTHER | BEA Weblogic Admin Console Cross Site Scripting Vulnerability attempt | off | off | off |
1 | 17571 | BROWSER-PLUGINS | obfuscated instantiation of ActiveX object - likely malicious | off | off | off |
1 | 17573 | FILE-MULTIMEDIA | ffdshow codec URL parsing buffer overflow attempt | off | off | off |
1 | 17574 | FILE-OFFICE | Sophos Anti-Virus Visio File Parsing Buffer Overflow attempt | off | off | off |
1 | 17575 | BROWSER-PLUGINS | SizerOne 2 ActiveX clsid access | off | off | drop |
1 | 17577 | POLICY-OTHER | CA BightStor ARCserver Backup possible insecure method access | off | off | off |
1 | 17578 | FILE-OFFICE | Microsoft Office Word Section Table Array Buffer Overflow attempt | off | off | off |
1 | 17579 | FILE-OFFICE | Microsoft Office Drawing Record msofbtOPT Code Execution attempt | off | off | off |
1 | 17580 | BROWSER-IE | Microsoft Internet Explorer span tag memory corruption attempt | off | off | off |
1 | 17581 | BROWSER-FIREFOX | Mozilla Firefox tag order memory corruption attempt | off | off | off |
1 | 17582 | BROWSER-PLUGINS | Symantec Norton AntiVirus CcErrDisp ActiveX function call access | off | off | off |
1 | 17585 | BROWSER-IE | Microsoft Internet Explorer possible javascript onunload event memory corruption | off | off | off |
1 | 17586 | FILE-JAVA | Oracle Java Web Start malicious parameter value | off | off | off |
1 | 17587 | BROWSER-PLUGINS | Adobe Multiple Product AcroPDF.PDF ActiveX exploit attempt | off | off | off |
1 | 17588 | BROWSER-PLUGINS | Microsoft Internet Explorer Install Engine ActiveX clsid access | off | off | off |
1 | 17591 | FILE-OFFICE | Microsoft Office Word crafted sprm structure memory corruption attempt | off | off | off |
1 | 17596 | BROWSER-PLUGINS | Microsoft ciodm.dll ActiveX clsid access | off | off | off |
1 | 17597 | SERVER-WEBAPP | TikiWiki jhot.php script file upload attempt | off | off | off |
1 | 17601 | BROWSER-FIREFOX | Mozilla Firefox file type memory corruption attempt | off | off | off |
1 | 17603 | BROWSER-FIREFOX | Mozilla Firefox file type memory corruption attempt | off | off | off |
1 | 17604 | SERVER-OTHER | Oracle Java AWT ConvolveOp memory corruption attempt | off | off | off |
1 | 17605 | SERVER-WEBAPP | Trend Micro OfficeScan CGI password decryption buffer overflow attempt | off | off | off |
1 | 17606 | FILE-FLASH | Adobe Flash Player ASnative command execution attempt | off | off | off |
1 | 17607 | SERVER-OTHER | Xi Software Net Transport eDonkey Protocol Buffer Overflow attempt | off | off | off |
1 | 17609 | SERVER-WEBAPP | Oracle Java Web Server WebDAV Stack Buffer Overflow attempt | off | off | drop |
1 | 17610 | FILE-MULTIMEDIA | GStreamer QuickTime file parsing multiple heap overflow attempt | off | off | off |
1 | 17611 | FILE-MULTIMEDIA | GStreamer QuickTime file parsing multiple heap overflow attempt | off | off | off |
1 | 17612 | FILE-MULTIMEDIA | GStreamer QuickTime file parsing multiple heap overflow attempt | off | off | off |
1 | 17613 | BROWSER-FIREFOX | Mozilla Firefox browser engine memory corruption attempt | off | off | off |
1 | 17614 | BROWSER-PLUGINS | SAP GUI SAPBExCommonResources ActiveX clsid access | off | off | off |
1 | 17616 | BROWSER-PLUGINS | SAP GUI SAPBExCommonResources ActiveX function call access | off | off | off |
1 | 17618 | OS-WINDOWS | Microsoft Windows hraphics engine EMF rendering vulnerability | off | off | off |
1 | 17620 | SERVER-OTHER | Products Discovery Service Buffer Overflow | off | off | off |
1 | 17622 | BROWSER-IE | Microsoft Internet Explorer object reference memory corruption attempt | off | off | off |
1 | 17623 | FILE-JAVA | Oracle Java Runtime Environment Type1 Font parsing integer overflow attempt | off | off | off |
1 | 17629 | BROWSER-FIREFOX | Mozilla Firefox Chrome Page Loading Restriction Bypass attempt | off | off | off |
1 | 17630 | BROWSER-FIREFOX | Mozilla multiple products CSSValue array memory corruption attempt | off | off | off |
1 | 17631 | FILE-JAVA | Oracle Java Web Start JNLP j2se key value buffer overflow attempt | off | off | off |
1 | 17633 | FILE-OTHER | RealNetworks RealPlayer SWF frame handling buffer overflow attempt | off | off | off |
1 | 17635 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc function 0 little endian overflow attempt | off | off | off |
1 | 17638 | SERVER-ORACLE | Secure Backup administration server login.php cookies command injection attempt | off | off | off |
1 | 17640 | NETBIOS | DCERPC NCACN-IP-TCP brightstor opnum 43 overflow attempt | off | off | off |
1 | 17641 | FILE-PDF | CUPS and Xpdf JBIG2 symbol dictionary buffer overflow attempt | off | off | off |
1 | 17642 | BROWSER-FIREFOX | Mozilla Firefox ConstructFrame with floating first-letter memory corruption attempt | off | off | off |
1 | 17645 | BROWSER-IE | Microsoft Internet Explorer CSS strings parsing memory corruption attempt | off | off | off |
1 | 17649 | FILE-OFFICE | Microsoft Office Word array data handling buffer overflow attempt | off | off | off |
1 | 17650 | FILE-OTHER | Adobe Pagemaker Key Strings Stack Buffer Overflow attempt | off | off | off |
1 | 17651 | FILE-OTHER | Multiple AV vendor invalid archive checksum bypass attempt | off | off | off |
1 | 17655 | FILE-OFFICE | Microsoft Office Excel malformed formula parsing code execution attempt | off | off | off |
1 | 17656 | SERVER-APACHE | Apache HTTP server mod_rewrite module LDAP scheme handling buffer overflow attempt | off | off | off |
1 | 17657 | SERVER-OTHER | Symantec NetBackup BPCD Daemon exploit attempt | off | off | off |
1 | 17658 | FILE-FLASH | Adobe Flash frame type identifier memory corruption attempt | off | off | off |
1 | 17660 | SERVER-OTHER | Oracle Java Web Start arbitrary command execution attempt | off | off | drop |
1 | 17661 | SERVER-SAMBA | Samba send_mailslot buffer overflow attempt | off | off | off |
1 | 17662 | SERVER-OTHER | VMware Workstation DHCP service integer overflow attempt | off | off | off |
1 | 17666 | FILE-MULTIMEDIA | RealNetworks RealPlayer invalid chunk size heap overflow attempt | off | off | off |
1 | 17668 | FILE-PDF | download of a PDF with embedded JavaScript - JS string attempt | off | off | off |
1 | 17669 | SERVER-ORACLE | Oracle Application Server 10g OPMN service format string vulnerability exploit attempt | off | off | off |
1 | 17685 | BROWSER-IE | Microsoft Internet Explorer invalid pointer memory corruption attempt | off | off | drop |
1 | 17686 | BROWSER-IE | Microsoft Internet Explorer invalid pointer memory corruption attempt | off | off | drop |
1 | 17687 | BROWSER-IE | Microsoft Internet Explorer invalid pointer memory corruption attempt | off | off | drop |
1 | 17688 | BROWSER-IE | Microsoft Internet Explorer userdata behavior memory corruption attempt | off | off | drop |
1 | 17689 | BROWSER-IE | Microsoft Internet Explorer userdata behavior memory corruption attempt | off | off | drop |
1 | 17690 | FILE-OFFICE | Microsoft Office Word remote code execution attempt | off | off | off |
1 | 17692 | BROWSER-IE | Microsoft Internet Explorer ExecWB security zone bypass attempt | off | off | off |
1 | 17698 | SERVER-MAIL | RealNetworks RealPlayer wav chunk string overflow attempt in email | off | off | off |
1 | 17701 | BROWSER-PLUGINS | Office Viewer ActiveX arbitrary command execution attempt | off | off | off |
1 | 17704 | FILE-OTHER | McAfee LHA file parsing buffer overflow attempt | off | off | off |
1 | 17705 | SERVER-IIS | web agent chunked encoding overflow attempt | off | off | off |
1 | 17706 | SERVER-OTHER | Veritas NetBackup java user interface service format string attack attempt | off | off | off |
1 | 17708 | SERVER-OTHER | VNC password request URL buffer overflow attempt | off | off | off |
1 | 17709 | BROWSER-IE | Microsoft Internet Explorer EMBED element memory corruption attempt | off | off | off |
1 | 17710 | SERVER-OTHER | Veritas NetBackup vmd shared library buffer overflow attempt | off | off | off |
1 | 17711 | OS-WINDOWS | Microsoft Windows ASF parsing memory corruption attempt | off | off | off |
1 | 17712 | OS-WINDOWS | TFTP PUT Microsoft RIS filename overwrite attempt | off | off | off |
1 | 17713 | SERVER-OTHER | Novell NetMail NMAP STOR buffer overflow attempt | off | off | off |
1 | 17716 | SERVER-MAIL | IBM Lotus Notes DOC attachment viewer buffer overflow | off | off | off |
1 | 17717 | SERVER-MAIL | IBM Lotus Notes HTML input tag buffer overflow attempt | off | off | off |
1 | 17718 | SERVER-ORACLE | Oracle MDSYS drop table trigger injection attempt | off | off | off |
1 | 17719 | BROWSER-FIREFOX | Mozilla Firefox ClearTextRun exploit attempt | off | off | off |
1 | 17720 | BROWSER-IE | Microsoft Internet Explorer static text range overflow attempt | off | off | off |
1 | 17721 | OS-WINDOWS | Microsoft Windows WINS replication inform2 request memory corruption attempt | off | off | off |
1 | 17722 | SERVER-ORACLE | XDB.XDB_PITRIG_PKG buffer overflow attempt | off | off | off |
1 | 17723 | OS-WINDOWS | possible SMB replay attempt - overlapping encryption keys detected | off | off | drop |
1 | 17724 | OS-WINDOWS | malicious ASP file upload attempt | off | off | off |
1 | 17725 | BROWSER-OTHER | Opera file URI handling buffer overflow | off | off | off |
1 | 17727 | FILE-OTHER | Oracle JDK image parsing library ICC buffer overflow attempt | off | off | off |
1 | 17729 | BROWSER-IE | Microsoft Internet Explorer EMBED element memory corruption attempt | off | off | off |
1 | 17730 | OS-WINDOWS | Microsoft XML Core Services MIME Viewer memory corruption attempt | off | off | off |
1 | 17731 | OS-WINDOWS | Microsoft Windows wpad dynamic update request | off | off | off |
1 | 17734 | FILE-OFFICE | Microsoft Office Excel REPT integer underflow attempt | off | off | off |
1 | 17740 | FILE-IMAGE | Apple Quicktime FlashPix processing overflow attempt | off | off | off |
1 | 17742 | FILE-OFFICE | Microsoft Office Word remote code execution attempt | off | drop | drop |
1 | 17743 | FILE-OFFICE | Microsoft Office Word RTF parsing memory corruption | off | off | off |
1 | 17746 | OS-WINDOWS | SMB client TRANS response Find_First2 filename overflow attempt | off | off | off |
1 | 17747 | BROWSER-IE | Microsoft Internet Explorer compressed HDMX font processing integer overflow attempt | off | off | drop |
1 | 17753 | FILE-MULTIMEDIA | Microsoft Windows Media Player network sharing service RTSP code execution attempt | off | off | off |
1 | 17756 | FILE-OFFICE | Microsoft Office Word XP PLFLSInTableStream heap overflow attempt | off | off | drop |
1 | 17757 | FILE-OFFICE | Microsoft Office Excel CrErr record integer overflow attempt | off | off | drop |
1 | 17758 | FILE-OFFICE | Microsoft Office Excel PtgExtraArray data parsing vulnerability exploit attempt | off | off | drop |
1 | 17759 | FILE-OFFICE | Microsoft Office Excel invalid SerAr object exploit attempt | off | off | drop |
1 | 17760 | FILE-OFFICE | Microsoft Office Excel RealTimeData record exploit attempt | off | off | drop |
1 | 17764 | FILE-OFFICE | Microsoft Office Excel PtgName invalid index exploit attempt | off | off | drop |
1 | 17766 | BROWSER-IE | Microsoft Internet Explorer 8 XSS in toStaticHTML API attempt | off | off | off |
1 | 17767 | BROWSER-IE | Microsoft Internet Explorer 8 tostaticHTML CSS import vulnerability | off | off | off |
1 | 17768 | BROWSER-IE | Microsoft Internet Explorer 8 object event handler use after free exploit attempt | off | off | drop |
1 | 17769 | BROWSER-IE | Microsoft Internet Explorer 8 CSS invalid mapping exploit attempt | off | off | drop |
1 | 17770 | FILE-OFFICE | Microsoft HtmlDlgHelper ActiveX clsid access | off | off | drop |
1 | 17771 | BROWSER-IE | Microsoft Internet Explorer cross-domain information disclosure attempt | off | off | off |
1 | 17772 | BROWSER-PLUGINS | Microsoft Internet Explorer Scriptlet Component ActiveX clsid access | off | off | drop |
1 | 17777 | SERVER-MAIL | IBM Lotus Notes WPD attachment handling buffer overflow | off | off | off |
1 | 17778 | FILE-OTHER | BitDefender Internet Security script code execution attempt | off | off | off |
1 | 17803 | FILE-OTHER | Adobe Shockwave Director rcsL chunk memory corruption attempt | off | off | drop |
1 | 17804 | BROWSER-FIREFOX | Mozilla Firefox html tag attributes memory corruption | off | off | drop |
1 | 17806 | FILE-OTHER | Adobe Shockwave Director rcsL chunk remote code execution attempt | off | off | drop |
1 | 17807 | FILE-OTHER | Adobe Shockwave Director rcsL chunk remote code execution attempt | off | off | drop |
1 | 18065 | FILE-OFFICE | Microsoft Office PowerPoint converter bad indirection remote code execution attempt | off | off | drop |
1 | 18066 | FILE-OFFICE | Microsoft Office PowerPoint integer underflow heap corruption attempt | off | off | drop |
1 | 18067 | FILE-OFFICE | Microsoft Office RTF parsing remote code execution attempt | off | off | drop |
1 | 18068 | FILE-OFFICE | Microsoft Office Excel malformed MsoDrawingObject record attempt | off | off | drop |
1 | 18069 | FILE-OFFICE | Microsoft Office Art drawing invalid shape identifier attempt | off | off | drop |
1 | 18076 | OS-WINDOWS | Microsoft Forefront UAG URL XSS alternate attempt | off | off | off |
1 | 18097 | BROWSER-PLUGINS | VMWare Remote Console format string code execution attempt | off | off | drop |
1 | 18102 | FILE-PDF | Adobe Acrobat Reader invalid PDF JavaScript printSeps extension call attempt | off | off | drop |
1 | 18103 | BLACKLIST | DNS request for known malware domain 5yvod.net | off | off | off |
1 | 18104 | BLACKLIST | DNS request for known malware domain b.9s3.info | off | off | off |
1 | 18106 | BLACKLIST | DNS request for known malware domain e.msssm.com | off | off | off |
1 | 18108 | BLACKLIST | DNS request for known malware domain phoroshop.es | off | off | off |
1 | 18114 | BLACKLIST | DNS request for known malware domain www.5fqq.com | off | off | off |
1 | 18115 | BLACKLIST | DNS request for known malware domain www.ajs2002.com | off | off | off |
1 | 18116 | BLACKLIST | DNS request for known malware domain www.bnbsoft.co.kr | off | off | off |
1 | 18117 | BLACKLIST | DNS request for known malware domain www.cineseoul.com | off | off | off |
1 | 18118 | BLACKLIST | DNS request for known malware domain www.hao1345.com | off | off | off |
1 | 18119 | BLACKLIST | DNS request for known malware domain www.ilbondrama.net | off | off | off |
1 | 18120 | BLACKLIST | DNS request for known malware domain www.iwebdy.net | off | off | off |
1 | 18121 | BLACKLIST | DNS request for known malware domain www.linzhiling123.com | off | off | off |
1 | 18122 | BLACKLIST | DNS request for known malware domain www.opusgame.com | off | off | off |
1 | 18123 | BLACKLIST | DNS request for known malware domain www.phoroshop.es | off | off | off |
1 | 18124 | BLACKLIST | DNS request for known malware domain www.sijianfeng.com | off | off | off |
1 | 18125 | BLACKLIST | DNS request for known malware domain www.tpydb.com | off | off | off |
1 | 18127 | BLACKLIST | DNS request for known malware domain www.univus.co.kr | off | off | off |
1 | 18128 | BLACKLIST | DNS request for known malware domain www.uwonderfull.com | off | off | off |
1 | 18129 | BLACKLIST | DNS request for known malware domain www.w22rt.com | off | off | off |
1 | 18130 | BLACKLIST | DNS request for known malware domain www.wwmei.com | off | off | off |
1 | 18133 | BLACKLIST | DNS request for known malware domain www.001zs.com | off | off | off |
1 | 18134 | BLACKLIST | DNS request for known malware domain www.551sf.com | off | off | off |
1 | 18135 | BLACKLIST | DNS request for known malware domain www.555hd.com | off | off | off |
1 | 18136 | BLACKLIST | DNS request for known malware domain www.66xihu.com | off | off | off |
1 | 18137 | BLACKLIST | DNS request for known malware domain www.9292cs.cn | off | off | off |
1 | 18138 | BLACKLIST | DNS request for known malware domain www.chateaulegend.com | off | off | off |
1 | 18139 | BLACKLIST | DNS request for known malware domain www.china-aoben.com | off | off | off |
1 | 18140 | BLACKLIST | DNS request for known malware domain www.cqtjg.com | off | off | off |
1 | 18141 | BLACKLIST | DNS request for known malware domain www.dspenter.com | off | off | off |
1 | 18142 | BLACKLIST | DNS request for known malware domain www.eastadmin.com | off | off | off |
1 | 18143 | BLACKLIST | DNS request for known malware domain www.fp0755.cn | off | off | off |
1 | 18144 | BLACKLIST | DNS request for known malware domain www.fp0769.com | off | off | off |
1 | 18145 | BLACKLIST | DNS request for known malware domain www.fp360.net | off | off | off |
1 | 18146 | BLACKLIST | DNS request for known malware domain www.gdfp365.cn | off | off | off |
1 | 18147 | BLACKLIST | DNS request for known malware domain www.gev.cn | off | off | off |
1 | 18148 | BLACKLIST | DNS request for known malware domain www.haoleyou.com | off | off | off |
1 | 18149 | BLACKLIST | DNS request for known malware domain www.haosf08.com | off | off | off |
1 | 18150 | BLACKLIST | DNS request for known malware domain www.jxbaike.com | off | off | off |
1 | 18151 | BLACKLIST | DNS request for known malware domain www.kingsoftduba2009.com | off | off | off |
1 | 18152 | BLACKLIST | DNS request for known malware domain www.mainhu.com | off | off | off |
1 | 18154 | BLACKLIST | DNS request for known malware domain www.nc57.com | off | off | off |
1 | 18155 | BLACKLIST | DNS request for known malware domain www.pplog.cn | off | off | off |
1 | 18156 | BLACKLIST | DNS request for known malware domain www.pxflm.com | off | off | off |
1 | 18157 | BLACKLIST | DNS request for known malware domain www.quyou365.com | off | off | off |
1 | 18158 | BLACKLIST | DNS request for known malware domain www.shzhaotian.cn | off | off | off |
1 | 18159 | BLACKLIST | DNS request for known malware domain www.soanala.com | off | off | off |
1 | 18160 | BLACKLIST | DNS request for known malware domain www.stony-skunk.com | off | off | off |
1 | 18161 | BLACKLIST | DNS request for known malware domain www.street08.com | off | off | off |
1 | 18162 | BLACKLIST | DNS request for known malware domain www.weilingcy.com | off | off | off |
1 | 18163 | BLACKLIST | DNS request for known malware domain www.yisaa.com | off | off | off |
1 | 18164 | BLACKLIST | DNS request for known malware domain www.yx240.com | off | off | off |
1 | 18165 | BLACKLIST | DNS request for known malware domain e.mssm.com | off | off | off |
1 | 18167 | INDICATOR-SHELLCODE | Possible generic javascript heap spray attempt | off | off | off |
1 | 18168 | INDICATOR-SHELLCODE | Possible generic javascript heap spray attempt | off | off | off |
1 | 18184 | BLACKLIST | DNS request for known malware domain dnf.gametime.co.kr | off | off | off |
1 | 18185 | BLACKLIST | DNS request for known malware domain www.dd0415.net | off | off | off |
1 | 18196 | BROWSER-IE | Microsoft Internet Explorer CSS importer use-after-free attempt | off | off | drop |
1 | 18197 | BROWSER-PLUGINS | Microsoft Internet Explorer COleSite ActiveX memory corruption attempt | off | off | drop |
1 | 18198 | BROWSER-PLUGINS | Microsoft Internet Explorer COleSite ActiveX memory corruption attempt | off | off | drop |
1 | 18199 | BROWSER-PLUGINS | Microsoft Internet Explorer COleSite ActiveX memory corruption attempt | off | off | drop |
1 | 18200 | FILE-OFFICE | Microsoft Office .CGM file cell array heap overflow attempt | off | drop | drop |
1 | 18204 | OS-WINDOWS | Microsoft Windows Address Book wab32res.dll dll-load exploit attempt | off | drop | drop |
1 | 18205 | OS-WINDOWS | Microsoft Windows Address Book msoeres32.dll dll-load exploit attempt | off | drop | drop |
1 | 18206 | OS-WINDOWS | Microsoft Windows Address Book wab32res.dll dll-load exploit attempt | off | drop | drop |
1 | 18207 | OS-WINDOWS | Microsoft Windows Address Book msoeres32.dll dll-load exploit attempt | off | drop | drop |
1 | 18212 | FILE-OFFICE | Microsoft Office Publisher tyo.oty field heap overflow attempt | off | off | drop |
1 | 18216 | BROWSER-IE | Microsoft Internet Explorer 6 #default#anim attempt | off | off | drop |
1 | 18217 | BROWSER-IE | Microsoft Internet Explorer select element memory corruption attempt | off | off | drop |
1 | 18218 | BROWSER-IE | Microsoft Internet Explorer time element memory corruption attempt | off | off | drop |
1 | 18219 | FILE-OTHER | Microsoft Windows ATMFD font driver remote code execution attempt | off | off | off |
1 | 18221 | BROWSER-IE | Microsoft Internet Explorer malformed table remote code execution attempt | off | off | drop |
1 | 18233 | FILE-OFFICE | Microsoft Office Publisher Adobe Font Driver code execution attempt | off | off | drop |
1 | 18235 | FILE-OFFICE | Microsoft Office PICT graphics converter memory corruption attempt | off | off | drop |
1 | 18237 | FILE-IMAGE | Microsoft Windows Flashpix graphics filter fpx32.flt remote code execution attempt | off | off | drop |
1 | 18238 | SERVER-WEBAPP | Microsoft Office SharePoint document conversion remote code excution attempt | off | off | off |
1 | 18239 | INDICATOR-OBFUSCATION | known malicious JavaScript decryption routine | off | off | off |
1 | 18240 | BROWSER-IE | Microsoft Internet Explorer CSS importer use-after-free attempt | off | off | drop |
1 | 18241 | BROWSER-PLUGINS | Microsoft Windows WMI administrator tools object viewer ActiveX clsid access | off | off | drop |
1 | 18242 | BROWSER-PLUGINS | Microsoft Windows WMI Administrator Tools Object Viewer ActiveX function call access | off | off | drop |
1 | 18243 | SERVER-IIS | Microsoft Windows 7 IIS7.5 FTPSVC buffer overflow attempt | off | off | drop |
1 | 18244 | FILE-JAVA | Oracle Java browser plugin docbase overflow attempt | off | off | drop |
1 | 18245 | BROWSER-PLUGINS | Oracle Java browser plugin docbase overflow attempt | off | off | drop |
1 | 18265 | FILE-OFFICE | Microsoft Office thumbnail bitmap invalid biClrUsed attempt | off | off | drop |
1 | 18269 | BLACKLIST | DNS request for known malware domain dnf.6bom.com | off | off | off |
1 | 18270 | BLACKLIST | DNS request for known malware domain koonol.com | off | off | off |
1 | 18272 | BLACKLIST | DNS request for known malware domain www.886.com | off | off | off |
1 | 18277 | OS-WINDOWS | Microsoft Windows Vista Backup Tool fveapi.dll dll-load exploit attempt | off | off | drop |
1 | 18278 | OS-WINDOWS | Microsoft Windows Vista Backup Tool fveapi.dll dll-load exploit attempt | off | off | drop |
1 | 18280 | BROWSER-IE | Microsoft Internet Explorer oversize recordset object cache size exploit attempt | off | drop | drop |
1 | 18293 | SERVER-WEBAPP | Secure Backup login.php uname variable based command injection attempt | off | off | off |
1 | 18297 | OS-WINDOWS | Microsoft Windows Comctl32.dll third-party SVG viewer heap overflow attempt | off | off | off |
1 | 18308 | FILE-PDF | Adobe Acrobat Reader ICC mluc integer overflow attempt | off | off | drop |
1 | 18309 | OS-WINDOWS | Microsoft Vector Markup Language fill method overflow attempt | off | off | off |
1 | 18310 | FILE-OFFICE | Microsoft Office RTF parsing remote code execution attempt | off | off | drop |
1 | 18311 | SERVER-WEBAPP | Novell iManager getMultiPartParameters arbitrary file upload attempt | off | off | off |
1 | 18329 | BROWSER-PLUGINS | Microsoft Windows WMI Administrator Tools Object Viewer ActiveX function call access | off | off | drop |
1 | 18331 | FILE-OFFICE | Microsoft Office Visio DXF variable name overflow attempt | off | off | off |
1 | 18335 | OS-WINDOWS | Microsoft Windows MHTML XSS attempt | off | off | off |
1 | 18398 | FILE-OFFICE | Microsoft Office thumbnail bitmap invalid biClrUsed attempt | off | off | drop |
1 | 18399 | FILE-OFFICE | Microsoft Office Excel BRAI record remote code execution attempt | off | off | off |
1 | 18401 | BROWSER-IE | Microsoft Internet Explorer Base64 encoded script overflow attempt | off | off | drop |
1 | 18402 | FILE-OTHER | Microsoft Windows ATMFD Adobe font driver remote code execution attempt | off | drop | drop |
1 | 18403 | BROWSER-IE | Microsoft Internet Explorer Data Source Object memory corruption attempt | off | off | off |
1 | 18404 | BROWSER-IE | Microsoft Internet Explorer document.insertBefore memory corruption attempt | off | drop | drop |
1 | 18416 | FILE-OFFICE | Microsoft Office Visio ORMinfo classes length overflow attempt | off | drop | drop |
1 | 18417 | FILE-OFFICE | Microsoft Office Visio ORMinfo classes length overflow attempt | off | drop | drop |
1 | 18448 | FILE-PDF | Adobe Acrobat Universal 3D stream memory corruption attempt | off | off | drop |
1 | 18450 | FILE-PDF | Adobe Acrobat Reader malformed BMP RGBQUAD attempt | off | drop | drop |
1 | 18451 | FILE-PDF | Adobe Acrobat ICC color integer overflow attempt | off | drop | drop |
1 | 18453 | FILE-PDF | Adobe Acrobat universal 3D format memory corruption attempt | off | off | drop |
1 | 18454 | FILE-PDF | Adobe Acrobat universal 3D format memory corruption attempt | off | drop | drop |
1 | 18457 | FILE-PDF | Adobe Acrobat Reader U3D rgba parsing overflow attempt | off | drop | drop |
1 | 18460 | SERVER-WEBAPP | Symantec Alert Management System pin number buffer overflow attempt | off | drop | drop |
1 | 18461 | SERVER-MAIL | IBM Lotus Domino nrouter.exe iCalendar MAILTO stack buffer overflow attempt | off | off | drop |
1 | 18463 | FILE-OTHER | Microsoft Windows MPEG Layer-3 audio heap corruption attempt | off | off | drop |
1 | 18464 | SERVER-WEBAPP | Adobe ColdFusion locale directory traversal attempt | off | off | off |
1 | 18465 | SERVER-WEBAPP | FreePBX recording interface file upload code execution attempt | off | off | off |
1 | 18482 | BROWSER-IE | Microsoft Internet Explorer History.go method double free corruption attempt | off | off | off |
1 | 18487 | SERVER-OTHER | Ingres Database iidbms heap overflow attempt | off | off | off |
1 | 18494 | OS-WINDOWS | Microsoft product .dll dll-load exploit attempt | off | off | off |
1 | 18495 | OS-WINDOWS | Microsoft product .dll dll-load exploit attempt | off | off | off |
1 | 18496 | OS-WINDOWS | Microsoft Windows Media Player and shell extension ehtrace.dll dll-load exploit attempt | off | drop | drop |
1 | 18497 | OS-WINDOWS | Microsoft Windows Media Player and shell extension ehtrace.dll dll-load exploit attempt | off | drop | drop |
1 | 18498 | FILE-OTHER | Microsoft Media Player dvr-ms file parsing remote code execution attempt | off | drop | drop |
1 | 18499 | OS-WINDOWS | Microsoft Groove mso.dll dll-load exploit attempt | off | off | drop |
1 | 18500 | OS-WINDOWS | Microsoft Groove mso.dll dll-load exploit attempt | off | off | drop |
1 | 18506 | FILE-PDF | Adobe Acrobat Reader CCITT stream compression filter invalid image size heap overflow attempt | off | drop | drop |
1 | 18507 | FILE-PDF | Adobe Acrobat Reader CCITT stream compression filter invalid image size heap overflow attempt | off | drop | drop |
1 | 18510 | FILE-IMAGE | Apple QuickTime FlashPix Movie file integer overflow attempt | off | off | off |
1 | 18513 | SERVER-MYSQL | yaSSL SSL Hello Message Buffer Overflow attempt | off | off | off |
1 | 18514 | FILE-OFFICE | Microsoft Office PowerPoint malformed shapeid arbitrary code execution attempt | off | off | off |
1 | 18515 | FILE-OFFICE | Microsoft Office Visio VSD file icon memory corruption attempt | off | off | off |
1 | 18519 | BROWSER-IE | Microsoft Internet Explorer HTML DOM invalid DHTML element creation attempt | off | off | off |
1 | 18525 | SERVER-OTHER | Lotus Domino LDAP Heap Buffer Overflow Attempt | off | off | drop |
1 | 18535 | FILE-OFFICE | Microsoft Office Word file sprmTSetBrc processing buffer overflow attempt | off | off | off |
1 | 18536 | FILE-OFFICE | OpenOffice.org Microsoft Office Word file processing integer underflow attempt | off | off | drop |
1 | 18537 | FILE-OTHER | OpenOffice.org XPM file processing integer overflow attempt | off | off | drop |
1 | 18538 | FILE-OFFICE | Microsoft Office Excel PtgName invalid index exploit attempt | off | off | drop |
1 | 18539 | BROWSER-IE | Microsoft Internet Explorer event handling remote code execution attempt | off | off | drop |
1 | 18541 | FILE-OFFICE | Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt 3 | off | off | drop |
1 | 18542 | BROWSER-PLUGINS | Microsoft Windows Media Player ActiveX unknow compression algorithm use arbitrary code execution attempt | off | off | drop |
1 | 18543 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 18544 | FILE-FLASH | embedded Shockwave dropper in email attachment | off | drop | drop |
1 | 18545 | FILE-OFFICE | Microsoft Office Excel with embedded Flash file transfer | off | off | off |
1 | 18546 | FILE-OFFICE | Microsoft Office Word with embedded Flash file transfer | off | drop | drop |
1 | 18547 | FILE-OFFICE | Microsoft Office PowerPoint with embedded Flash file transfer | off | off | off |
1 | 18548 | FILE-OFFICE | Microsoft Office Excel with embedded Flash file attachment | off | off | off |
1 | 18549 | FILE-OFFICE | Microsoft Office Word with embedded Flash file attachment | off | off | off |
1 | 18555 | SERVER-OTHER | VERITAS NetBackup java authentication service format string exploit attempt | off | off | off |
1 | 18556 | SERVER-WEBAPP | Symantec IM manager IMAdminReportTrendFormRun.asp sql injection attempt | off | off | off |
1 | 18557 | PROTOCOL-RPC | IBM Informix Dynamic Server librpc.dll buffer overflow attempt | off | off | drop |
1 | 18558 | PROTOCOL-RPC | IBM Informix Dynamic Server librpc.dll buffer overflow attempt | off | off | drop |
1 | 18559 | SERVER-WEBAPP | HP OpenView Performance Insight Server backdoor account code execution attempt | drop | drop | drop |
1 | 18560 | SERVER-WEBAPP | HP OpenView Performance Insight Server backdoor account code execution attempt | drop | drop | drop |
1 | 18561 | FILE-IMAGE | Apple QuickTime PICT file overread buffer overflow attempt | off | off | off |
1 | 18575 | PROTOCOL-FTP | Computer Associates eTrust Secure Content Manager LIST stack overflow attempt | off | off | off |
1 | 18578 | BROWSER-PLUGINS | RealNetworks RealPlayer RMOC3260.DLL cdda URI overflow attempt | off | off | drop |
1 | 18583 | FILE-IMAGE | Microsoft Windows wmf integer overflow attempt | off | off | off |
1 | 18585 | FILE-PDF | Adobe Acrobat Reader malformed TIFF remote code execution attempt | off | off | drop |
1 | 18587 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 267 buffer overflow attempt | off | off | off |
1 | 18588 | PROTOCOL-FTP | Ipswitch Ws_ftp XCRC overflow attempt | off | off | off |
1 | 18589 | NETBIOS | Novell Client NetIdentity Agent remote arbitrary pointer dereference code execution attempt | off | off | off |
1 | 18590 | OS-WINDOWS | Outlook Express WAB file parsing buffer overflow attempt | off | off | off |
1 | 18592 | BROWSER-PLUGINS | Yahoo Music Jukebox ActiveX exploit | off | off | off |
1 | 18594 | BROWSER-PLUGINS | Trend Micro Web Deployment ActiveX clsid access | off | off | off |
1 | 18595 | BROWSER-PLUGINS | Trend Micro Web Deployment ActiveX clsid access | off | off | off |
1 | 18596 | FILE-PDF | Adobe Acrobat Reader util.printf buffer overflow attempt | off | off | off |
1 | 18597 | BROWSER-OTHER | Opera file URI handling buffer overflow | off | off | off |
1 | 18599 | FILE-IMAGE | Apple QuickTime PictureViewer buffer overflow attempt | off | off | off |
1 | 18601 | BROWSER-PLUGINS | Microsoft Common Controls Animation Object ActiveX clsid access | off | off | off |
1 | 18611 | SERVER-WEBAPP | Oracle Java Web Server WebDAV Stack Buffer Overflow attempt | off | off | drop |
1 | 18612 | SERVER-WEBAPP | Oracle Java Web Server WebDAV Stack Buffer Overflow attempt | off | off | drop |
1 | 18613 | SERVER-WEBAPP | Oracle Java Web Server WebDAV Stack Buffer Overflow attempt | off | off | drop |
1 | 18615 | FILE-OFFICE | Microsoft Works 4.x converter font name buffer overflow attempt | off | off | off |
1 | 18632 | FILE-OFFICE | Microsoft Office Excel malformed Label record exploit attempt | off | drop | drop |
1 | 18638 | FILE-OFFICE | Microsoft Office Excel drawing layer use after free attempt | off | drop | drop |
1 | 18643 | FILE-OFFICE | Microsoft Office Word Converter sprmTTextFflow overflow attempt | off | drop | drop |
1 | 18648 | PROTOCOL-SCADA | IGSS IGSSDataServer.exe file upload/download attempt | off | off | drop |
1 | 18649 | PROTOCOL-SCADA | IGSS IGSSDataServer.exe file operation overflow attempt | off | off | drop |
1 | 18651 | PROTOCOL-SCADA | IGSS IGSSDataServer.exe report template overflow attempt | off | off | drop |
1 | 18654 | PROTOCOL-SCADA | IGSS IGSSDataServer.exe format string attempt | off | off | drop |
1 | 18655 | OS-WINDOWS | Microsoft Windows LLMNR invalid reverse name lookup stack corruption attempt | off | off | off |
1 | 18656 | PROTOCOL-SCADA | IGSS IGSSDataServer.exe strep overflow attempt | off | off | drop |
1 | 18657 | PROTOCOL-SCADA | IGSS dc.exe file execution directory traversal attempt | off | off | drop |
1 | 18659 | PROTOCOL-SCADA | RealWin 2.1 SCPC_INITIALIZE overflow attempt | off | off | drop |
1 | 18668 | BROWSER-PLUGINS | Microsoft Windows Messenger ActiveX clsid access | off | drop | drop |
1 | 18670 | BROWSER-IE | Microsoft Internet Explorer object management memory corruption attempt | off | drop | drop |
1 | 18671 | BROWSER-IE | Microsoft Internet Explorer object management memory corruption attempt | off | drop | drop |
1 | 18679 | SERVER-OTHER | Oracle Java Applet2ClassLoader Remote Code Execution | drop | drop | drop |
1 | 18680 | FILE-OFFICE | Microsoft Office RTF malformed pfragments field | off | off | drop |
1 | 18681 | FILE-PDF | transfer of a PDF with embedded JavaScript - JavaScript object detected | off | off | off |
1 | 18682 | FILE-PDF | transfer of a PDF with OpenAction object attempt | off | off | off |
1 | 18710 | SERVER-OTHER | McAfee ePolicy Orchestrator Framework Services buffer overflow attempt | off | off | off |
1 | 18740 | FILE-OFFICE | Microsoft Office Excel sheet object type confusion exploit attempt | off | off | drop |
1 | 18753 | SERVER-OTHER | Zend Server Java Bridge remote code execution attempt | off | off | off |
1 | 18755 | FILE-OFFICE | Microsoft Office Visio Data Type Memory Corruption | off | drop | drop |
1 | 18756 | INDICATOR-COMPROMISE | Microsoft cmd.exe banner Windows 7/Server 2008R2 | off | off | off |
1 | 18757 | INDICATOR-COMPROMISE | Microsoft cmd.exe banner Windows Vista | off | off | off |
1 | 18759 | SERVER-WEBAPP | HP OpenView Network Node Manager ovwebsnmpsrv.exe displayWidth buffer overflow attempt - POST | drop | drop | drop |
1 | 18760 | SERVER-WEBAPP | HP OpenView Network Node Manager ovwebsnmpsrv.exe displayWidth buffer overflow attempt - GET | drop | drop | drop |
1 | 18764 | SERVER-WEBAPP | HP OpenView Network Node Manager nnmRptConfig.exe multiple parameters buffer overflow attempt | drop | drop | drop |
1 | 18766 | SERVER-OTHER | OpenSSL CMS structure OriginatorInfo memory corruption attempt | off | off | off |
1 | 18767 | PROTOCOL-TFTP | Multiple TFTP product buffer overflow attempt | off | off | off |
1 | 18768 | SERVER-MAIL | Novell GroupWise Internet Agent RRULE parsing buffer overflow attempt | off | drop | drop |
1 | 18770 | BROWSER-WEBKIT | Apple Safari WebKit range object remote code execution attempt | off | off | off |
1 | 18776 | FILE-OTHER | Adobe Shockwave Director pamm chunk memory corruption attempt | off | off | drop |
1 | 18790 | SERVER-OTHER | Novell ZENworks Handheld Management ZfHIPCND.exe overflow attempt | off | off | drop |
1 | 18791 | SERVER-OTHER | Novell ZENworks Configuration Management Preboot service code overflow attempt | off | off | off |
1 | 18792 | SERVER-WEBAPP | Novell ZENworks Configuration Management UploadServlet code execution attempt | off | off | off |
1 | 18793 | SERVER-WEBAPP | Novell ZENworks Configuration Management UploadServlet code execution attempt | off | off | off |
1 | 18794 | SERVER-WEBAPP | RedHat JBoss Enterprise Application Platform JMX authentication bypass attempt | off | off | off |
1 | 18795 | SERVER-WEBAPP | HP OpenView Network Node Manager ovet_demandpoll.exe format string execution attempt | off | off | drop |
1 | 18796 | SERVER-WEBAPP | Novell iManager ClassName handling overflow attempt | off | off | drop |
1 | 18797 | SERVER-WEBAPP | Oracle Secure Backup Administration property_box.php other variable command execution attempt | off | off | drop |
1 | 18801 | FILE-PDF | Adobe Acrobat Reader JpxDecode invalid crgn memory corruption attempt | off | off | drop |
1 | 18802 | SERVER-WEBAPP | HP Power Manager formExportDataLogs directory traversal attempt | off | off | drop |
1 | 18803 | SERVER-WEBAPP | Oracle Java Runtime CMM readMabCurveData buffer overflow attempt | off | off | off |
1 | 18804 | SERVER-WEBAPP | OpenLDAP Modrdn utf-8 string code execution attempt | off | off | off |
1 | 18806 | FILE-OFFICE | Microsoft Office Excel RealTimeData record exploit attempt | off | off | drop |
1 | 18808 | SERVER-MAIL | Ipswitch IMail Server List Mailer Reply-To address buffer overflow attempt | off | off | off |
1 | 18809 | BROWSER-FIREFOX | Mozilla EnsureCachedAttrParamArrays integer overflow attempt | off | off | off |
1 | 18901 | SERVER-OTHER | MIT Kerberos KDC Ticket validation double free memory corruption attempt | off | off | off |
1 | 18902 | SERVER-WEBAPP | Novell Teaming ajaxUploadImageFile remote code execution attempt | off | off | off |
1 | 18903 | BROWSER-WEBKIT | Apple Safari WebKit Rendering Counter Code Execution | off | off | drop |
1 | 18926 | PROTOCOL-SNMP | Multiple vendors AgentX receive_agentx integer overflow attempt | off | off | drop |
1 | 18928 | FILE-MULTIMEDIA | Apple QuickTime streaming debug error logging buffer overflow attempt | off | off | drop |
1 | 18929 | SERVER-ORACLE | Oracle Secure Backup Administration objectname variable command injection attempt | off | off | drop |
1 | 18930 | SERVER-WEBAPP | HP OpenView Network Node Manager nnmRptConfig.exe Template format string code execution attempt | drop | drop | drop |
1 | 18948 | FILE-OFFICE | Microsoft Office PowerPoint converter bad indirection remote code execution attempt | off | off | drop |
1 | 18951 | BROWSER-IE | Microsoft Internet Explorer CTableLayout memory corruption attempt | off | off | off |
1 | 18952 | FILE-OTHER | Microsoft Windows uniscribe fonts parsing memory corruption attempt | off | off | drop |
1 | 18953 | FILE-OTHER | rich text format unexpected field type memory corruption attempt | off | off | drop |
1 | 18954 | FILE-OTHER | rich text format unexpected field type memory corruption attempt | off | off | drop |
1 | 18957 | BROWSER-WEBKIT | Apple Safari Webkit attribute child removal code execution attempt | off | off | drop |
1 | 18958 | BROWSER-WEBKIT | Apple Safari Webkit attribute child removal code execution attempt | off | off | drop |
1 | 18959 | SERVER-WEBAPP | VMware SpringSource Spring Framework class.classloader remote code execution attempt | off | off | off |
1 | 18960 | SERVER-WEBAPP | Novell GroupWise agents HTTP request remote code execution attempt | drop | drop | drop |
1 | 18972 | SERVER-ORACLE | Oracle Secure Backup Administration selector variable command injection attempt | off | off | drop |
1 | 18973 | BROWSER-WEBKIT | Apple Safari Webkit button first-letter style rendering code execution attempt | off | off | drop |
1 | 18974 | BROWSER-PLUGINS | SAP Crystal Reports PrintControl.dll ActiveX function call attempt | off | off | drop |
1 | 18975 | BROWSER-PLUGINS | SAP Crystal Reports PrintControl.dll ActiveX function call access | off | off | drop |
1 | 18986 | FILE-PDF | Adobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 18987 | FILE-PDF | Adobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 18988 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 18989 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 18990 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 18991 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 18995 | BROWSER-WEBKIT | Apple Safari Webkit removeAllRanges use-after-free attempt | off | off | off |
1 | 18996 | SERVER-ORACLE | DBMS_JAVA.SET_OUTPUT_TO_JAVA privilege escalation attempt | off | off | off |
1 | 18998 | SERVER-WEBAPP | HP OpenView NNM ovwebsnmpsrv.exe command line argument buffer overflow attempt | off | drop | drop |
1 | 18999 | SERVER-WEBAPP | HP OpenView NNM webappmon.exe buffer overflow attempt | off | off | drop |
1 | 19002 | FILE-FLASH | RealNetworks RealPlayer FLV parsing two integer overflow vulnerabilities | off | off | drop |
1 | 19003 | BROWSER-WEBKIT | Apple Safari Webkit run-in use-after-free attempt | off | off | drop |
1 | 19004 | BROWSER-WEBKIT | Apple Safari Webkit run-in use-after-free attempt | off | off | drop |
1 | 19005 | BROWSER-CHROME | Apple Safari/Google Chrome Webkit memory corruption attempt | off | off | off |
1 | 19006 | SERVER-OTHER | HP Data Protector Express DtbClsLogin buffer overflow attempt | off | off | off |
1 | 19007 | SERVER-SAMBA | Samba SID parsing overflow attempt | off | off | off |
1 | 19008 | BROWSER-WEBKIT | Apple Safari Webkit floating point conversion memory corruption attempt | off | off | drop |
1 | 19009 | BROWSER-WEBKIT | Apple Safari WebKit menu onchange memory corruption attempt | off | off | off |
1 | 19010 | BROWSER-WEBKIT | Apple Safari WebKit menu onchange memory corruption attempt | off | off | off |
1 | 19011 | FILE-OTHER | Adobe Shockwave Player Lnam chunk processing buffer overflow attempt | off | off | drop |
1 | 19012 | FILE-OTHER | Adobe Shockwave Player Lnam chunk processing buffer overflow attempt | off | off | drop |
1 | 19013 | PROTOCOL-TFTP | HP Intelligent Management Center TFTP server MODE remote code execution attempt - WRQ | drop | drop | drop |
1 | 19063 | FILE-MULTIMEDIA | Microsoft Windows Movie Maker string size overflow attempt | off | off | drop |
1 | 19064 | FILE-OTHER | Microsoft OpenType font index remote code execution attempt | off | off | drop |
1 | 19065 | FILE-OFFICE | Microsoft Office Excel with embedded Flash file attachment attempt | off | off | off |
1 | 19066 | FILE-OFFICE | Microsoft Office Excel with embedded Flash file attachment attempt | off | off | off |
1 | 19071 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 19072 | SERVER-OTHER | CA Discovery Service Overflow Attempt | off | off | off |
1 | 19078 | BROWSER-FIREFOX | Mozilla Firefox appendChild use-after-free attempt | off | off | drop |
1 | 19080 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 19082 | FILE-PDF | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 19083 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 19084 | BROWSER-IE | Microsoft Internet Explorer CSS style memory corruption attempt | off | off | drop |
1 | 19085 | BROWSER-PLUGINS | LEADTOOLS Raster Twain LtocxTwainu.dll ActiveX clsid access | off | off | off |
1 | 19086 | BROWSER-PLUGINS | LEADTOOLS Raster Twain LtocxTwainu.dll ActiveX function call | off | off | off |
1 | 19091 | SERVER-OTHER | OpenSSL ssl3_get_key_exchange use-after-free attempt | off | off | off |
1 | 19092 | SERVER-OTHER | OpenSSL ssl3_get_key_exchange use-after-free attempt | off | off | off |
1 | 19095 | BROWSER-WEBKIT | Apple Safari Webkit CSS Charset Text transformation code execution attempt | off | off | drop |
1 | 19096 | BROWSER-WEBKIT | Apple Safari Webkit CSS Charset Text transformation code execution attempt | off | off | drop |
1 | 19097 | BROWSER-WEBKIT | Apple Safari Webkit ContentEditable code execution attempt | off | off | drop |
1 | 19098 | BROWSER-WEBKIT | Apple Safari Webkit ContentEditable code exeuction attempt | off | off | drop |
1 | 19099 | BROWSER-WEBKIT | Apple Safari CSS font format corruption attempt | off | off | drop |
1 | 19100 | FILE-JAVA | Oracle Java Soundbank resource name overflow attempt | off | off | off |
1 | 19102 | BROWSER-PLUGINS | Symantec CLIProxy.dll ActiveX clsid access | off | off | drop |
1 | 19103 | BROWSER-PLUGINS | Symantec CLIProxy.dll ActiveX function call access | off | off | drop |
1 | 19104 | SERVER-OTHER | HP OpenView Storage Data Protector Cell Manager heap overflow attempt | off | off | off |
1 | 19105 | SERVER-OTHER | HP Data Protector Manager MMD service buffer overflow attempt | off | off | off |
1 | 19107 | SERVER-APACHE | Apache mod_isapi dangling pointer code execution attempt | off | off | drop |
1 | 19108 | BROWSER-PLUGINS | SonicWall Aventail EPInstaller ActiveX clsid access | off | off | off |
1 | 19109 | BROWSER-PLUGINS | SonicWall Aventail EPInstaller ActiveX function call access | off | off | off |
1 | 19112 | FILE-OTHER | Adobe Shockwave 3D stucture heap overflow | off | off | drop |
1 | 19113 | FILE-OTHER | Adobe Shockwave 3D structure opcode 81 overflow attempt | off | off | drop |
1 | 19114 | FILE-OTHER | Adobe Shockwave 3D structure opcode 45 overflow attempt | off | off | drop |
1 | 19115 | FILE-OTHER | Adobe Shockwave 3D structure opcode 89 overflow attempt | off | off | drop |
1 | 19116 | SERVER-OTHER | IBM Tivoli Storage Manager FastBack mount service code execution attempt | off | off | off |
1 | 19117 | FILE-PDF | Adobe Acrobat Reader malformed U3D integer overflow | off | off | drop |
1 | 19118 | FILE-PDF | Adobe Acrobat Reader script injection vulnerability | off | off | drop |
1 | 19119 | OS-WINDOWS | Microsoft Windows ATMFD font driver remote code execution attempt | off | off | off |
1 | 19120 | SERVER-OTHER | IBM Informix DBINFO stack buffer overflow | off | off | drop |
1 | 19121 | SERVER-OTHER | IBM Informix EXPLAIN stack buffer overflow attempt | off | off | drop |
1 | 19124 | SERVER-APACHE | Apache mod_isapi dangling pointer exploit attempt | off | off | drop |
1 | 19126 | FILE-MULTIMEDIA | RealNetworks RealPlayer IVR handling heap buffer overflow attempt | off | drop | drop |
1 | 19127 | FILE-MULTIMEDIA | RealNetworks RealPlayer IVR handling heap buffer overflow attempt | off | drop | drop |
1 | 19130 | FILE-IMAGE | Microsoft Windows MSPaint jpeg with malformed SOFx field exploit attempt | off | off | drop |
1 | 19131 | FILE-OFFICE | Microsoft Office Excel RTD buffer overflow attempt | off | off | drop |
1 | 19132 | FILE-OFFICE | Microsoft Office Excel RTD buffer overflow attempt | off | off | drop |
1 | 19133 | FILE-OFFICE | Microsoft Office Excel EntExU2 write access violation attempt | off | off | drop |
1 | 19134 | FILE-OFFICE | Microsoft Office Excel PtgExtraArray data parsing vulnerability exploit attempt | off | off | drop |
1 | 19136 | SERVER-WEBAPP | CA XOsoft Multiple Products entry_point.aspx buffer overflow attempt | off | off | drop |
1 | 19137 | SERVER-WEBAPP | HP OpenView NNM getnnmdata.exe CGI ICount parameter buffer overflow attempt | off | off | drop |
1 | 19138 | SERVER-WEBAPP | HP OpenView NNM getnnmdata.exe CGI hostname parameter buffer overflow attempt | off | off | drop |
1 | 19139 | SERVER-WEBAPP | HP OpenView NNM getnnmdata.exe CGI MaxAge parameter buffer overflow attempt | off | off | drop |
1 | 19140 | SERVER-WEBAPP | HP OpenView NNM snmpviewer.exe CGI parameter buffer overflow attempt | off | off | drop |
1 | 19141 | FILE-OFFICE | Microsoft Access Wizard control memory corruption ActiveX clsid access | off | off | drop |
1 | 19142 | SERVER-WEBAPP | Symantec IM Manager IMAdminScheduleReport.asp SQL injection attempt | off | off | off |
1 | 19143 | FILE-MULTIMEDIA | Microsoft Windows Media Player JPG header record mismatch memory corruption attempt | off | off | drop |
1 | 19144 | FILE-OTHER | Microsoft Windows MPEG Layer-3 audio heap corruption attempt | off | off | drop |
1 | 19145 | FILE-FLASH | Adobe Flash Player newfunction memory corruption attempt | off | off | drop |
1 | 19146 | FILE-MULTIMEDIA | Microsoft Windows DirectX quartz.dll MJPEG content processing memory corruption attempt | off | off | drop |
1 | 19147 | BROWSER-IE | Microsoft Internet Explorer outerHTML against incomplete element heap corruption attempt | off | off | drop |
1 | 19148 | FILE-MULTIMEDIA | Adobe Flash Player SWF file MP4 data parsing memory corruption attempt | off | off | drop |
1 | 19149 | BROWSER-IE | Microsoft Internet Explorer malformed table tag memory corruption attempt | off | off | drop |
1 | 19150 | BROWSER-IE | Microsoft Internet Explorer malformed table tag memory corruption attempt | off | off | drop |
1 | 19151 | BROWSER-PLUGINS | Trend Micro HouseCall ActiveX clsid access | off | off | drop |
1 | 19152 | BROWSER-PLUGINS | Trend Micro HouseCall ActiveX function call access | off | off | drop |
1 | 19153 | FILE-OFFICE | Microsoft Office Word malformed index code execution attempt | off | off | drop |
1 | 19154 | FILE-OFFICE | Microsoft Office Excel PtgExtraArray parsing attempt | off | off | drop |
1 | 19155 | SERVER-WEBAPP | HP Data Protector Media Operations SignInName Parameter overflow attempt | off | off | off |
1 | 19156 | FILE-OFFICE | Microsoft Office .CGM file cell array heap overflow attempt | off | drop | drop |
1 | 19158 | POLICY-OTHER | HP Universal CMDB server axis2 service upload attempt | off | off | off |
1 | 19160 | SERVER-OTHER | NetSupport Manager client buffer overflow attempt | off | off | off |
1 | 19161 | SERVER-OTHER | NetSupport Manager client buffer overflow attempt | off | off | off |
1 | 19162 | SERVER-ORACLE | get_domain_index_metadata privilege escalation attempt | off | off | off |
1 | 19163 | SERVER-ORACLE | get_v2_domain_index_tables privilege escalation attempt | off | off | off |
1 | 19167 | PROTOCOL-VOIP | Digium Asterisk UDPTL processing overflow attempt | off | off | off |
1 | 19168 | SERVER-WEBAPP | Oracle GoldenGate Veridata Server soap request overflow attempt | off | off | off |
1 | 19169 | FILE-MULTIMEDIA | RealNetworks RealPlayer vidplin.dll avi header parsing execution attempt | off | drop | drop |
1 | 19170 | FILE-OTHER | Microsoft Windows .NET Framework XAML browser applications stack corruption | off | drop | drop |
1 | 19171 | BROWSER-IE | Microsoft Internet Explorer 8 ieshims.dll dll-load exploit attempt | off | off | off |
1 | 19172 | BROWSER-IE | Microsoft Internet Explorer 8 ieshims.dll dll-load exploit attempt | off | off | off |
1 | 19173 | PROTOCOL-RPC | CDE Calendar Manager service memory corruption attempt | drop | drop | drop |
1 | 19174 | OS-WINDOWS | Microsoft Windows Vista feed headlines cross-site scripting attack attempt | off | off | off |
1 | 19180 | FILE-OFFICE | Microsoft Office Excel pivot item index boundary corruption attempt | off | off | drop |
1 | 19181 | BROWSER-IE | Microsoft Internet Explorer iframe uninitialized memory corruption attempt | off | off | drop |
1 | 19182 | SERVER-OTHER | strongSwan Certificate and Identification payload overflow attempt | off | off | off |
1 | 19183 | SERVER-IIS | Microsoft Windows IIS FastCGI request header buffer overflow attempt | off | off | drop |
1 | 19184 | OS-WINDOWS | Microsoft Windows OLEAUT32.DLL malicious WMF file remote code execution attempt | off | drop | drop |
1 | 19186 | OS-WINDOWS | Microsoft Certification service XSS attempt | off | off | off |
1 | 19193 | BROWSER-PLUGINS | Oracle Document Capture ActiveX clsid access | off | drop | drop |
1 | 19194 | BROWSER-PLUGINS | Oracle Document Capture ActiveX function call access | off | drop | drop |
1 | 19195 | BROWSER-PLUGINS | Oracle Document Capture ActiveX function call access | off | drop | drop |
1 | 19196 | OS-WINDOWS | Microsoft Windows ATMFD Adobe font driver remote code execution attempt | off | drop | drop |
1 | 19197 | BROWSER-PLUGINS | CA Internet Security Suite XMLSecDB ActiveX clsid access | off | off | drop |
1 | 19198 | BROWSER-PLUGINS | CA Internet Security Suite XMLSecDB ActiveX function call access | off | off | drop |
1 | 19201 | SQL | waitfor delay function - possible SQL injection attempt | off | off | off |
1 | 19202 | SQL | declare varchar - possible SQL injection attempt | off | off | off |
1 | 19203 | BROWSER-IE | Microsoft Internet Explorer MsgBox arbitrary code execution attempt | off | off | off |
1 | 19204 | BROWSER-IE | Microsoft Internet Explorer MsgBox arbitrary code execution attempt | off | off | off |
1 | 19206 | SERVER-OTHER | IBM DB2 Universal Database receiveDASMessage buffer overflow attempt | off | off | off |
1 | 19207 | SERVER-OTHER | Symantec Alert Management System AMSSendAlertAck stack buffer overflow attempt | off | off | off |
1 | 19208 | SERVER-OTHER | Citrix Provisioning Services streamprocess.exe buffer overflow attempt | off | off | off |
1 | 19209 | SERVER-WEBAPP | Symantec Alert Management System modem string buffer overflow attempt | off | drop | drop |
1 | 19210 | SERVER-OTHER | IBM Informix Dynamic Server set environment buffer overflow attempt | off | drop | drop |
1 | 19213 | SERVER-MAIL | Ipswitch IMail Server Mailing List Message Subject buffer overflow | off | off | off |
1 | 19216 | BROWSER-CHROME | Google Chrome Uninitialized bug_report Pointer Code Execution | drop | drop | drop |
1 | 19217 | BROWSER-CHROME | Google Chrome Uninitialized bug_report Pointer Code Execution | drop | drop | drop |
1 | 19219 | FILE-OTHER | Microsoft Windows Fax Services Cover Page Editor Double Free Memory Corruption | off | off | drop |
1 | 19220 | FILE-OTHER | Microsoft Windows Fax Services Cover Page Editor Double Free Memory Corruption | off | off | drop |
1 | 19221 | OS-WINDOWS | SMB-DS Trans2 Distributed File System response PathConsumed integer overflow attempt | drop | drop | drop |
1 | 19222 | FILE-OFFICE | Microsoft Office Excel ObjBiff validation exploit attempt | off | drop | drop |
1 | 19223 | SERVER-OTHER | SAP Crystal Reports 2008 directory traversal attempt | off | off | off |
1 | 19225 | FILE-OFFICE | Microsoft Office Excel SerAuxTrend biff record corruption attempt | off | off | drop |
1 | 19226 | FILE-OTHER | Cisco Webex Player .wrf stack buffer overflow | off | drop | drop |
1 | 19227 | FILE-OFFICE | Microsoft Office Excel Scenario heap memory overflow | off | drop | drop |
1 | 19228 | SERVER-WEBAPP | Oracle Secure Backup Administration preauth variable command injection attempt | off | off | drop |
1 | 19237 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt | off | drop | drop |
1 | 19241 | BROWSER-IE | Microsoft Windows Vector Markup Language imagedata page deconstruction attempt | off | off | off |
1 | 19242 | BROWSER-IE | Microsoft Windows Vector Markup Language imagedata page deconstruction attempt | off | off | off |
1 | 19243 | BROWSER-IE | Microsoft Internet Explorer layout-grid-char value exploit attempt | off | drop | drop |
1 | 19245 | BROWSER-IE | Microsoft Internet Explorer redirect to cdl protocol attempt | off | drop | drop |
1 | 19246 | BROWSER-IE | Microsoft Internet Explorer CSS expression defined to empty selection attempt | off | drop | drop |
1 | 19258 | FILE-OFFICE | Microsoft Office Excel SxView record memory pointer corruption attempt | off | off | drop |
1 | 19259 | FILE-OFFICE | Microsoft Office Excel WOpt record memory corruption attempt | off | off | drop |
1 | 19260 | FILE-OFFICE | Microsoft Office Excel malformed MsoDrawingObject record attempt | off | off | drop |
1 | 19262 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption | drop | drop | drop |
1 | 19263 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption | drop | drop | drop |
1 | 19264 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption | drop | drop | drop |
1 | 19265 | BROWSER-IE | Microsoft Internet Explorer layout-grid-char value exploit attempt | off | drop | drop |
1 | 19266 | BROWSER-IE | Microsoft Internet Explorer layout-grid-char value exploit attempt | off | drop | drop |
1 | 19268 | FILE-PDF | attempted download of a PDF with embedded Flash | off | off | drop |
1 | 19269 | FILE-PDF | attempted download of a PDF with embedded Flash | off | off | drop |
1 | 19281 | INDICATOR-SHELLCODE | x86 OS agnostic single-byte xor countodwn encoder | off | off | off |
1 | 19282 | INDICATOR-SHELLCODE | x86 OS agnostic cpuid-based context keyed encoder | off | off | off |
1 | 19283 | INDICATOR-SHELLCODE | x86 OS agnostic stat-based context keyed encoder | off | off | off |
1 | 19284 | INDICATOR-SHELLCODE | x86 OS agnostic time-based context keyed encoder | off | off | off |
1 | 19285 | INDICATOR-SHELLCODE | x86 OS agnostic non-alpha/non-upper encoder | off | off | off |
1 | 19286 | INDICATOR-SHELLCODE | x86 OS agnostic unicode uppercase encoder | off | off | off |
1 | 19287 | INDICATOR-SHELLCODE | x86 OS agnostic unicode mixed encoder | off | off | off |
1 | 19288 | INDICATOR-SHELLCODE | x86 OS agnostic unicode tolower encoder | off | off | off |
1 | 19290 | FILE-OTHER | Microsoft LNK shortcut arbitary dll load attempt | off | off | drop |
1 | 19294 | FILE-OFFICE | Microsoft Office Excel Chart Sheet Substream memory corruption attempt | off | off | drop |
1 | 19295 | FILE-OFFICE | Microsoft Office Word HTML linked objects memory corruption attempt | off | off | drop |
1 | 19296 | FILE-OFFICE | Microsoft Office PowerPoint improper filename remote code execution attempt | off | off | drop |
1 | 19303 | FILE-OFFICE | Microsoft Office PowerPoint out of bounds value remote code execution attempt | off | off | drop |
1 | 19304 | BROWSER-PLUGINS | Oracle EasyMail ActiveX clsid access | off | off | off |
1 | 19305 | BROWSER-PLUGINS | Oracle EasyMail ActiveX function call access | off | off | off |
1 | 19306 | FILE-OFFICE | Microsoft Office Publisher pubconv.dll corruption attempt | off | off | drop |
1 | 19308 | FILE-OTHER | Microsoft Windows embedded OpenType EOT font integer overflow attempt | off | off | drop |
1 | 19314 | OS-WINDOWS | Groove GroovePerfmon.dll dll-load exploit attempt | off | off | drop |
1 | 19315 | OS-WINDOWS | Microsoft Groove GroovePerfmon.dll dll-load exploit attempt | off | off | drop |
1 | 19317 | FILE-OFFICE | Microsoft Office Word sprmTDiagLine80 record parsing stack buffer overflow attempt | off | off | alert |
1 | 19320 | FILE-MULTIMEDIA | Microsoft Windows AVI Header insufficient data corruption attempt | off | off | off |
1 | 19321 | BROWSER-FIREFOX | Mozilla Products nsCSSValue Array Index Integer Overflow | off | off | drop |
1 | 19403 | FILE-MULTIMEDIA | Cinepak Codec VIDC decompression remote code execution attempt | off | off | drop |
1 | 19405 | FILE-OFFICE | Microsoft Office Outlook SMB attach by reference code execution attempt | off | off | drop |
1 | 19406 | FILE-OFFICE | Microsoft Office Outlook SMB attach by reference code execution attempt | off | off | drop |
1 | 19407 | FILE-OFFICE | Microsoft Office Outlook SMB attach by reference code execution attempt | off | off | drop |
1 | 19408 | FILE-FLASH | Adobe Flash Player newfunction memory corruption exploit attempt | off | off | drop |
1 | 19411 | BROWSER-IE | Microsoft Internet Explorer Cross-Domain information disclosure attempt | off | off | off |
1 | 19412 | FILE-OFFICE | Microsoft Office Excel RealTimeData record parsing memory corruption | off | off | drop |
1 | 19413 | FILE-OFFICE | Microsoft Office Publisher 2007 and earlier stack buffer overflow attempt | off | off | drop |
1 | 19414 | FILE-OFFICE | Microsoft Office Publisher 2007 and earlier stack buffer overflow attempt | off | off | drop |
1 | 19420 | FILE-MULTIMEDIA | VideoLAN VLC Media Player Subtitle StripTags Heap Buffer Overflow | off | off | off |
1 | 19421 | FILE-MULTIMEDIA | VideoLAN VLC Media Player Subtitle StripTags Heap Buffer Overflow | off | off | off |
1 | 19431 | FILE-MULTIMEDIA | Nullsoft Winamp MIDI Timestamp buffer overflow attempt | off | off | off |
1 | 19432 | FILE-MULTIMEDIA | Nullsoft Winamp MIDI Timestamp buffer overflow attempt | off | off | off |
1 | 19436 | BROWSER-IE | Microsoft Internet Explorer CStyleSheetRule array memory corruption attempt | off | off | drop |
1 | 19438 | SQL | url ending in comment characters - possible sql injection attempt | off | drop | drop |
1 | 19441 | SERVER-WEBAPP | Oracle Virtual Server Agent command injection attempt | off | off | drop |
1 | 19442 | FILE-OFFICE | Microsoft Office embedded Office Art drawings execution attempt | off | off | drop |
1 | 19444 | FILE-MULTIMEDIA | Microsoft Windows Media sample duration header RCE attempt | off | off | off |
1 | 19445 | FILE-MULTIMEDIA | Microsoft Windows Media Timecode header RCE attempt | off | off | off |
1 | 19446 | FILE-MULTIMEDIA | Microsoft Windows Media file name header RCE attempt | off | off | off |
1 | 19447 | FILE-MULTIMEDIA | Microsoft Windows Media content type header RCE attempt | off | off | off |
1 | 19448 | FILE-MULTIMEDIA | Microsoft Windows Media pixel aspect ratio header RCE attempt | off | off | off |
1 | 19449 | FILE-MULTIMEDIA | Microsoft Windows Media encryption sample ID header RCE attempt | off | off | off |
1 | 19450 | FILE-MULTIMEDIA | Microsoft Windows Media encryption sample ID header RCE attempt | off | off | off |
1 | 19451 | SERVER-OTHER | Oracle VM server agent command injection | off | off | drop |
1 | 19452 | SERVER-OTHER | Oracle VM server agent command injection | off | off | drop |
1 | 19458 | FILE-OFFICE | Microsoft Office Word sprmCMajority record buffer overflow attempt | off | off | drop |
1 | 19459 | FILE-OFFICE | Microsoft Office Word sprmCMajority record buffer overflow attempt | off | off | drop |
1 | 19552 | FILE-OFFICE | Microsoft Office Excel format record code execution attempt | off | off | off |
1 | 19600 | SERVER-ORACLE | Warehouse builder WE_OLAP_AW_SET_SOLVE_ID SQL Injection attempt | off | off | off |
1 | 19645 | SERVER-WEBAPP | cross-site scripting attempt via form data attempt | off | off | off |
1 | 19649 | SERVER-OTHER | HP Intelligent Management Center dbman buffer overflow attempt | drop | drop | drop |
1 | 19650 | BROWSER-PLUGINS | Cisco AnyConnect ActiveX clsid access | off | off | off |
1 | 19668 | BROWSER-IE | Microsoft Internet Explorer telnet.exe file load exploit attempt | off | off | off |
1 | 19670 | BROWSER-IE | Microsoft Internet Explorer telnet.exe file load exploit attempt | off | drop | drop |
1 | 19671 | BROWSER-IE | Microsoft Internet Explorer XSLT memory corruption attempt | off | off | drop |
1 | 19672 | BROWSER-IE | Microsoft Internet Explorer stylesheet dynamic access memory corruption attempt | off | drop | drop |
1 | 19675 | FILE-OFFICE | Microsoft Office Visio invalid UMLString data length exploit attempt | off | drop | drop |
1 | 19687 | FILE-FLASH | Adobe Flash ActionStoreRegister instruction length invalidation attempt | drop | drop | drop |
1 | 19707 | FILE-OFFICE | Microsoft Office Word Converter sprmTSplit overflow attempt | off | drop | drop |
1 | 19708 | SERVER-MAIL | Postfix SMTP Server SASL AUTH Handle Reuse Memory Corruption | off | off | off |
1 | 19710 | BROWSER-CHROME | Google Chrome float rendering corruption attempt | off | off | off |
1 | 19713 | BROWSER-FIREFOX | Mozilla Array.reduceRight integer overflow | drop | drop | drop |
1 | 19803 | MALWARE-CNC | Win.Trojan.Renos.FH variant outbound connection | off | off | off |
1 | 19808 | BROWSER-IE | Microsoft Internet Explorer covered object memory corruption attempt | off | drop | drop |
1 | 19809 | BROWSER-IE | Microsoft Internet Explorer covered object memory corruption attempt | off | drop | drop |
1 | 19810 | SERVER-OTHER | CA Total Defense Suite UNCWS deleteReportTemplate SQL injection attempt | off | off | off |
1 | 19812 | SERVER-OTHER | CA Total Defense Suite UNCWS getDBConfigSettings credential information disclosure attempt | drop | drop | drop |
1 | 19813 | SERVER-WEBAPP | Novell File Reporter Agent XMLK parsing stack bugger overflow attempt | drop | drop | drop |
1 | 19814 | BROWSER-IE | Microsoft Internet Explorer empty table tag memory corruption attempt | off | off | off |
1 | 19826 | SERVER-WEBAPP | HP Power Manager remote code execution attempt | off | off | off |
1 | 19867 | INDICATOR-OBFUSCATION | randomized javascript encodings detected | off | off | off |
1 | 19871 | BROWSER-IE | Microsoft Internet Explorer VML buffer overflow attempt | off | off | off |
1 | 19872 | BROWSER-IE | Microsoft Internet Explorer MDAC remote code execution attempt | off | off | off |
1 | 19873 | BROWSER-IE | Microsoft Internet Explorer CSS style memory corruption attempt | off | off | drop |
1 | 19884 | INDICATOR-OBFUSCATION | String.fromCharCode with multiple encoding types detected | off | off | off |
1 | 19885 | BROWSER-IE | Microsoft Internet Explorer daxctle.ocx spline method buffer overflow attempt | off | off | off |
1 | 19887 | INDICATOR-OBFUSCATION | potential javascript unescape obfuscation attempt detected | off | off | off |
1 | 19888 | INDICATOR-OBFUSCATION | potential javascript unescape obfuscation attempt detected | off | off | off |
1 | 19889 | INDICATOR-OBFUSCATION | base64-encoded data object found | off | off | off |
1 | 19890 | NETBIOS | DCERPC NCACN-IP-TCP CA Arcserve Backup directory traversal attempt | off | off | off |
1 | 19893 | BROWSER-PLUGINS | Microsoft Windows Tabular Control ActiveX overflow by CLSID / param tag | off | off | drop |
1 | 19894 | FILE-OFFICE | Microsoft Office PowerPoint unbound memcpy and remote code execution attempt | off | off | drop |
1 | 19909 | BROWSER-PLUGINS | Cisco AnyConnect ActiveX clsid access | off | off | off |
1 | 19910 | BROWSER-IE | Microsoft Internet Explorer VML use after free attempt | off | drop | drop |
1 | 19911 | FILE-OTHER | Microsoft SYmbolic LinK stack overflow attempt | off | drop | drop |
1 | 19926 | FILE-JAVA | Oracle Java Runtime AWT setDiffICM stack buffer overflow attempt | off | off | off |
1 | 19932 | FILE-OFFICE | Microsoft Office Publisher 2007 pointer dereference attempt | off | off | off |
1 | 19937 | BROWSER-IE | Microsoft Internet Explorer invalid object access memory corruption attempt | off | off | drop |
1 | 19938 | SERVER-OTHER | IBM Tivoli Directory Server ibmslapd.exe stack buffer overflow attempt | drop | drop | drop |
1 | 19943 | FILE-OFFICE | Microsoft Office Excel MsoDrawingGroup record remote code execution attempt | off | off | off |
1 | 19956 | FILE-MULTIMEDIA | Microsoft Windows Movie Maker project file heap buffer overflow attempt | off | off | drop |
1 | 19972 | OS-WINDOWS | SMB client TRANS response paramcount overflow attempt | off | off | off |
1 | 20029 | FILE-OFFICE | Microsoft Office Excel FNGROUPNAME record memory corruption attempt | off | off | drop |
1 | 20030 | PROTOCOL-SCADA | IGSS IGSSDataServer.exe file operation directory traversal attempt | off | off | drop |
1 | 20031 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption | drop | drop | drop |
1 | 20034 | FILE-OTHER | ESTsoft ALZip MIM file buffer overflow attempt | off | off | off |
1 | 20061 | NETBIOS | DCERPC NCACN-IP-TCP ca-alert function 16,23,40, and 41 overflow attempt | off | off | off |
1 | 20062 | FILE-OFFICE | Microsoft Office Excel File Importing Code Execution | off | off | off |
1 | 20072 | BROWSER-FIREFOX | Mozilla Firefox nsTreeRange Use After Free attempt | drop | drop | drop |
1 | 20073 | OS-WINDOWS | Microsoft Windows ATMFD font driver malicious font file remote code execution attempt | off | drop | drop |
1 | 20110 | SERVER-OTHER | Nullsoft Winamp Ultravox streaming malicious metadata | off | off | off |
1 | 20124 | FILE-OFFICE | Microsoft Office Excel invalid Lbl record attempt | off | off | drop |
1 | 20127 | FILE-OFFICE | Microsoft Office Excel Conditional Formatting record vulnerability | off | drop | drop |
1 | 20128 | FILE-OFFICE | Microsoft Office invalid MS-OGRAPH DataFormat buffer overflow attempt | off | off | drop |
1 | 20131 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt | off | drop | drop |
1 | 20134 | SERVER-WEBAPP | HP OpenView Storage Data Protector buffer overflow attempt | drop | drop | drop |
1 | 20137 | INDICATOR-OBFUSCATION | Possible generic javascript heap spray attempt | off | off | off |
1 | 20139 | FILE-OFFICE | Microsoft Office Word document summary information string overflow attempt | off | off | off |
1 | 20140 | FILE-OFFICE | Microsoft Office Word document summary information string overflow attempt | off | off | off |
1 | 20141 | FILE-OFFICE | Microsoft Office Word document summary information string overflow attempt | off | off | off |
1 | 20154 | FILE-PDF | Adobe Acrobat Reader CoolType.dll glyf directory table buffer overflow attempt | off | drop | drop |
1 | 20155 | FILE-PDF | Adobe Acrobat Reader CoolType.dll composite glyf buffer overflow attempt | off | drop | drop |
1 | 20158 | SERVER-WEBAPP | Oracle GlassFish Server default credentials login attempt | drop | drop | drop |
1 | 20175 | BROWSER-PLUGINS | Microsoft Windows Remote Desktop Client ActiveX clsid access | off | off | off |
1 | 20188 | INDICATOR-SHELLCODE | Metasploit meterpreter stdapi_sys_config_method request/response attempt | off | off | off |
1 | 20191 | INDICATOR-SHELLCODE | Metasploit meterpreter stdapi_net_method request/response attempt | off | off | off |
1 | 20210 | PROTOCOL-SCADA | Cogent unicode buffer overflow attempt | drop | drop | drop |
1 | 20214 | PROTOCOL-SCADA | Measuresoft ScadaPro msvcrt.dll local command execution attempt | drop | drop | drop |
1 | 20215 | PROTOCOL-SCADA | Measuresoft ScadaPro directory traversal file operation attempt | drop | drop | drop |
1 | 20246 | FILE-OFFICE | Microsoft Office Outlook SMB attach by reference code execution attempt | off | off | drop |
1 | 20247 | FILE-OFFICE | Microsoft Office Outlook SMB attach by reference code execution attempt | off | off | drop |
1 | 20255 | BROWSER-PLUGINS | Microsoft Silverlight inheritance restriction bypass | off | drop | drop |
1 | 20259 | FILE-OTHER | Microsoft Agent Helper Malicious JAR download attempt | off | drop | drop |
1 | 20261 | FILE-EXECUTABLE | Microsoft Windows win32k.sys kernel mode null pointer dereference attempt | off | off | off |
1 | 20262 | BROWSER-IE | Microsoft Internet Explorer onscroll DOS attempt | off | off | off |
1 | 20263 | BROWSER-IE | Microsoft Internet Explorer htmlfile null attribute access attempt | off | drop | drop |
1 | 20264 | BROWSER-IE | Microsoft Internet Explorer form selection reset attempt | off | off | drop |
1 | 20265 | BROWSER-IE | Microsoft Internet Explorer null attribute DoS attempt | off | drop | drop |
1 | 20266 | BROWSER-IE | Microsoft Internet Explorer 8 Javascript negative option index attack attempt | off | drop | drop |
1 | 20267 | BROWSER-IE | Microsoft Internet Explorer circular reference exploit attempt | off | drop | drop |
1 | 20268 | BROWSER-IE | Microsoft Internet Explorer Marquee stylesheet object removal | off | drop | drop |
1 | 20276 | INDICATOR-OBFUSCATION | standard ASCII encoded with UTF-8 possible evasion detected | off | off | off |
1 | 20283 | FILE-MULTIMEDIA | VideoLAN VLC ModPlug ReadS3M overflow attempt | off | off | off |
1 | 20284 | FILE-MULTIMEDIA | VideoLAN VLC ModPlug ReadS3M overflow attempt | off | off | off |
1 | 20288 | FILE-MULTIMEDIA | RealNetworks RealPlayer QCP parsing buffer overflow attempt | off | drop | drop |
1 | 20294 | FILE-IMAGE | Adobe Reader and Acrobat Libtiff TIFFFetchShortPair stack buffer overflow attempt | off | off | off |
1 | 20295 | FILE-IMAGE | Public LibTiff Exploit | off | off | off |
1 | 20381 | PROTOCOL-VOIP | Remote-Party-ID header hexadecimal characters in IP address field | off | off | off |
1 | 20390 | PROTOCOL-VOIP | Attribute header rtpmap field invalid payload type | off | off | off |
1 | 20532 | SERVER-WEBAPP | HP OpenView Storage Data Protector get file buffer overflow attempt | drop | drop | drop |
1 | 20554 | PUA-OTHER | Microsoft MSN Messenger and Windows Live Messenger Code Execution attempt | off | off | off |
1 | 20577 | FILE-PDF | Adobe Acrobat Reader malicious TIFF remote code execution attempt | off | off | drop |
1 | 20579 | BROWSER-CHROME | Google Chrome and Apple Safari Ruby before and after memory corruption | off | off | off |
1 | 20591 | BROWSER-PLUGINS | Flexera InstallShield ISGrid2.dll DoFindReplace heap buffer overlow ActiveX clsid access | off | off | off |
1 | 20592 | BROWSER-PLUGINS | Flexera InstallShield ISGrid2.dll DoFindReplace heap buffer overlow ActiveX function call access | off | off | off |
1 | 20593 | BROWSER-WEBKIT | Apple Safari Webkit libxslt arbitrary file creation attempt | off | off | drop |
1 | 20600 | BROWSER-FIREFOX | Mozilla Products SVG text content element getCharNumAtPosition use after free attempt | drop | drop | drop |
1 | 20607 | SERVER-OTHER | Novell Groupwise internet agent http uri buffer overflow attempt | drop | drop | drop |
1 | 20622 | FILE-JAVA | Oracle Java Applet remote code execution attempt | drop | drop | drop |
1 | 20628 | SERVER-WEBAPP | HP Data Protector FinishedCopy SQL Injection attempt | drop | drop | drop |
1 | 20634 | BROWSER-IE | Microsoft Internet Explorer onscroll DOS attempt | off | drop | drop |
1 | 20635 | SERVER-WEBAPP | HP Data Protector GetPolicies SQL Injection attempt | drop | drop | drop |
1 | 20636 | FILE-IMAGE | Adobe Photoshop CS5 gif file heap corruption attempt | off | drop | drop |
1 | 20637 | FILE-IMAGE | Adobe Photoshop CS5 gif file heap corruption attempt | off | drop | drop |
1 | 20659 | FILE-PDF | Adobe Acrobat Reader malformed shading modifier heap corruption attempt | drop | drop | drop |
1 | 20700 | FILE-OFFICE | Microsoft Office PowerPoint pp7x32.dll dll-load exploit attempt | off | off | off |
1 | 20701 | FILE-OFFICE | Microsoft Office PowerPoint pp4x322.dll dll-load exploit attempt | off | off | off |
1 | 20702 | FILE-OFFICE | Microsoft Office PowerPoint pp7x32.dll dll-load exploit attempt | off | off | off |
1 | 20703 | FILE-OFFICE | Microsoft Office PowerPoint pp4x322.dll dll-load exploit attempt | off | off | off |
1 | 20704 | BROWSER-PLUGINS | Microsoft Internet Explorer defaulttime behavior attack attempt | off | drop | drop |
1 | 20708 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX clsid access | off | drop | drop |
1 | 20709 | BROWSER-PLUGINS | HP Photo Creative ActiveX clsid access | off | drop | drop |
1 | 20720 | FILE-OFFICE | Microsoft Office Publisher 2003 EscherStm memory corruption attempt | off | drop | drop |
1 | 20722 | FILE-OFFICE | Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord exploit attempt | off | alert | drop |
1 | 20724 | FILE-OFFICE | Microsoft Office Word border use-after-free attempt | off | off | off |
1 | 20734 | FILE-MULTIMEDIA | Microsoft Windows Media Player digital video recording buffer overflow attempt | off | drop | drop |
1 | 20749 | SERVER-OTHER | EMC Retrospect client crafted packet buffer overflow attempt | off | off | off |
1 | 20764 | SERVER-WEBAPP | SyBase MBusiness xml closing tag overflow attempt | off | off | off |
1 | 20766 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt | off | drop | drop |
1 | 20767 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption | drop | drop | drop |
1 | 20777 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption attempt | drop | drop | drop |
1 | 20778 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt - economy.rar | off | drop | drop |
1 | 20779 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt - dear chu.rar | off | drop | drop |
1 | 20780 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt - namelist.xls | off | drop | drop |
1 | 20781 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt | off | drop | drop |
1 | 20782 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt - economy.rar | off | drop | drop |
1 | 20783 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt - dear chu.rar | off | drop | drop |
1 | 20784 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt - namelist.xls | off | drop | drop |
1 | 20785 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt | off | drop | drop |
1 | 20786 | BROWSER-IE | Microsoft Internet Explorer layout-grid-char value exploit attempt | off | drop | drop |
1 | 20787 | BROWSER-IE | Microsoft Internet Explorer layout-grid-char value exploit attempt | off | drop | drop |
1 | 20788 | BROWSER-IE | Microsoft Internet Explorer layout-grid-char value exploit attempt | off | drop | drop |
1 | 20789 | BROWSER-IE | Microsoft Internet Explorer layout-grid-char value exploit attempt | off | drop | drop |
1 | 20790 | BROWSER-IE | Microsoft Internet Explorer layout-grid-char value exploit attempt | off | drop | drop |
1 | 20803 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt | off | drop | drop |
1 | 20804 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt | off | drop | drop |
1 | 20805 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt | off | drop | drop |
1 | 20806 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt | off | drop | drop |
1 | 20807 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt | off | drop | drop |
1 | 20808 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt | off | drop | drop |
1 | 20809 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt | off | drop | drop |
1 | 20810 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt | off | drop | drop |
1 | 20811 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt | off | drop | drop |
1 | 20822 | BROWSER-IE | Microsoft Internet Explorer contenteditable corruption attempt malicious string | off | drop | drop |
1 | 20828 | SERVER-IIS | Microsoft Windows IIS aspx login ReturnURL arbitrary redirect attempt | off | off | off |
1 | 20834 | BROWSER-PLUGINS | Novell ZENworks LaunchHelp.dll LaunchProcess Code Execution ActiveX clsid access | off | off | off |
1 | 20835 | BROWSER-PLUGINS | Novell ZENworks LaunchHelp.dll LaunchProcess Code Execution ActiveX function call access | off | off | off |
1 | 20842 | FILE-OTHER | Interactive Data eSignal stack buffer overflow attempt | drop | drop | drop |
1 | 20843 | FILE-OTHER | Interactive Data eSignal stack buffer overflow attempt | drop | drop | drop |
1 | 20884 | OS-WINDOWS | Microsoft Anti-Cross Site Scripting library bypass attempt | off | off | off |
1 | 20900 | FILE-OTHER | Microsoft Windows Media MIDI file memory corruption attempt | off | drop | drop |
1 | 20903 | FILE-OTHER | Microsoft Windows OpenType font parsing stack overflow attempt | off | drop | drop |
1 | 20993 | SERVER-OTHER | HP OpenView Storage Data Protector exec_cmd buffer overflow | drop | drop | drop |
1 | 20994 | SERVER-OTHER | HP OpenView Storage Data Protector exec_cmd buffer overflow | drop | drop | drop |
1 | 21002 | FILE-OFFICE | Microsoft Office Word border use-after-free attempt | off | off | off |
1 | 21037 | INDICATOR-OBFUSCATION | randomized javascript encodings detected | off | off | off |
1 | 21038 | INDICATOR-OBFUSCATION | String.fromCharCode with multiple encoding types detected | off | off | off |
1 | 21039 | INDICATOR-OBFUSCATION | potential javascript unescape obfuscation attempt detected | off | off | off |
1 | 21050 | SERVER-OTHER | HP Diagnostics Server magentservice.exe stack overflow attempt | drop | drop | drop |
1 | 21060 | SERVER-WEBAPP | Symantec IM Manager Administrator console site injection attempt | off | off | off |
1 | 21063 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX clsid access | off | drop | drop |
1 | 21064 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX function call access | off | drop | drop |
1 | 21072 | SERVER-APACHE | Apache Struts allowStaticMethodAccess invocation attempt | off | drop | drop |
1 | 21073 | SERVER-APACHE | Apache Struts allowStaticMethodAccess invocation attempt | off | drop | drop |
1 | 21074 | SERVER-APACHE | Apache Struts remote code execution attempt - CookieInterceptor | off | alert | drop |
1 | 21076 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX clsid access | off | drop | drop |
1 | 21077 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX function call | off | drop | drop |
1 | 21086 | BROWSER-IE | Microsoft Internet Explorer object clone deletion memory corruption | off | off | off |
1 | 21112 | FILE-MULTIMEDIA | RealNetworks RealPlayer mpeg width integer memory underflow attempt | off | off | drop |
1 | 21116 | FILE-OTHER | Cisco Webex selector and size2 subrecords corruption attempt | off | drop | drop |
1 | 21159 | FILE-OTHER | Microsoft Windows Media MIDI file memory corruption attempt | off | drop | drop |
1 | 21167 | FILE-OTHER | Microsoft Windows Media MIDI file memory corruption attempt | off | drop | drop |
1 | 21170 | FILE-OFFICE | Microsoft Office OLESS stream object name corruption attempt | off | drop | drop |
1 | 21190 | BROWSER-FIREFOX | Mozilla Multiple Products MozOrientation loading attempt | off | off | off |
1 | 21191 | BROWSER-FIREFOX | Mozilla Multiple Products MozOrientation loading attempt | off | off | off |
1 | 21243 | FILE-OFFICE | Microsoft Office Publisher 2003 EscherStm memory corruption attempt | off | drop | drop |
1 | 21253 | FILE-PDF | Adobe Acrobat Reader malformed shading modifier heap corruption attempt | drop | drop | drop |
1 | 21258 | INDICATOR-SHELLCODE | Feng-Shui heap grooming using Oleaut32 | off | off | off |
1 | 21299 | BROWSER-PLUGINS | Microsoft Silverlight privilege escalation attempt | off | drop | drop |
1 | 21301 | FILE-OFFICE | Microsoft Office Visio TAG_xxxSect code execution attempt | off | drop | drop |
1 | 21302 | FILE-OFFICE | Microsoft Office Visio TAG_OLEChunk code execution attempt | off | drop | drop |
1 | 21305 | FILE-EXECUTABLE | Microsoft .NET Framework System.Uri.ReCreateParts System.Uri.PathAndQuery overflow attempt | off | drop | drop |
1 | 21307 | FILE-OFFICE | Microsoft Office Visio TAG_xxxSheet code execution attempt | off | drop | drop |
1 | 21308 | FILE-OTHER | Microsoft Windows C Run-Time Library remote code execution attempt | off | drop | drop |
1 | 21316 | FILE-OTHER | Adobe shockwave director tSAC string termination memory corruption attempt | off | drop | drop |
1 | 21336 | FILE-FLASH | Adobe Flash ASConstructor insecure calling attempt | drop | drop | drop |
1 | 21338 | FILE-FLASH | Adobe Flash Player MP4 zero length atom attempt | drop | drop | drop |
1 | 21339 | FILE-MULTIMEDIA | Adobe Flash Player MP4 zero length atom auth field attempt | drop | drop | drop |
1 | 21340 | FILE-MULTIMEDIA | Adobe Flash Player MP4 zero length atom titl field attempt | drop | drop | drop |
1 | 21341 | FILE-MULTIMEDIA | Adobe Flash Player MP4 zero length atom 'dscp' field attempt | drop | drop | drop |
1 | 21342 | FILE-MULTIMEDIA | Adobe Flash Player MP4 zero length atom cprt field attempt | drop | drop | drop |
1 | 21371 | FILE-OTHER | Adobe Shockwave Director KEY chunk buffer overflow attempt | off | drop | drop |
1 | 21378 | SERVER-OTHER | Novell iPrint attributes-natural-language buffer overflow attempt | off | off | off |
1 | 21392 | BROWSER-IE | Microsoft Internet Explorer writing-mode property memory corruption attempt | off | off | off |
1 | 21405 | OS-WINDOWS | Microsoft Anti-Cross Site Scripting library bypass attempt | off | off | off |
1 | 21415 | FILE-OFFICE | Microsoft Office Excel MergeCells record parsing code execution attempt | off | off | drop |
1 | 21422 | FILE-OFFICE | Microsoft Office Excel Lel record memory corruption attempt | off | drop | drop |
1 | 21423 | FILE-OFFICE | Microsoft Office Publisher Opltc memory corruption attempt | off | drop | drop |
1 | 21447 | BROWSER-CHROME | Google Chrome FileSystemObject function call | off | off | off |
1 | 21457 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption | drop | drop | drop |
1 | 21458 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption | off | drop | drop |
1 | 21481 | FILE-JAVA | Oracle Java Web Start arbitrary command execution attempt | off | off | drop |
1 | 21484 | FILE-OTHER | ZIP file name overflow attempt | off | off | drop |
1 | 21504 | OS-WINDOWS | Microsoft Windows Object Packager ClickOnce object remote code execution attempt | off | drop | drop |
1 | 21505 | OS-WINDOWS | Microsoft Windows Object Packager ClickOnce object remote code execution attempt | off | drop | drop |
1 | 21506 | OS-WINDOWS | Microsoft Windows Object Packager ClickOnce object remote code execution attempt | off | drop | drop |
1 | 21507 | OS-WINDOWS | Microsoft Windows Object Packager ClickOnce object remote code execution attempt | off | drop | drop |
1 | 21508 | OS-WINDOWS | Microsoft Windows Object Packager ClickOnce object remote code execution attempt | off | drop | drop |
1 | 21522 | SERVER-APACHE | Apache Struts parameters interceptor remote code execution attempt | off | off | off |
1 | 21570 | OS-WINDOWS | Microsoft Windows RemoteDesktop new session flood attempt | off | drop | drop |
1 | 21663 | SERVER-OTHER | CA BrightStor Agent for Microsoft SQL overflow attempt | off | off | off |
1 | 21664 | FILE-JAVA | Oracle Java JRE sandbox Atomic breach attempt | drop | drop | drop |
1 | 21665 | FILE-JAVA | Oracle Java JRE sandbox Atomic breach attempt | drop | drop | drop |
1 | 21666 | FILE-JAVA | Oracle Java JRE sandbox Atomic breach attempt | alert | alert | alert |
1 | 21667 | FILE-JAVA | Oracle Java JRE sandbox Atomic breach attempt | alert | alert | alert |
1 | 21752 | SERVER-OTHER | Novell ZENWorks configuration management preboot request buffer overflow attempt | drop | drop | drop |
1 | 21753 | PROTOCOL-VOIP | Digium Asterisk Management Interface HTTP digest authentication stack buffer overflow attempt | off | off | off |
1 | 21792 | FILE-EXECUTABLE | Microsoft Windows .NET invalid parsing of graphics data attempt | off | drop | drop |
1 | 21793 | BROWSER-IE | Microsoft Internet Explorer vector graphics reference counting use-after-free attempt | off | alert | drop |
1 | 21795 | FILE-EXECUTABLE | Microsoft Windows Authenticode signature verification bypass attempt | off | drop | drop |
1 | 21796 | BROWSER-IE | Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt | off | drop | drop |
1 | 21797 | FILE-OFFICE | MSCOMCTL ActiveX control deserialization arbitrary code execution attempt | off | drop | drop |
1 | 21798 | FILE-OFFICE | MSCOMCTL ActiveX control deserialization arbitrary code execution attempt | off | drop | drop |
1 | 21799 | FILE-OFFICE | MSCOMCTL ActiveX control deserialization arbitrary code execution attempt | off | drop | drop |
1 | 21800 | FILE-OFFICE | MSCOMCTL ActiveX control deserialization arbitrary code execution attempt | off | drop | drop |
1 | 21801 | FILE-OFFICE | MSCOMCTL ActiveX control deserialization arbitrary code execution attempt | off | drop | drop |
1 | 21869 | FILE-OTHER | Java Applet Rhino script engine remote code execution attempt | alert | alert | drop |
1 | 21878 | FILE-PDF | Adobe Acrobat Reader embedded TTF integer overflow attempt | drop | drop | drop |
1 | 21896 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21897 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21898 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21899 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21900 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21901 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21902 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21903 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21904 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21905 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21906 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21914 | SERVER-OTHER | Novell ZENWorks configuration management preboot opcode 6C request buffer overflow attempt | drop | drop | drop |
1 | 21918 | BROWSER-PLUGINS | IBM Tivoli Provisioning Manager Express Buffer Overflow ActiveX clsid access attempt | off | drop | drop |
1 | 21919 | BROWSER-PLUGINS | IBM Tivoli Provisioning Manager Express Buffer Overflow ActiveX function call access attempt | off | drop | drop |
1 | 21922 | FILE-OTHER | VLC mms hostname buffer overflow attempt | off | off | off |
1 | 21927 | FILE-OFFICE | Microsoft Office Excel style handling overflow attempt | off | off | off |
1 | 21935 | FILE-OFFICE | Microsoft Works 9 and Word 12 converter heap overflow attempt | off | off | drop |
1 | 21937 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 21944 | SERVER-OTHER | IBM Tivoli Endpoint Manager Web Reports xss attempt | off | off | off |
1 | 21948 | FILE-IMAGE | Adobe Photoshop CS4 TIFF parsing heap overflow attempt | off | off | off |
1 | 22009 | SERVER-SAMBA | Samba malicious user defined array size and buffer attempt | drop | drop | drop |
1 | 22038 | BROWSER-IE | Microsoft Internet Explorer SelectAll dangling pointer use after free attempt | off | alert | drop |
1 | 22042 | FILE-EXECUTABLE | Microsoft Windows .NET invalid parsing of graphics data attempt | off | drop | drop |
1 | 22052 | FILE-OFFICE | Microsoft Office Excel style record overflow attempt | off | off | off |
1 | 22066 | FILE-OFFICE | Microsoft Office Word ScriptBridge OCX controller attempt | off | off | off |
1 | 22069 | FILE-FLASH | Adobe Flash Player object confusion attempt | off | drop | drop |
1 | 22070 | FILE-FLASH | Adobe Flash Player object confusion attempt | off | drop | drop |
1 | 22075 | FILE-OFFICE | Microsoft Office Visio IndexDirectorySize greater than ChildrenSize memory access attempt | off | drop | drop |
1 | 22076 | FILE-OFFICE | Microsoft Office Excel invalid Window2 BIFF record value attempt | off | off | alert |
1 | 22077 | FILE-OFFICE | Microsoft Office Excel ObjectLink invalid wLinkVar2 value attempt | off | drop | drop |
1 | 22078 | FILE-OFFICE | Microsoft Office Excel invalid Window2 BIFF record value attempt | off | off | off |
1 | 22091 | FILE-OFFICE | Microsoft Office Excel SXLI record integer overrun attempt | off | drop | drop |
1 | 22092 | FILE-OFFICE | Microsoft Office Excel SERIES record sdtY memory corruption attempt | off | drop | drop |
1 | 22093 | FILE-OFFICE | Microsoft Office Excel SERIES record SerAuxTrend sdtX memory corruption attempt | off | drop | drop |
1 | 22094 | FILE-OFFICE | Microsoft Office Excel SERIES record SerAuxErrBar sdtX memory corruption attempt | off | drop | drop |
1 | 22104 | FILE-IMAGE | libpng chunk decompression integer overflow attempt | off | off | off |
1 | 22105 | FILE-IMAGE | libpng chunk decompression integer overflow attempt | off | off | off |
1 | 22106 | FILE-IMAGE | libpng chunk decompression integer overflow attempt | off | off | off |
1 | 22107 | FILE-IMAGE | libpng chunk decompression integer overflow attempt | off | off | off |
1 | 22108 | FILE-IMAGE | libpng chunk decompression integer overflow attempt | off | off | off |
1 | 22109 | FILE-IMAGE | libpng chunk decompression integer overflow attempt | off | off | off |
1 | 22915 | FILE-FLASH | Adobe Flash Player object confusion attempt | off | drop | drop |
1 | 22916 | FILE-FLASH | Adobe Flash Player object confusion attempt | off | drop | drop |
1 | 22938 | FILE-PDF | Adobe Acrobat Reader embedded TTF integer overflow attempt | drop | drop | drop |
1 | 22942 | FILE-EXECUTABLE | Microsoft Windows Authenticode signature verification bypass attempt | off | drop | drop |
1 | 22947 | FILE-OTHER | Novell Groupwise Addressbook buffer overflow attempt | off | off | off |
1 | 22950 | SERVER-WEBAPP | EXIF header parsing integer overflow attempt big endian | off | off | off |
1 | 22954 | FILE-OFFICE | Microsoft Office Excel Malformed SELECTION Record Code Execution attempt | off | off | off |
1 | 23009 | FILE-OFFICE | Microsoft Office Excel SXLI record integer overrun attempt | off | drop | drop |
1 | 23014 | FILE-OTHER | Adobe Photoshop asset elements stack based buffer overflow attempt | off | off | off |
1 | 23015 | BROWSER-CHROME | Google Chrome and Apple Safari runin handling use after free attempt | off | off | off |
1 | 23041 | FILE-PDF | EmbeddedFile contained within a PDF | off | off | off |
1 | 23046 | SERVER-WEBAPP | Oracle GlassFish Enterprise server cross site scripting attempt | off | off | off |
1 | 23047 | SERVER-WEBAPP | Oracle GlassFish Enterprise server cross site scripting attempt | off | off | off |
1 | 23056 | SERVER-OTHER | SAP NetWeaver Dispatcher DiagTraceR3Info buffer overflow attempt | off | drop | drop |
1 | 23059 | FILE-OFFICE | Microsoft Office Visio TAG_xxxSect code execution attempt | off | drop | drop |
1 | 23096 | SERVER-OTHER | VERITAS NetBackup java authentication service format string exploit attempt | off | off | off |
1 | 23098 | FILE-MULTIMEDIA | Adobe Flash Player MP4 sequence parameter set parsing overflow attempt | drop | drop | drop |
1 | 23100 | FILE-OTHER | Cisco WebEx recording integer overflow attempt | off | off | off |
1 | 23101 | FILE-OTHER | Cisco WebEx recording integer overflow attempt | off | off | off |
1 | 23111 | POLICY-OTHER | PHP uri tag injection attempt | drop | drop | drop |
1 | 23116 | BROWSER-IE | Microsoft Internet Explorer 9 CTreeNode use after free attempt | off | drop | drop |
1 | 23117 | BROWSER-IE | Microsoft Internet Explorer 9 DOM element use after free attempt | off | drop | drop |
1 | 23118 | BROWSER-IE | Microsoft Internet Explorer console object use after free attempt | off | drop | drop |
1 | 23121 | BROWSER-IE | Microsoft Internet Explorer getBoundingClientRect incorrect rebalancing attempt | off | drop | drop |
1 | 23123 | BROWSER-IE | Microsoft Internet Explorer getBoundingClientRect incorrect rebalancing attempt | off | off | drop |
1 | 23124 | BROWSER-IE | Microsoft Internet Explorer html table column span width increase memory corruption attempt | off | drop | drop |
1 | 23125 | BROWSER-IE | Microsoft Internet Explorer DOM manipulation memory corruption attempt | off | drop | drop |
1 | 23136 | BROWSER-IE | Microsoft multiple product toStaticHTML XSS attempt | off | off | off |
1 | 23137 | BROWSER-IE | Microsoft multiple product toStaticHTML XSS attempt | off | off | off |
1 | 23151 | FILE-OFFICE | Microsoft Office Excel zero-width worksheet code execution attempt | off | off | off |
1 | 23152 | FILE-OTHER | OpenType Font file integer overflow attempt | off | off | off |
1 | 23170 | FILE-MULTIMEDIA | Apple QuickTime MPEG stream padding buffer overflow attempt | off | off | off |
1 | 23175 | BROWSER-PLUGINS | IBM Lotus Quickr ActiveX stack buffer overflow attempt | off | drop | drop |
1 | 23177 | SERVER-WEBAPP | Symantec Web Gateway timer.php cross site scripting attempt | off | off | off |
1 | 23186 | BROWSER-PLUGINS | Dell CrazyTalk.DLL ActiveX clsid access | off | off | off |
1 | 23209 | PROTOCOL-VOIP | Digium Asterisk Manager command shell execution attempt | off | off | off |
1 | 23210 | PROTOCOL-VOIP | Digium Asterisk Manager command shell execution attempt | off | off | off |
1 | 23212 | BROWSER-FIREFOX | Mozilla Firefox IDB use-after-free attempt | drop | drop | drop |
1 | 23213 | SQL | Ruby on rails SQL injection attempt | off | off | off |
1 | 23227 | FILE-OFFICE | Microsoft Office Excel rtMergeCells heap overflow attempt | off | off | off |
1 | 23229 | BROWSER-PLUGINS | Oracle Webcenter ActiveX function call access | off | off | off |
1 | 23237 | OS-WINDOWS | SMB2 client NetBufferList NULL entry remote code execution attempt | off | off | alert |
1 | 23238 | NETBIOS | Wireshark console.lua file load exploit attempt | off | off | off |
1 | 23241 | SERVER-OTHER | HP DPNECentral RequestCopy type SQL injection attempt | drop | drop | drop |
1 | 23243 | FILE-JAVA | Oracle Java Zip file directory record overflow attempt | off | off | off |
1 | 23253 | BROWSER-PLUGINS | HP Easy Printer Care XMLSimpleAccessor ActiveX function call access attempt | off | off | off |
1 | 23256 | FILE-EXECUTABLE | Armadillo v1.71 packer file magic detected | off | off | off |
1 | 23258 | SERVER-WEBAPP | LANDesk Thinkmanagement Suite ServerSetup directory traversal attempt | off | off | off |
1 | 23263 | FILE-PDF | Adobe Acrobat Reader XDP encoded download attempt | off | off | drop |
1 | 23264 | FILE-FLASH | Adobe Flash Player newfunction memory corruption attempt | off | off | drop |
1 | 23265 | FILE-FLASH | Adobe Flash Player newfunction memory corruption attempt | off | off | drop |
1 | 23269 | FILE-OTHER | Cisco WebEx recording integer overflow attempt | off | drop | drop |
1 | 23271 | FILE-MULTIMEDIA | Apple iTunes Extended M3U playlist record overflow attempt | off | off | drop |
1 | 23273 | FILE-JAVA | Oracle Java field bytecode verifier cache code execution attempt | drop | drop | drop |
1 | 23274 | FILE-JAVA | Oracle Java field bytecode verifier cache code execution attempt | drop | drop | drop |
1 | 23275 | FILE-JAVA | Oracle Java field bytecode verifier cache code execution attempt | drop | drop | drop |
1 | 23276 | FILE-JAVA | Oracle Java field bytecode verifier cache code execution attempt | drop | drop | drop |
1 | 23277 | FILE-JAVA | Oracle Java field bytecode verifier cache code execution attempt | drop | drop | drop |
1 | 23278 | BROWSER-IE | Microsoft Internet Explorer nested list memory corruption attempt | off | drop | drop |
1 | 23280 | BROWSER-IE | Microsoft Internet Explorer corrupted HROW instance write access violation attempt | off | drop | drop |
1 | 23284 | BROWSER-PLUGINS | Oracle WebCenter Forms Recognition ActiveX function call attempt | off | off | off |
1 | 23285 | BROWSER-IE | Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt | off | drop | drop |
1 | 23286 | BROWSER-PLUGINS | Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt | off | drop | drop |
1 | 23305 | FILE-OFFICE | Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt | off | drop | drop |
1 | 23314 | OS-WINDOWS | SMB invalid character argument injection attempt | off | off | off |
1 | 23346 | FILE-OTHER | Oracle outside in Lotus 1-2-3 heap overflow attempt | off | off | off |
1 | 23352 | BROWSER-PLUGINS | Cisco Linksys PlayerPT ActiveX clsid access attempt | off | drop | drop |
1 | 23354 | SERVER-WEBAPP | Novell iManager buffer overflow attempt | off | off | off |
1 | 23355 | SERVER-OTHER | Trend Micro Control Manager AddTask stack buffer overflow attempt | drop | drop | drop |
1 | 23370 | FILE-OFFICE | Microsoft Office Drawing object code execution attempt | off | off | off |
1 | 23384 | SERVER-WEBAPP | Novell Groupwise Messenger parameter memory corruption attempt | off | off | off |
1 | 23385 | SERVER-WEBAPP | Novell Groupwise Messenger parameter memory corruption attempt | off | off | off |
1 | 23395 | BROWSER-PLUGINS | Quest InTrust Annotation Objects ActiveX clsid access attempt | drop | drop | drop |
1 | 23398 | SERVER-OTHER | Citrix Provisioning Services stack buffer overflow attempt | off | off | off |
1 | 23400 | FILE-OTHER | Apple Quicktime JPEG2000 length integer underflow attempt | off | drop | drop |
1 | 23401 | SERVER-WEBAPP | Oracle GlassFish server REST interface cross site request forgery attempt | off | off | off |
1 | 23414 | BROWSER-PLUGINS | Veritas Storage Exec ActiveX clsid access attempt | off | off | off |
1 | 23444 | SERVER-OTHER | Flexera FlexNet License Server buffer overflow attempt | off | off | off |
1 | 23461 | FILE-OTHER | Apple Quicktime TeXML Transform attribute overflow attempt | off | drop | drop |
1 | 23462 | FILE-OTHER | Apple Quicktime TeXML Style attribute overflow attempt | off | drop | drop |
1 | 23463 | FILE-OTHER | Apple Quicktime TeXML sampleData attribute overflow attempt | off | drop | drop |
1 | 23464 | FILE-OTHER | Apple Quicktime TeXML description attribute overflow attempt | off | drop | drop |
1 | 23465 | FILE-OTHER | Apple Quicktime TeXML Style attribute overflow attempt | off | drop | drop |
1 | 23504 | FILE-PDF | Adobe Acrobat Reader getAnnots exploit attempt | off | off | off |
1 | 23577 | FILE-OTHER | VLC mms hostname buffer overflow attempt | off | drop | drop |
1 | 23580 | FILE-OTHER | Novell Groupwise Addressbook buffer overflow attempt | off | off | off |
1 | 23609 | BROWSER-IE | Microsoft Internet Explorer getBoundingClientRect incorrect rebalancing attempt | off | drop | drop |
1 | 23614 | FILE-JAVA | Oracle JavaScript heap exploitation library usage attempt | off | drop | drop |
1 | 23626 | SERVER-IIS | cmd.exe access | off | off | off |
1 | 23632 | SERVER-OTHER | HP Data Protector Express stack buffer overflow attempt | drop | drop | drop |
1 | 23753 | FILE-IDENTIFY | Visio file magic detected | off | off | off |
1 | 23757 | FILE-IDENTIFY | Microsoft Windows CHM file magic detected | off | off | off |
1 | 23783 | SERVER-WEBAPP | Symantec Web Gateway pbcontrol.php filename parameter command injection attempt | drop | drop | drop |
1 | 23789 | BROWSER-FIREFOX | Mozilla Multiple Products table frames memory corruption attempt | off | drop | drop |
1 | 23805 | BROWSER-WEBKIT | WebKit button column memory corruption attempt | off | drop | drop |
1 | 23806 | FILE-OTHER | Oracle Outside-In JPEG2000 QCD segment processing heap buffer overflow attempt | off | off | off |
1 | 23834 | BROWSER-IE | Microsoft Internet Explorer asynchronous code execution attempt | off | drop | drop |
1 | 23835 | BROWSER-IE | Microsoft Internet Explorer asynchronous code execution attempt | off | drop | drop |
1 | 23836 | BROWSER-IE | Microsoft Internet Explorer negative margin use after free attempt | off | drop | drop |
1 | 23838 | OS-WINDOWS | SMB NetServerEnum response host format string exploit attempt | drop | drop | drop |
1 | 23842 | FILE-OFFICE | Microsoft Office Visio DXF file text overflow attempt | off | drop | drop |
1 | 23844 | FILE-OFFICE | Microsoft Office MSCOMCTL ActiveX control tabstrip method attempt | off | drop | drop |
1 | 23853 | FILE-FLASH | Adobe Flash OpenType font memory corruption attempt | off | drop | drop |
1 | 23854 | FILE-FLASH | Adobe Flash OpenType font memory corruption attempt | off | drop | drop |
1 | 23855 | FILE-FLASH | string heapspray flash file - likely attack | off | off | off |
1 | 23856 | FILE-FLASH | string heapspray flash file - likely attack | off | off | off |
1 | 23857 | INDICATOR-SHELLCODE | heapspray characters detected - ASCII | off | off | off |
1 | 23858 | FILE-OTHER | heapspray characters detected - binary | off | off | off |
1 | 23859 | INDICATOR-SHELLCODE | heapspray characters detected - hexadecimal encoding | off | off | off |
1 | 23860 | INDICATOR-SHELLCODE | heapspray characters detected - ASCII | off | off | off |
1 | 23861 | FILE-OTHER | heapspray characters detected - binary | off | off | off |
1 | 23862 | INDICATOR-SHELLCODE | heapspray characters detected - hexadecimal encoding | off | off | off |
1 | 23878 | BROWSER-PLUGINS | Oracle JRE Deployment Toolkit ActiveX clsid access attempt | off | off | drop |
1 | 23879 | FILE-PDF | Adobe Acrobat Reader Texture Declaration buffer overflow attempt | alert | alert | drop |
1 | 23880 | FILE-PDF | Adobe Acrobat Reader Texture Declaration buffer overflow attempt | off | alert | drop |
1 | 23897 | FILE-PDF | Sending of a PDF with embedded JavaScript - JS string attempt | off | off | off |
1 | 23904 | BLACKLIST | DNS request for known malware domain publicnews.mooo.com - Backdoor.Briba | off | off | off |
1 | 23934 | SERVER-WEBAPP | Symantec Web Gateway blocked.php blind sql injection attempt | off | off | off |
1 | 23939 | SERVER-ORACLE | Oracle Business Transaction Management FlashTunnelService directory traversal attempt | off | off | off |
1 | 23957 | FILE-OFFICE | Microsoft Office Visio DXF file text overflow attempt | off | drop | drop |
1 | 23958 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 23959 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 23960 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 23961 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 23967 | FILE-FLASH | Adobe Flash OpenType font memory corruption attempt - compressed | off | drop | drop |
1 | 23985 | BROWSER-PLUGINS | Apple Quicktime plugin SetLanguage buffer overflow attempt | off | drop | drop |
1 | 23986 | BROWSER-PLUGINS | Apple Quicktime plugin SetLanguage buffer overflow attempt | off | drop | drop |
1 | 23989 | FILE-OFFICE | Microsoft Office EMF image EMFPlusPointF record memory corruption attempt | off | drop | drop |
1 | 23993 | SERVER-OTHER | Dhcpcd packet size buffer overflow attempt | off | off | drop |
1 | 23996 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption attempt | drop | drop | drop |
1 | 23997 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption attempt | off | drop | drop |
1 | 23999 | FILE-OTHER | Microsoft Windows Media MIDI file memory corruption attempt | off | drop | drop |
1 | 24000 | FILE-OTHER | Microsoft Windows Media MIDI file memory corruption attempt | off | drop | drop |
1 | 24001 | FILE-OTHER | Microsoft Windows Media MIDI file memory corruption attempt | off | drop | drop |
1 | 24002 | FILE-OTHER | Microsoft Windows Media MIDI file memory corruption attempt | off | drop | drop |
1 | 24003 | FILE-OTHER | Microsoft Windows Media MIDI file memory corruption attempt | off | drop | drop |
1 | 24006 | FILE-OFFICE | Microsoft Office MSCOMCTL ActiveX control tabstrip method attempt | off | drop | drop |
1 | 24026 | FILE-JAVA | Oracle Java privileged protection domain exploitation attempt | drop | drop | drop |
1 | 24029 | FILE-OTHER | Oracle outside in Lotus 1-2-3 heap overflow attempt | off | off | off |
1 | 24039 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX function call access | off | drop | drop |
1 | 24040 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX clsid access | off | drop | drop |
1 | 24041 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX clsid access | off | drop | drop |
1 | 24042 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX clsid access | off | drop | drop |
1 | 24043 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX clsid access | off | drop | drop |
1 | 24044 | BROWSER-PLUGINS | HP Easy Printer Care Software ActiveX clsid access | off | drop | drop |
1 | 24063 | FILE-JAVA | Oracle Java privileged protection domain exploitation attempt | drop | drop | drop |
1 | 24091 | SERVER-WEBAPP | SAP NetWeaver SOAP interface command injection attempt | off | off | off |
1 | 24142 | FILE-FLASH | Adobe Flash Player object confusion attempt | off | drop | drop |
1 | 24195 | SERVER-WEBAPP | socket_connect buffer overflow attempt | off | off | off |
1 | 24196 | BROWSER-PLUGINS | GE Intelligent Platforms Proficy HTML help ActiveX clsid access attempt | off | drop | drop |
1 | 24199 | SERVER-MAIL | IBM Lotus Notes URI handler command execution attempt | off | drop | drop |
1 | 24201 | FILE-JAVA | Oracle Java field bytecode verifier cache code execution attempt | drop | drop | drop |
1 | 24202 | FILE-JAVA | Oracle Java field bytecode verifier cache code execution attempt | off | drop | drop |
1 | 24207 | FILE-OTHER | IBM Lotus Notes LZH Attachment Viewer buffer overflow | off | drop | drop |
1 | 24208 | FILE-OTHER | IBM Lotus Notes LZH Attachment Viewer buffer overflow | off | drop | drop |
1 | 24210 | BROWSER-IE | Microsoft Internet Explorer execCommand use-after-free attempt | off | off | off |
1 | 24212 | BROWSER-IE | Microsoft Internet Explorer execCommand use-after-free attempt | off | drop | drop |
1 | 24239 | SERVER-WEBAPP | Novell GroupWise Internet Agent content-length integer overflow attempt | drop | drop | drop |
1 | 24244 | FILE-FLASH | Adobe Flash Player Matrix3D copyRawDataTo integer overflow attempt | off | drop | drop |
1 | 24245 | FILE-FLASH | Adobe Flash Player Matrix3D copyRawDataTo integer overflow attempt | off | drop | drop |
1 | 24252 | BROWSER-IE | Microsoft Internet Explorer execCommand use embedded within javascript tags | off | drop | drop |
1 | 24267 | FILE-OFFICE | Microsoft Office Excel Malformed Range Code Execution attempt | off | off | off |
1 | 24268 | FILE-OFFICE | Microsoft Office Excel Malformed Range Code Execution attempt | off | off | off |
1 | 24269 | FILE-OFFICE | Microsoft Office Excel Malformed Range Code Execution attempt | off | off | off |
1 | 24281 | BROWSER-PLUGINS | Cisco Secure Desktop CSDWebInstaller ActiveX clsid access | off | drop | drop |
1 | 24284 | FILE-OFFICE | Microsoft Office Drawing object code execution attempt | off | off | off |
1 | 24293 | SERVER-OTHER | EMC NetWorker SunRPC buffer overflow attempt | off | off | off |
1 | 24315 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24316 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24317 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24318 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24319 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24320 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24321 | SERVER-OTHER | HP StorageWorks File Migration Agent buffer overflow attempt | off | off | off |
1 | 24329 | SERVER-OTHER | EMC AutoStart ftAgent.exe integer overflow attempt | off | off | off |
1 | 24335 | BROWSER-PLUGINS | Citrix Access Gateway plug-in buffer overflow attempt | off | off | off |
1 | 24336 | OS-WINDOWS | SMB Microsoft Windows RAP API NetServerEnum2 long comment buffer overflow attempt | off | off | off |
1 | 24338 | FILE-OTHER | Apple Quicktime TeXML Style attribute overflow attempt | off | drop | drop |
1 | 24351 | FILE-OFFICE | Microsoft Works 9 use-after-free attempt | off | drop | drop |
1 | 24352 | FILE-OFFICE | Microsoft Works 9 use-after-free attempt | off | drop | drop |
1 | 24353 | FILE-OFFICE | Microsoft Office Word RTF malformed listid attempt | off | drop | drop |
1 | 24354 | FILE-OFFICE | Microsoft Office Word RTF malformed listid attempt | off | drop | drop |
1 | 24357 | FILE-OFFICE | Microsoft Office Word rgfc value overflow attempt | off | drop | drop |
1 | 24358 | FILE-OFFICE | Microsoft Office Word rgfc value overflow attempt | off | drop | drop |
1 | 24428 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | drop | drop | drop |
1 | 24429 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | off | drop | drop |
1 | 24430 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | drop | drop | drop |
1 | 24431 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | off | drop | drop |
1 | 24435 | SERVER-WEBAPP | Novell ZENworks Asset Management default admin credentials function call attempt | off | off | off |
1 | 24436 | SERVER-WEBAPP | Novell ZENworks Asset Management default admin credentials function call attempt | off | off | off |
1 | 24446 | SERVER-OTHER | EMC NetWorker SunRPC format string exploit attempt | off | drop | drop |
1 | 24480 | PROTOCOL-SCADA | WellinTech Kingview HMI history server buffer overflow attempt | drop | drop | drop |
1 | 24485 | FILE-PDF | Microsoft Windows kernel-mode drivers core font parsing integer overflow attempt | off | off | drop |
1 | 24486 | FILE-PDF | Microsoft Windows kernel-mode drivers core font parsing integer overflow attempt | off | off | drop |
1 | 24487 | FILE-PDF | Microsoft Windows kernel-mode drivers core font parsing integer overflow attempt | off | off | off |
1 | 24507 | FILE-PDF | Adobe Acrobat font parsing integer overflow attempt | off | off | drop |
1 | 24508 | FILE-PDF | Adobe Acrobat font parsing integer overflow attempt | off | off | drop |
1 | 24520 | SERVER-WEBAPP | Avaya IP Office Customer Call Reporter invalid file upload attempt | alert | alert | drop |
1 | 24549 | FILE-MULTIMEDIA | Apple QuickTime MOV Atom length buffer overflow attempt | off | drop | drop |
1 | 24554 | FILE-IDENTIFY | Apple QuickTime PICT v2.0 Image header | off | off | off |
1 | 24555 | FILE-IDENTIFY | Apple QuickTime PICT v2.0 Image header | off | off | off |
1 | 24559 | BROWSER-PLUGINS | CYME Power Engineering ShowPropertiesDialog ActiveX clsid access | off | off | off |
1 | 24560 | BROWSER-PLUGINS | CYME Power Engineering ShowPropertiesDialog ActiveX function call access | off | off | off |
1 | 24570 | BROWSER-FIREFOX | Mozilla Firefox IDB use-after-free attempt | off | drop | drop |
1 | 24571 | BROWSER-FIREFOX | Mozilla Firefox IDB use-after-free attempt | drop | drop | drop |
1 | 24572 | BROWSER-FIREFOX | Mozilla Firefox IDB use-after-free attempt | drop | drop | drop |
1 | 24573 | BROWSER-FIREFOX | Mozilla Firefox IDB use-after-free attempt | off | drop | drop |
1 | 24574 | BROWSER-FIREFOX | Mozilla Firefox IDB use-after-free attempt | off | drop | drop |
1 | 24587 | FILE-OFFICE | Microsoft Works Word document use after free attempt | off | drop | drop |
1 | 24588 | FILE-OFFICE | Microsoft Works Word document use after free attempt | off | drop | drop |
1 | 24599 | FILE-IDENTIFY | Alt-N MDaemon IMAP Server | off | off | off |
1 | 24639 | PROTOCOL-RPC | portmap CA BrightStor ARCserve tcp procedure 122 invalid function call attempt | off | off | off |
1 | 24640 | FILE-MULTIMEDIA | Apple QuickTime movie buffer overflow attempt | off | off | off |
1 | 24645 | BROWSER-PLUGINS | Tom Sawyer GET Extension ActiveX clsid access | off | drop | drop |
1 | 24646 | BROWSER-PLUGINS | Tom Sawyer GET exetension ActiveX clsid access | off | drop | drop |
1 | 24675 | BROWSER-PLUGINS | Novell iPrint ActiveX realm parameter overflow attempt | drop | drop | drop |
1 | 24676 | BROWSER-PLUGINS | Novell iPrint ActiveX real parameter overflow attempt | drop | drop | drop |
1 | 24678 | FILE-OTHER | Cisco WebEx recording format buffer overflow attempt | off | drop | drop |
1 | 24679 | FILE-OTHER | Cisco WebEx recording format buffer overflow attempt | off | drop | drop |
1 | 24680 | FILE-OTHER | Cisco WebEx recording format buffer overflow attempt | off | drop | drop |
1 | 24686 | SERVER-OTHER | HP StorageWorks file migration agent buffer overflow attempt | off | off | off |
1 | 24687 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 24688 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 24693 | SERVER-WEBAPP | HP OpenView CGI parameter buffer overflow attempt | drop | drop | drop |
1 | 24694 | FILE-IMAGE | Apple QuickTime PICT file opcode corruption attempt | off | drop | drop |
1 | 24696 | PROTOCOL-RPC | EMC Networker nsrindexd.exe procedure 0x01 buffer overflow attempt | off | drop | drop |
1 | 24700 | FILE-MULTIMEDIA | Apple QuickTime text track descriptors heap buffer overflow attempt | off | drop | drop |
1 | 24701 | FILE-JAVA | Oracle Java Runtime true type font idef opcode heap buffer overflow attempt | drop | drop | drop |
1 | 24704 | SERVER-WEBAPP | CA Total Defense management.asmx sql injection attempt | drop | drop | drop |
1 | 24705 | SERVER-WEBAPP | CA Total Defense management.asmx sql injection attempt | drop | drop | drop |
1 | 24706 | SERVER-WEBAPP | Netop Remote Control dws file buffer overflow attempt | off | off | off |
1 | 24711 | FILE-IMAGE | Oracle Outside In JPEG COD parameter buffer overflow attempt | off | off | off |
1 | 24712 | FILE-IMAGE | Oracle Outside In JPEG COC parameter buffer overflow attempt | off | off | off |
1 | 24713 | FILE-IMAGE | Oracle Outside In JPEG COD parameter buffer overflow attempt | off | off | off |
1 | 24714 | FILE-IMAGE | Oracle Outside In JPEG COC parameter buffer overflow attempt | off | off | off |
1 | 24715 | FILE-IMAGE | Oracle Outside In JPEG COD parameter buffer overflow attempt | off | off | off |
1 | 24716 | FILE-IMAGE | Oracle Outside In JPEG COC parameter buffer overflow attempt | off | off | off |
1 | 24717 | FILE-IMAGE | Oracle Outside In JPEG COD parameter buffer overflow attempt | off | off | off |
1 | 24718 | FILE-IMAGE | Oracle Outside In JPEG COC parameter buffer overflow attempt | off | off | off |
1 | 24723 | BROWSER-PLUGINS | IBM Rational Rhapsody BBFlashback ActiveX clsid access attempt | off | drop | drop |
1 | 24738 | SERVER-OTHER | EMC AutoStart ftAgent.exe integer overflow attempt | off | off | off |
1 | 24739 | SERVER-OTHER | Gimp Script-Fu server buffer overflow attempt | off | off | off |
1 | 24741 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24742 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24743 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24744 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24745 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24746 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24747 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24748 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24749 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24750 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24751 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24752 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24753 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24754 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24755 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24756 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24757 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24758 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24759 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24760 | SERVER-OTHER | Citrix Provisioning Services multiple opcode integer overflow attempt | off | off | off |
1 | 24768 | SERVER-OTHER | RealPlayer Helix rn5auth credential overflow attempt | off | off | off |
1 | 24769 | FILE-JAVA | Oracle Java privileged protection domain exploitation attempt | drop | drop | drop |
1 | 24773 | BROWSER-PLUGINS | IBM Lotus iNotes buffer overflow ActiveX clsid access | off | drop | drop |
1 | 24774 | BROWSER-PLUGINS | ASUS Net4Switch ipswcom.dll ActiveX clsid access | off | off | off |
1 | 24776 | BROWSER-PLUGINS | ASUS Net4Switch ipswcom.dll ActiveX clsid access | off | off | off |
1 | 24801 | SERVER-WEBAPP | IBM Tivoli Provisioning Manager Express asset.getmimetype sql injection attempt | off | off | off |
1 | 24802 | SERVER-OTHER | HP Database Archiving Software GIOP parsing buffer overflow attempt | drop | drop | drop |
1 | 24803 | PROTOCOL-SCADA | GE Proficy Real-Time Information Portal directory traversal attempt | off | off | off |
1 | 24827 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24828 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24829 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24830 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24831 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24832 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24833 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24834 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24835 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24836 | SERVER-WEBAPP | HP OpenView Operations Agent buffer overflow attempt | drop | drop | drop |
1 | 24874 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | drop | drop | drop |
1 | 24875 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | off | drop | drop |
1 | 24876 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | drop | drop | drop |
1 | 24877 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | off | drop | drop |
1 | 24898 | SERVER-OTHER | ABB Multiple Product RobNetScanHost.exe buffer overflow attempt | drop | drop | drop |
1 | 24911 | SERVER-ORACLE | Oracle Outside In Excel file parsing integer overflow attempt | off | off | off |
1 | 24914 | SERVER-WEBAPP | HP OpenView NNM ovutil.dll getProxiedStorageAddress buffer overflow attempt | off | off | drop |
1 | 24957 | BROWSER-PLUGINS | Microsoft dpnet.dll DirectPlay ActiveX clsid access | off | drop | drop |
1 | 24958 | BROWSER-PLUGINS | Microsoft dpnet.dll DirectPlay ActiveX clsid access | off | drop | drop |
1 | 24959 | BROWSER-PLUGINS | Microsoft dpnet.dll DirectPlay ActiveX clsid access | off | drop | drop |
1 | 24960 | BROWSER-PLUGINS | Microsoft dpnet.dll DirectPlay ActiveX clsid access | off | drop | drop |
1 | 24961 | BROWSER-PLUGINS | Microsoft dpnet.dll DirectPlay ActiveX clsid access | off | drop | drop |
1 | 24962 | BROWSER-PLUGINS | Microsoft dpnet.dll DirectPlay ActiveX clsid access | off | drop | drop |
1 | 24963 | BROWSER-PLUGINS | Microsoft DirectPlay ActiveX clsid access | off | drop | drop |
1 | 24974 | FILE-OFFICE | Microsoft Office Word rtf invalid listoverridecount value attempt | off | drop | drop |
1 | 24975 | FILE-OFFICE | Microsoft Office Word rtf invalid listoverridecount value attempt | off | drop | drop |
1 | 24987 | POLICY-OTHER | Adobe InDesign SOAP interface RunScript method access attempt | off | off | off |
1 | 24994 | BROWSER-FIREFOX | Mozilla Firefox onChannelRedirect method attempt | drop | drop | drop |
1 | 24995 | SERVER-OTHER | Free Software Foundation GnuTLS record application integer overflow attempt | off | off | off |
1 | 24998 | FILE-OTHER | Cisco WebEx recording format buffer overflow attempt | off | drop | drop |
1 | 25003 | SERVER-OTHER | HP Archive Query Server stack overflow attempt | drop | drop | drop |
1 | 25005 | BROWSER-PLUGINS | ClearQuest session stack corruption attempt | off | drop | drop |
1 | 25006 | FILE-JAVA | Oracle JavaScript heap exploitation library usage attempt | off | drop | drop |
1 | 25019 | OS-OTHER | Cisco Nexus OS software command injection attempt | off | off | off |
1 | 25035 | BROWSER-PLUGINS | Microsoft Silverlight inheritance restriction bypass | off | drop | drop |
1 | 25037 | BROWSER-WEBKIT | Apple Safari Webkit css title memory corruption attempt | off | off | off |
1 | 25038 | BROWSER-WEBKIT | Apple Safari Webkit css title memory corruption attempt | off | off | off |
1 | 25061 | FILE-EXECUTABLE | Microsoft Software Installer MSI binary file magic detected | off | off | off |
1 | 25063 | SERVER-WEBAPP | PHP htmlspecialchars htmlentities function buffer overflow attempt | off | off | off |
1 | 25078 | BROWSER-IE | Microsoft Internet Explorer sign extension vulnerability exploitation attempt | off | drop | drop |
1 | 25111 | BROWSER-PLUGINS | Oracle SetMarkupMode buffer overflow ActiveX clsid access attempt | off | off | off |
1 | 25112 | BROWSER-PLUGINS | Oracle SetMarkupMode buffer overflow ActiveX function call access attempt | off | off | off |
1 | 25113 | BROWSER-PLUGINS | Oracle SetMarkupMode buffer overflow ActiveX function call access attempt | off | off | off |
1 | 25114 | BROWSER-PLUGINS | Oracle SetMarkupMode buffer overflow ActiveX function call access attempt | off | off | off |
1 | 25115 | BROWSER-PLUGINS | Oracle SetMarkupMode buffer overflow ActiveX clsid access attempt | off | off | off |
1 | 25116 | BROWSER-PLUGINS | Oracle SetMarkupMode buffer overflow ActiveX function call access attempt | off | off | off |
1 | 25117 | BROWSER-PLUGINS | Oracle SetMarkupMode buffer overflow ActiveX function call access attempt | off | off | off |
1 | 25118 | BROWSER-PLUGINS | Oracle SetMarkupMode buffer overflow ActiveX function call access attempt | off | off | off |
1 | 25122 | FILE-JAVA | Oracle Java field bytecode verifier cache code execution attempt | drop | drop | drop |
1 | 25123 | FILE-JAVA | Oracle Java field bytecode verifier cache code execution attempt | drop | drop | drop |
1 | 25225 | BROWSER-IE | Microsoft Internet Explorer Marquee stylesheet object removal | off | drop | drop |
1 | 25226 | BROWSER-IE | Microsoft Internet Explorer Marquee stylesheet object removal | off | drop | drop |
1 | 25252 | FILE-EXECUTABLE | Microsoft Windows .NET Framework System.Uri.ReCreateParts System.Uri.PathAndQuery overflow attempt | off | drop | drop |
1 | 25253 | FILE-EXECUTABLE | Microsoft Windows .NET Framework System.Uri.ReCreateParts System.Uri.PathAndQuery overflow attempt | off | drop | drop |
1 | 25287 | SERVER-OTHER | Rails XML parameter parsing vulnerability exploitation attempt | off | off | drop |
1 | 25288 | SERVER-OTHER | Rails XML parameter parsing vulnerability exploitation attempt | off | off | drop |
1 | 25293 | FILE-OFFICE | Microsoft Office Excel IPMT record buffer overflow attempt | off | drop | drop |
1 | 25297 | FILE-MULTIMEDIA | Mozilla products Ogg Vorbis decoding memory corruption attempt | drop | drop | drop |
1 | 25299 | BROWSER-PLUGINS | IBM VsVIEW ActiveX control directory traversal attempt | off | drop | drop |
1 | 25300 | BROWSER-PLUGINS | IBM VsVIEW ActiveX control directory traversal attempt | off | drop | drop |
1 | 25303 | FILE-OTHER | Cisco WebEx WRF memory corruption attempt | off | drop | drop |
1 | 25304 | FILE-OTHER | Cisco WebEx WRF memory corruption attempt | off | drop | drop |
1 | 25309 | FILE-OTHER | Adobe Audition Session file stack buffer overflow attempt | off | drop | drop |
1 | 25310 | FILE-OTHER | Adobe Audition Session file stack buffer overflow attempt | off | drop | drop |
1 | 25312 | SERVER-OTHER | Microsoft Forefront Threat Management Gateway remote code execution attempt | drop | drop | drop |
1 | 25315 | SERVER-ORACLE | Oracle TNS listener service registration | off | off | off |
1 | 25316 | BROWSER-PLUGINS | InduSoft ISSymbol InternationalSeparator heap overflow attempt | off | drop | drop |
1 | 25317 | POLICY-OTHER | RedHat JBOSS JNDI service naming | off | off | off |
1 | 25318 | SERVER-WEBAPP | InduSoft Web Studio arbitrary file upload attempt | drop | drop | drop |
1 | 25319 | SERVER-WEBAPP | InduSoft Web Studio arbitrary file upload attempt | drop | drop | drop |
1 | 25321 | SERVER-ORACLE | Oracle Database tablefunc_asown buffer overflow attempt | off | off | drop |
1 | 25329 | BROWSER-IE | Microsoft Internet Explorer CSS style memory corruption attempt | off | off | off |
1 | 25330 | FILE-OFFICE | Microsoft Office Excel conditional code execution attempt | off | drop | drop |
1 | 25331 | FILE-OFFICE | Microsoft Office Excel conditional code execution attempt | off | drop | drop |
1 | 25332 | FILE-OTHER | Adobe Audition Session file tkrm stack buffer overflow attempt | off | drop | drop |
1 | 25333 | PROTOCOL-DNS | Exim DKIM decoding buffer overflow attempt | off | off | off |
1 | 25334 | SERVER-OTHER | Novell File Reporter record tag parsing buffer overflow attempt | off | off | off |
1 | 25335 | SERVER-OTHER | Novell File Reporter record tag parsing buffer overflow attempt | off | off | off |
1 | 25336 | SERVER-OTHER | Novell File Reporter record tag parsing buffer overflow attempt | off | off | off |
1 | 25337 | SERVER-OTHER | Novell File Reporter record tag parsing buffer overflow attempt | off | off | off |
1 | 25338 | SERVER-OTHER | Novell File Reporter record tag parsing buffer overflow attempt | off | off | off |
1 | 25339 | SERVER-OTHER | Novell File Reporter record tag parsing buffer overflow attempt | off | off | off |
1 | 25340 | SERVER-OTHER | Novell File Reporter record tag parsing buffer overflow attempt | off | off | off |
1 | 25341 | FILE-OTHER | Cisco WebEx player remote code execution attempt | off | drop | drop |
1 | 25343 | BROWSER-PLUGINS | Citrix Access Gateway plug-in ActiveX code execution attempt | off | drop | drop |
1 | 25344 | BROWSER-PLUGINS | Citrix Access Gateway plug-in ActiveX code execution attempt | off | drop | drop |
1 | 25345 | SERVER-WEBAPP | Symantec IM Manager Web interface arbitrary command execution attempt | off | off | off |
1 | 25346 | FILE-IMAGE | ImageMagick EXIF resolutionunit handling memory corruption attempt | off | drop | drop |
1 | 25347 | FILE-IMAGE | ImageMagick EXIF resolutionunit handling memory corruption attempt | off | drop | drop |
1 | 25348 | FILE-IMAGE | ImageMagick EXIF resolutionunit handling memory corruption attempt | off | drop | drop |
1 | 25352 | SERVER-OTHER | HP HP Intelligent Management Center syslog remote code execution attempt | off | off | off |
1 | 25353 | FILE-OFFICE | Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord exploit attempt | off | alert | drop |
1 | 25354 | FILE-OFFICE | Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord exploit attempt | off | alert | drop |
1 | 25355 | FILE-OFFICE | Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord exploit attempt | off | alert | drop |
1 | 25356 | SERVER-OTHER | Squid Gopher response processing buffer overflow attempt | off | off | off |
1 | 25357 | FILE-EXECUTABLE | Microsoft Windows Authenticode signature verification bypass attempt | off | drop | drop |
1 | 25366 | FILE-OFFICE | Microsoft Office Excel invalid Window2 BIFF record value attempt | off | drop | drop |
1 | 25367 | FILE-OFFICE | Microsoft Office Excel invalid Window2 BIFF record value attempt | off | drop | drop |
1 | 25380 | SERVER-OTHER | EMC AutoStart domain name logging stack buffer overflow attempt | off | off | off |
1 | 25472 | FILE-JAVA | Oracle Java JMX class arbitrary code execution attempt | drop | drop | drop |
1 | 25534 | SERVER-WEBAPP | Sonicwall Global Management System authentication bypass attempt | off | off | off |
1 | 25535 | PROTOCOL-SERVICES | Cisco Prime Lan Management rsh command execution attempt | drop | drop | drop |
1 | 25542 | PROTOCOL-RPC | EMC NetWorker nsrindexd service buffer overflow attempt | off | drop | drop |
1 | 25549 | SERVER-OTHER | Novell eDirectory NCP stack buffer overflow attempt | drop | drop | drop |
1 | 25550 | SERVER-OTHER | Novell eDirectory NCP stack buffer overflow attempt | drop | drop | drop |
1 | 25562 | FILE-JAVA | Oracle Java obfuscated jar file download attempt | off | off | off |
1 | 25582 | SERVER-OTHER | EMC AlphaStor Device Manager command injection attempt | off | drop | drop |
1 | 25586 | SERVER-WEBAPP | Nagios Core get_history buffer overflow attempt | off | off | off |
1 | 25634 | INDICATOR-SHELLCODE | unescape encoder shellcode | off | off | off |
1 | 25636 | INDICATOR-SHELLCODE | unescape encoded shellcode | off | off | off |
1 | 25639 | INDICATOR-SHELLCODE | unescape encoded shellcode | off | off | off |
1 | 25640 | INDICATOR-SHELLCODE | unescape encoded shellcode | off | off | off |
1 | 25644 | FILE-OTHER | Apple QuickTime TeXML style sub-element buffer overflow attempt | off | drop | drop |
1 | 25645 | FILE-OTHER | Apple QuickTime TeXML style sub-element buffer overflow attempt | off | drop | drop |
1 | 25646 | FILE-OTHER | Apple QuickTime TeXML style sub-element buffer overflow attempt | off | drop | drop |
1 | 25647 | FILE-OTHER | Apple QuickTime TeXML style sub-element buffer overflow attempt | off | drop | drop |
1 | 25648 | FILE-OTHER | Apple QuickTime TeXML style sub-element buffer overflow attempt | off | drop | drop |
1 | 25659 | BLACKLIST | User-Agent known malicious user agent - spam_bot | off | drop | drop |
1 | 25676 | FILE-FLASH | Adobe Flash malformed regular expression exploit attempt | off | drop | drop |
1 | 25677 | FILE-FLASH | Adobe Flash malformed regular expression exploit attempt | off | drop | drop |
1 | 25678 | FILE-FLASH | Adobe Flash malformed regular expression exploit attempt | off | drop | drop |
1 | 25679 | FILE-FLASH | Adobe Flash malformed regular expression exploit attempt | off | drop | drop |
1 | 25681 | FILE-FLASH | Adobe Flash Player CFF FeatureCount integer overflow attempt | off | drop | drop |
1 | 25803 | EXPLOIT-KIT | Multiple exploit kit jar file dropped | off | drop | drop |
1 | 25810 | FILE-OTHER | VMWare OVF Tool format string exploit attempt | off | off | drop |
1 | 25811 | FILE-OTHER | VMWare OVF Tool format string exploit attempt | off | off | drop |
1 | 25817 | BLACKLIST | DNS request for known malware domain bolsilloner.es | off | off | off |
1 | 25818 | FILE-PDF | Adobe Acrobat Reader known malicious variable exploit attempt | off | drop | drop |
1 | 25819 | FILE-PDF | Adobe Acrobat Reader known malicious variable exploit attempt | off | drop | drop |
1 | 25830 | FILE-JAVA | Oracle Java malicious class download attempt | drop | drop | drop |
1 | 25849 | PROTOCOL-SCADA | Schneider Electric IGSS integer underflow attempt | off | off | off |
1 | 25850 | PROTOCOL-SCADA | Schneider Electric IGSS integer underflow attempt | off | off | off |
1 | 25851 | PROTOCOL-SCADA | Schneider Electric IGSS integer underflow attempt | drop | drop | drop |
1 | 25852 | PROTOCOL-SCADA | Schneider Electric IGSS integer underflow attempt | drop | drop | drop |
1 | 25984 | BROWSER-IE | Microsoft Internet Explorer userdata behavior memory corruption attempt | off | off | drop |
1 | 25985 | BROWSER-IE | Microsoft Internet Explorer userdata behavior memory corruption attempt | off | off | drop |
1 | 25986 | BROWSER-IE | Microsoft Internet Explorer userdata behavior memory corruption attempt | off | off | drop |
1 | 26021 | FILE-PDF | Adobe Acrobat Reader XML Java used in app.setTimeOut | off | drop | drop |
1 | 26076 | FILE-PDF | download of a PDF with embedded JavaScript - JS string attempt | off | off | off |
1 | 26077 | FILE-PDF | transfer of a PDF with embedded JavaScript - JavaScript object detected | off | off | off |
1 | 26078 | FILE-PDF | transfer of a PDF with OpenAction object attempt | off | off | off |
1 | 26103 | SERVER-OTHER | HP LeftHand Virtual SAN hydra ping request buffer overflow attempt | drop | drop | drop |
1 | 26105 | SERVER-OTHER | BigAnt IM Server buffer overflow attempt | drop | drop | drop |
1 | 26110 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 26111 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 26112 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 26113 | FILE-PDF | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 26193 | BROWSER-PLUGINS | Honeywell HscRemoteDeploy ActiveX control arbitrary HTA execution attempt | off | off | off |
1 | 26231 | FILE-PDF | PDF version 1.1 with FlateDecode embedded - seen in exploit kits | off | off | off |
1 | 26263 | SERVER-WEBAPP | Wordpress wp-banners-lite plugin cross site scripting attempt | off | off | off |
1 | 26264 | MALWARE-CNC | Dapato banking Trojan variant outbound connection | off | drop | drop |
1 | 26265 | BLACKLIST | DNS request for known malware domain mercury.yori.pl - Kazy Trojan | off | drop | drop |
1 | 26280 | FILE-PDF | Foxit Reader remote query string buffer overflow attempt | off | off | off |
1 | 26281 | FILE-PDF | Foxit Reader remote query string buffer overflow attempt | off | off | off |
1 | 26282 | FILE-PDF | Foxit Reader remote query string buffer overflow attempt | off | off | off |
1 | 26283 | FILE-PDF | Foxit Reader remote query string buffer overflow attempt | off | off | off |
1 | 26355 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26356 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26357 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26358 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26359 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26360 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26361 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26362 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26363 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26364 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26365 | BROWSER-PLUGINS | Microsoft Windows RDP ActiveX component mstscax use after free attempt | off | drop | drop |
1 | 26392 | PROTOCOL-SCADA | Schneider Electric IGSS integer underflow attempt | drop | drop | drop |
1 | 26414 | PROTOCOL-SCADA | CODESYS Gateway-Server executable file upload attempt | drop | drop | drop |
1 | 26415 | PROTOCOL-SCADA | CODESYS Gateway-Server directory traversal attempt | drop | drop | drop |
1 | 26416 | SERVER-WEBAPP | HP Intelligent Management Center mibFileUpload servlet arbitrary file upload attempt | drop | drop | drop |
1 | 26417 | SERVER-WEBAPP | HP Intelligent Management Center mibFileUpload servlet arbitrary file upload attempt | drop | drop | drop |
1 | 26418 | SERVER-WEBAPP | HP System Management iprange parameter buffer overflow attempt | off | off | off |
1 | 26479 | SERVER-OTHER | ActFax LPD Server data field buffer overflow attempt | off | off | off |
1 | 26488 | PROTOCOL-SCADA | CODESYS Gateway-Server directory traversal attempt | drop | drop | drop |
1 | 26491 | SERVER-OTHER | Nagios NRPE command execution attempt | off | off | off |
1 | 26495 | FILE-OTHER | WellinTech KingView KingMessage log file parsing buffer overflow attempt | drop | drop | drop |
1 | 26496 | FILE-OTHER | WellinTech KingView KingMessage log file parsing buffer overflow attempt | off | drop | drop |
1 | 26501 | SERVER-OTHER | BigAnt Document Service DDNF request stack buffer overflow attempt | off | off | off |
1 | 26502 | PROTOCOL-SCADA | 3S CoDeSys Gateway Server stack buffer overflow attempt | drop | drop | drop |
1 | 26503 | PROTOCOL-SCADA | 3S CoDeSys Gateway Server stack buffer overflow attempt | drop | drop | drop |
1 | 26504 | PROTOCOL-SCADA | 3S CoDeSys Gateway Server stack buffer overflow attempt | drop | drop | drop |
1 | 26513 | FILE-PDF | PDF with large embedded JavaScript - JS string attempt | off | off | off |
1 | 26547 | SERVER-WEBAPP | phpMyAdmin preg_replace remote code execution attempt | off | off | off |
1 | 26548 | SERVER-WEBAPP | HP OpenView NNM webappmon.exe buffer overflow attempt | off | off | drop |
1 | 26573 | BROWSER-PLUGINS | Honeywell HscRemoteDeploy ActiveX control arbitrary HTA execution attempt | off | off | off |
1 | 26584 | BROWSER-IE | Microsoft Internet Explorer vector graphics reference counting use-after-free attempt | off | drop | drop |
1 | 26587 | FILE-JAVA | Oracle Java runtime JMX findclass sandbox breach attempt | off | off | off |
1 | 26588 | FILE-JAVA | Oracle Java runtime JMX findclass sandbox breach attempt | off | off | off |
1 | 26595 | INDICATOR-OBFUSCATION | javascript hex character extraction routine detected | off | off | off |
1 | 26596 | INDICATOR-OBFUSCATION | javascript fromCharCode xor decryption routine detected | off | off | off |
1 | 26651 | FILE-PDF | Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt | drop | drop | drop |
1 | 26652 | FILE-PDF | Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt | off | drop | drop |
1 | 26664 | FILE-IMAGE | BMP extremely large xpos opcodes | drop | drop | drop |
1 | 26704 | SERVER-WEBAPP | LANDesk Thinkmanagement Suite ServerSetup directory traversal attempt | off | off | off |
1 | 26761 | OS-MOBILE | Android Fakedoc device information leakage | off | off | off |
1 | 26786 | INDICATOR-SHELLCODE | unescape encoded shellcode | off | off | off |
1 | 26787 | INDICATOR-SHELLCODE | unescape encoded shellcode | off | off | off |
1 | 26790 | INDICATOR-SHELLCODE | unescape encoded shellcode | off | off | off |
1 | 26791 | INDICATOR-SHELLCODE | unescape encoded shellcode | off | off | off |
1 | 26808 | EXPLOIT-KIT | Goon/Infinity/Redkit exploit kit short jar request | off | off | off |
1 | 26824 | SERVER-OTHER | Apache Struts allowStaticMethodAccess invocation attempt | off | drop | drop |
1 | 26825 | SERVER-OTHER | Apache Struts allowStaticMethodAccess invocation attempt | off | drop | drop |
1 | 26848 | BROWSER-IE | Microsoft Internet Explorer 7 emulation via meta tag | off | off | off |
1 | 26854 | FILE-IMAGE | Microsoft Windows Media Player Malformed PNG detected cHRM overflow attempt | off | off | off |
1 | 26855 | FILE-IMAGE | Microsoft Windows Media Player Malformed PNG detected iCCP overflow attempt | off | off | off |
1 | 26860 | FILE-IMAGE | Microsoft Windows Media Player Malformed PNG detected tRNS overflow attempt | off | off | off |
1 | 26927 | FILE-PDF | Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt | drop | drop | drop |
1 | 26928 | FILE-PDF | Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt | off | drop | drop |
1 | 26973 | FILE-OFFICE | Microsoft Office Visio TAG_xxxSect code execution attempt | off | drop | drop |
1 | 26976 | FILE-IMAGE | Oracle Outside In FlashPix image processing overflow attempt | off | off | off |
1 | 26977 | FILE-IMAGE | Oracle Outside In FlashPix image processing overflow attempt | off | off | off |
1 | 26979 | FILE-IMAGE | Oracle Outside In FlashPix image processing overflow attempt | off | off | off |
1 | 27018 | SERVER-WEBAPP | Novell ZENworks Mobile Management dusap.php directory traversal attempt | off | off | off |
1 | 27019 | SERVER-WEBAPP | Novell ZENworks Mobile Management dusap.php directory traversal attempt | off | off | off |
1 | 27020 | SERVER-WEBAPP | Novell ZENworks Mobile Management dusap.php directory traversal attempt | off | off | off |
1 | 27027 | POLICY-OTHER | PHP tag injection in http header attempt | off | off | off |
1 | 27028 | SERVER-WEBAPP | Novell ZENworks Mobile Management mdm.php directory traversal attempt | off | off | off |
1 | 27029 | SERVER-WEBAPP | Novell ZENworks Mobile Management mdm.php directory traversal attempt | off | off | off |
1 | 27030 | SERVER-WEBAPP | Novell ZENworks Mobile Management mdm.php directory traversal attempt | off | off | off |
1 | 27036 | SERVER-OTHER | Novell NetIQ User Manager modifyAccounts policy bypass attempt | off | off | off |
1 | 27075 | SERVER-OTHER | Novell NetIQ User Manager ldapagnt_eval remote code execution attempt | off | off | off |
1 | 27076 | FILE-JAVA | Oracle Java Applet disable security manager attempt | off | drop | drop |
1 | 27077 | FILE-JAVA | Oracle Java Applet disable security manager attempt | off | drop | drop |
1 | 27104 | SERVER-WEBAPP | HP System Management arbitrary command injection attempt | off | drop | drop |
1 | 27105 | SERVER-WEBAPP | HP System Management arbitrary command injection attempt | off | drop | drop |
1 | 27122 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt | drop | drop | drop |
1 | 27123 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 259 buffer overflow attempt | drop | drop | drop |
1 | 27124 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt | drop | drop | drop |
1 | 27125 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt | drop | drop | drop |
1 | 27150 | BROWSER-IE | Microsoft Internet Explorer use after free attempt | off | drop | drop |
1 | 27151 | BROWSER-IE | Microsoft Internet Explorer use after free attempt | off | drop | drop |
1 | 27152 | BROWSER-IE | Microsoft Internet Explorer use after free attempt | off | drop | drop |
1 | 27153 | BROWSER-IE | Microsoft Internet Explorer use after free attempt | off | drop | drop |
1 | 27170 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt | drop | drop | drop |
1 | 27171 | BROWSER-IE | Microsoft Internet Explorer use after free attempt | off | drop | drop |
1 | 27172 | BROWSER-IE | Microsoft Internet Explorer use after free attempt | off | drop | drop |
1 | 27182 | FILE-FLASH | Adobe Flash Player malicious swf file download attempt | off | off | off |
1 | 27183 | FILE-FLASH | Adobe Flash Player malicious swf file download attempt | off | off | off |
1 | 27184 | FILE-FLASH | Adobe Flash Player malicious swf file download attempt | off | off | off |
1 | 27185 | FILE-FLASH | Adobe Flash Player malicious swf file download attempt | off | off | off |
1 | 27186 | FILE-FLASH | Adobe Flash Player malicious swf file download attempt | off | off | off |
1 | 27187 | FILE-FLASH | Adobe Flash Player malicious swf file download attempt | off | off | off |
1 | 27188 | FILE-JAVA | Oracle Java Applet ProviderSkeleton sandbox bypass attempt | off | drop | drop |
1 | 27189 | FILE-JAVA | Oracle Java Applet ProviderSkeleton sandbox bypass attempt | off | drop | drop |
1 | 27190 | FILE-JAVA | Oracle Java Applet ProviderSkeleton sandbox bypass attempt | off | drop | drop |
1 | 27191 | FILE-JAVA | Oracle Java Applet ProviderSkeleton sandbox bypass attempt | off | drop | drop |
1 | 27211 | FILE-OFFICE | Microsoft Office Excel style handling overflow attempt | off | off | off |
1 | 27217 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 260 buffer overflow attempt | drop | drop | drop |
1 | 27232 | FILE-PDF | Adobe Acrobat Reader util.printf buffer overflow attempt | off | off | off |
1 | 27233 | FILE-PDF | Adobe Acrobat Reader util.printf buffer overflow attempt | off | off | off |
1 | 27245 | SERVER-APACHE | Apache Struts2 remote code execution attempt | off | drop | drop |
1 | 27261 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 215 buffer overflow attempt | drop | drop | drop |
1 | 27262 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 263 buffer overflow attempt | drop | drop | drop |
1 | 27264 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 227 buffer overflow attempt | drop | drop | drop |
1 | 27539 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt | drop | drop | drop |
1 | 27568 | BROWSER-FIREFOX | Mozilla Firefox 17 onreadystatechange memory corruption attempt | off | drop | drop |
1 | 27571 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt | drop | drop | drop |
1 | 27582 | FILE-OTHER | BitDefender Internet Security script code execution attempt | off | off | off |
1 | 27583 | FILE-OTHER | BitDefender Internet Security script code execution attempt | off | off | off |
1 | 27615 | BROWSER-IE | Microsoft Internet Explorer MoveToMarkupPointer call with CControlTracker OnExitTree use-after-free attempt | off | drop | drop |
1 | 27616 | BROWSER-IE | Microsoft Internet Explorer MoveToMarkupPointer call with CControlTracker OnExitTree use-after-free attempt | off | drop | drop |
1 | 27617 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 264 buffer overflow attempt | drop | drop | drop |
1 | 27621 | FILE-JAVA | Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt | drop | drop | drop |
1 | 27622 | FILE-JAVA | Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt | off | drop | drop |
1 | 27672 | FILE-JAVA | Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt | drop | drop | drop |
1 | 27673 | FILE-JAVA | Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt | off | drop | drop |
1 | 27674 | FILE-JAVA | Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt | drop | drop | drop |
1 | 27675 | FILE-JAVA | Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt | off | drop | drop |
1 | 27676 | FILE-JAVA | Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt | drop | drop | drop |
1 | 27677 | FILE-JAVA | Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt | off | drop | drop |
1 | 27691 | FILE-JAVA | Oracle Java IntegerInterleavedRaster integer overflow attempt | drop | drop | drop |
1 | 27692 | FILE-JAVA | Oracle Java IntegerInterleavedRaster integer overflow attempt | off | drop | drop |
1 | 27750 | FILE-JAVA | Oracle Java IntegerInterleavedRaster integer overflow attempt | drop | drop | drop |
1 | 27751 | FILE-JAVA | Oracle Java IntegerInterleavedRaster integer overflow attempt | off | drop | drop |
1 | 27769 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt | drop | drop | drop |
1 | 27770 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt | drop | drop | drop |
1 | 27771 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt | drop | drop | drop |
1 | 27772 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt | drop | drop | drop |
1 | 27773 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt | drop | drop | drop |
1 | 27781 | BROWSER-PLUGINS | Cisco WebEx Meeting Manager atucfobj ActiveX clsid access | off | off | off |
1 | 27782 | BROWSER-PLUGINS | Cisco WebEx Meeting Manager atucfobj ActiveX function call access | off | off | off |
1 | 27816 | EXPLOIT-KIT | Multiple exploit kit jar file download attempt | off | drop | drop |
1 | 27822 | FILE-OTHER | Microsoft Windows XP .theme file remote code execution attempt | off | drop | drop |
1 | 27837 | BROWSER-IE | Microsoft Internet Explorer CDisplayPointer use after free attempt | off | drop | drop |
1 | 27838 | BROWSER-IE | Microsoft Internet Explorer CDisplayPointer use after free attempt | off | drop | drop |
1 | 27843 | BROWSER-IE | Microsoft Internet Explorer CTreePos object use-after-free attempt | off | drop | drop |
1 | 27844 | BROWSER-IE | Microsoft Internet Explorer CTreePos object use-after-free attempt | off | drop | drop |
1 | 27862 | SERVER-WEBAPP | Avaya IP Office Customer Call Reporter invalid file upload attempt | alert | alert | drop |
1 | 27869 | BROWSER-PLUGINS | HP LoadRunner WriteFileString ActiveX function call attempt | drop | drop | drop |
1 | 27870 | BROWSER-PLUGINS | HP LoadRunner WriteFileString ActiveX function call attempt | drop | drop | drop |
1 | 27871 | BROWSER-PLUGINS | HP LoadRunner WriteFileString ActiveX function call attempt | off | drop | drop |
1 | 27872 | BROWSER-PLUGINS | HP LoadRunner WriteFileString ActiveX function call attempt | off | drop | drop |
1 | 27921 | SERVER-ORACLE | Oracle Endeca Server createDataStore remote command injection attempt | off | off | off |
1 | 27937 | SERVER-OTHER | HP ProCurve Manager SNAC UpdateCertificatesServlet directory traversal attempt | drop | drop | drop |
1 | 27941 | SERVER-OTHER | HP ProCurve Manager SNAC UpdateDomainControllerServlet directory traversal attempt | drop | drop | drop |
1 | 27943 | BROWSER-IE | Microsoft Internet Explorer onlosecapture memory corruption attempt | off | drop | drop |
1 | 27944 | BROWSER-IE | Microsoft Internet Explorer onlosecapture memory corruption attempt | off | drop | drop |
1 | 28135 | FILE-OFFICE | Microsoft Office Excel FtCbls remote code execution attempt | off | off | off |
1 | 28136 | FILE-OFFICE | Microsoft Office Excel FtCbls remote code execution attempt | off | off | off |
1 | 28207 | BROWSER-IE | Microsoft Internet Explorer swapNode memory corruption attempt | off | drop | drop |
1 | 28208 | BROWSER-IE | Microsoft Internet Explorer swapNode memory corruption attempt | off | drop | drop |
1 | 28227 | SERVER-OTHER | HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt | drop | drop | drop |
1 | 28252 | FILE-PDF | Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt | drop | drop | drop |
1 | 28256 | FILE-PDF | Adobe Acrobat Reader ICC mluc integer overflow attempt | off | off | off |
1 | 28257 | FILE-PDF | Adobe Acrobat Reader ICC remote memory corruption attempt | off | drop | drop |
1 | 28258 | BROWSER-IE | Microsoft Internet Explorer object management memory corruption attempt | off | drop | drop |
1 | 28259 | BROWSER-IE | Microsoft Internet Explorer object management memory corruption attempt | off | drop | drop |
1 | 28260 | FILE-PDF | Adobe Acrobat Reader ICC remote memory corruption attempt | off | drop | drop |
1 | 28261 | FILE-PDF | Adobe Acrobat Reader ICC mluc integer overflow attempt | off | off | off |
1 | 28262 | FILE-PDF | Adobe Acrobat Reader CoolType.dll glyf directory table buffer overflow attempt | off | drop | drop |
1 | 28266 | FILE-PDF | Adobe Acrobat Reader CoolType.dll composite glyf buffer overflow attempt | off | drop | drop |
1 | 28267 | BROWSER-IE | Microsoft Internet Explorer option element use after free attempt | off | drop | drop |
1 | 28268 | BROWSER-IE | Microsoft Internet Explorer option element use after free attempt | off | drop | drop |
1 | 28269 | BROWSER-IE | Microsoft Internet Explorer option element use after free attempt | off | drop | drop |
1 | 28270 | BROWSER-IE | Microsoft Internet Explorer option element use after free attempt | off | drop | drop |
1 | 28271 | BROWSER-IE | Microsoft Internet Explorer htmlfile null attribute access attempt | off | drop | drop |
1 | 28272 | BROWSER-PLUGINS | Microsoft Internet Explorer htmlfile ActiveX object access attempt | off | drop | drop |
1 | 28276 | FILE-JAVA | Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt | drop | drop | drop |
1 | 28277 | FILE-JAVA | Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt | off | drop | drop |
1 | 28278 | SERVER-WEBAPP | IBM Tivoli Provisioning Manager express user.updateUserValue sql injection attempt | off | drop | drop |
1 | 28287 | BROWSER-IE | Microsoft Internet Explorer deleted object cells reference memory corruption vulnerability | off | off | off |
1 | 28303 | FILE-PDF | Adobe Acrobat and Adobe Acrobat Reader U3D RHAdobeMeta buffer overflow attempt | off | off | off |
1 | 28306 | BROWSER-IE | Microsoft Internet Explorer CSS expression defined to empty selection attempt | off | drop | drop |
1 | 28309 | EXPLOIT-KIT | Himan exploit kit payload - Oracle Java compromise | off | drop | drop |
1 | 28315 | FILE-OTHER | Microsoft Office Image filter BMP overflow attempt | off | off | off |
1 | 28349 | BROWSER-PLUGINS | Microsoft Windows WMI administrator tools object viewer ActiveX clsid access | off | off | drop |
1 | 28350 | BROWSER-PLUGINS | Microsoft Windows WMI administrator tools object viewer ActiveX clsid access | off | off | drop |
1 | 28351 | BROWSER-PLUGINS | Microsoft Windows WMI administrator tools object viewer ActiveX clsid access | off | off | drop |
1 | 28352 | BROWSER-IE | Microsoft Internet Explorer CTableLayout memory corruption attempt | off | off | off |
1 | 28353 | BROWSER-IE | Microsoft Internet Explorer CTableLayout memory corruption attempt | off | off | off |
1 | 28354 | BROWSER-IE | Microsoft Internet Explorer DOM manipulation memory corruption attempt | off | drop | drop |
1 | 28355 | BROWSER-IE | Microsoft Internet Explorer DOM manipulation memory corruption attempt | off | drop | drop |
1 | 28356 | BROWSER-IE | Microsoft Internet Explorer DOM manipulation memory corruption attempt | off | drop | drop |
1 | 28357 | BROWSER-IE | Microsoft Internet Explorer DOM manipulation memory corruption attempt | off | drop | drop |
1 | 28358 | BROWSER-IE | Microsoft Internet Explorer DOM manipulation memory corruption attempt | off | drop | drop |
1 | 28359 | BROWSER-IE | Microsoft Internet Explorer DOM manipulation memory corruption attempt | off | drop | drop |
1 | 28360 | BROWSER-IE | Microsoft Internet Explorer DOM manipulation memory corruption attempt | off | drop | drop |
1 | 28361 | FILE-PDF | Adobe Acrobat Reader malformed shading modifier heap corruption attempt | drop | drop | drop |
1 | 28363 | BROWSER-IE | Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt | off | drop | drop |
1 | 28364 | BROWSER-IE | Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt | off | drop | drop |
1 | 28374 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28375 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28376 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28377 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28378 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28379 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28380 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28381 | MALWARE-OTHER | Win.Downloader.Temvice outbound communication attempt | off | drop | drop |
1 | 28388 | FILE-PDF | Adobe Acrobat TrueType font handling remote code execution attempt | off | off | drop |
1 | 28389 | FILE-PDF | Adobe Acrobat TrueType font handling remote code execution attempt | off | off | drop |
1 | 28394 | SERVER-OTHER | EMC AlphaStore format string vulnerability exploit attempt | off | off | off |
1 | 28395 | SERVER-OTHER | EMC AlphaStore format string vulnerability exploit attempt | off | off | off |
1 | 28396 | SERVER-OTHER | EMC AlphaStore format string vulnerability exploit attempt | off | off | off |
1 | 28397 | SERVER-OTHER | EMC AlphaStore format string vulnerability exploit attempt | off | off | off |
1 | 28398 | SERVER-OTHER | EMC AlphaStore format string vulnerability exploit attempt | off | off | off |
1 | 28407 | SERVER-WEBAPP | HP Intelligent Management Center BIMS UploadServlet arbitrary file upload attempt | drop | drop | drop |
1 | 28426 | FILE-PDF | Adobe Acrobat universal 3D format memory corruption attempt | off | drop | drop |
1 | 28427 | FILE-PDF | Adobe Acrobat universal 3D format memory corruption attempt | off | off | drop |
1 | 28435 | BROWSER-PLUGINS | IBM SPSS SamplePower ActiveX function call access attempt | off | off | drop |
1 | 28436 | BROWSER-PLUGINS | IBM SPSS SamplePower ActiveX function call access attempt | off | off | drop |
1 | 28437 | BROWSER-PLUGINS | IBM SPSS SamplePower ActiveX function call access | off | off | drop |
1 | 28438 | BROWSER-PLUGINS | IBM SPSS SamplePower ActiveX function call access | off | off | drop |
1 | 28451 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 28452 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 28453 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 28454 | FILE-PDF | Adobe Acrobat Reader compressed media.newPlayer memory corruption attempt | off | off | off |
1 | 28461 | FILE-PDF | Adobe Acrobat font parsing integer overflow attempt | off | off | drop |
1 | 28462 | FILE-PDF | Adobe Acrobat font parsing integer overflow attempt | off | off | drop |
1 | 28464 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28465 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28466 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28467 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28468 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28469 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28470 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28471 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28472 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28473 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28474 | EXPLOIT-KIT | Neutrino exploit kit outbound plugin detection response - generic detection | off | drop | drop |
1 | 28489 | BROWSER-IE | Microsoft Internet Explorer CAnchorElement use after free attempt | off | drop | drop |
1 | 28505 | BROWSER-PLUGINS | InformationCardSigninHelper ActiveX clsid access | off | off | drop |
1 | 28506 | BROWSER-PLUGINS | InformationCardSigninHelper ActiveX function call access | off | off | drop |
1 | 28525 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28526 | FILE-OFFICE | Microsoft Office GDI library TIFF handling integer overflow attempt | off | drop | drop |
1 | 28579 | BROWSER-PLUGINS | Microsoft Silverlight ScriptObject untrusted pointer dereference attempt | off | drop | drop |
1 | 28580 | BROWSER-PLUGINS | Microsoft Silverlight ScriptObject untrusted pointer dereference attempt | off | drop | drop |
1 | 28581 | BROWSER-PLUGINS | Microsoft Silverlight ScriptObject untrusted pointer dereference attempt | off | drop | drop |
1 | 28582 | BROWSER-PLUGINS | Microsoft Silverlight ScriptObject untrusted pointer dereference attempt | off | drop | drop |
1 | 28583 | BROWSER-PLUGINS | Microsoft Silverlight ScriptObject untrusted pointer dereference attempt | off | drop | drop |
1 | 28584 | BROWSER-PLUGINS | Microsoft Silverlight ScriptObject untrusted pointer dereference attempt | off | drop | drop |
1 | 28585 | FILE-PDF | Adobe Acrobat Reader OTF font head table size overflow attempt | off | drop | drop |
1 | 28586 | FILE-PDF | Adobe Acrobat Reader OTF font head table size overflow attempt | off | drop | drop |
1 | 28619 | FILE-FLASH | Adobe Flash malformed regular expression exploit attempt | off | drop | drop |
1 | 28620 | FILE-FLASH | Adobe Flash malformed regular expression exploit attempt | off | drop | drop |
1 | 28621 | FILE-PDF | Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt | drop | drop | drop |
1 | 28622 | FILE-PDF | Adobe Acrobat Reader malformed shading modifier heap corruption attempt | off | off | off |
1 | 28625 | FILE-PDF | Adobe Acrobat Reader U3D rgba parsing overflow attempt | off | drop | drop |
1 | 28626 | FILE-PDF | Adobe Acrobat and Adobe Acrobat Reader U3D RHAdobeMeta Buffer Overflow | off | drop | drop |
1 | 28627 | FILE-PDF | Adobe Acrobat universal 3D format memory corruption attempt | off | off | drop |
1 | 28628 | FILE-PDF | Adobe Acrobat universal 3D format memory corruption attempt | off | off | drop |
1 | 28631 | FILE-FLASH | Adobe Flash Player embedded JPG image height overflow attempt | off | off | off |
1 | 28632 | FILE-FLASH | Adobe Flash Player embedded JPG image height overflow attempt | off | off | off |
1 | 28633 | FILE-PDF | Adobe Acrobat Universal 3D stream memory corruption attempt | off | off | drop |
1 | 28634 | FILE-PDF | Adobe Acrobat Reader CoolType.dll composite glyf buffer overflow attempt | off | drop | drop |
1 | 28635 | FILE-PDF | Adobe Acrobat Reader CoolType.dll glyf directory table buffer overflow attempt | off | drop | drop |
1 | 28636 | FILE-FLASH | Adobe Flash Player multimedia file DefineSceneAndFrameLabelData code execution attempt | off | off | drop |
1 | 28637 | FILE-FLASH | Adobe Flash Player multimedia file DefineSceneAndFrameLabelData code execution attempt | off | off | drop |
1 | 28638 | FILE-PDF | Adobe Acrobat Reader CoolType.dll glyf directory table buffer overflow attempt | off | drop | drop |
1 | 28639 | FILE-PDF | Adobe Acrobat Reader CoolType.dll glyf directory table buffer overflow attempt | off | drop | drop |
1 | 28640 | FILE-FLASH | RealNetworks RealPlayer SWF frame handling buffer overflow attempt | off | off | off |
1 | 28641 | FILE-FLASH | RealNetworks RealPlayer SWF frame handling buffer overflow attempt | off | off | off |
1 | 28642 | FILE-PDF | Adobe Acrobat TrueType font handling remote code execution attempt | off | off | drop |
1 | 28643 | FILE-PDF | Adobe Acrobat TrueType font handling remote code execution attempt | off | off | drop |
1 | 28644 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28645 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28646 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28647 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28648 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28649 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28650 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28651 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28652 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28653 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28654 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28655 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28656 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28657 | FILE-PDF | Adobe Acrobat Reader TTF SING table parsing remote code execution attempt | off | off | drop |
1 | 28658 | FILE-PDF | Adobe Acrobat Reader XML Java used in app.setTimeOut | off | drop | drop |
1 | 28659 | FILE-PDF | Adobe Acrobat Reader known malicious variable exploit attempt | off | drop | drop |
1 | 28660 | FILE-FLASH | Adobe Flash Player remote code execution attempt | off | off | off |
1 | 28661 | FILE-FLASH | Adobe Flash Player remote code execution attempt | off | off | off |
1 | 28662 | BROWSER-IE | Microsoft Internet Explorer address bar spoofing attempt | off | off | off |
1 | 28663 | BROWSER-IE | Microsoft Internet Explorer address bar spoofing attempt | off | off | off |
1 | 28664 | FILE-FLASH | RealNetworks RealPlayer SWF flash file buffer overflow attempt | off | off | off |
1 | 28665 | FILE-FLASH | RealNetworks RealPlayer SWF flash file buffer overflow attempt | off | off | off |
1 | 28666 | FILE-FLASH | RealNetworks RealPlayer SWF flash file buffer overflow attempt | off | off | off |
1 | 28667 | FILE-FLASH | Adobe Flash ActionDefineFunction memory access exploit attempt | off | off | off |
1 | 28668 | FILE-FLASH | Adobe Flash ActionDefineFunction memory access exploit attempt | off | off | off |
1 | 28669 | FILE-FLASH | Adobe Flash ActionDefineFunction memory access exploit attempt | off | off | off |
1 | 28670 | FILE-FLASH | Adobe Flash frame type identifier memory corruption attempt | off | off | off |
1 | 28671 | FILE-FLASH | Adobe Flash frame type identifier memory corruption attempt | off | off | off |
1 | 28672 | FILE-FLASH | Adobe Flash frame type identifier memory corruption attempt | off | off | off |
1 | 28673 | FILE-FLASH | Adobe Flash Player newfunction memory corruption attempt | off | off | off |
1 | 28674 | FILE-FLASH | Adobe Flash Player newfunction memory corruption attempt | off | off | off |
1 | 28675 | FILE-FLASH | Adobe Flash Player newfunction memory corruption attempt | off | off | off |
1 | 28676 | FILE-FLASH | Adobe Flash Player newfunction memory corruption attempt | off | off | off |
1 | 28679 | FILE-FLASH | Adobe Flash Player ASnative command execution attempt | off | off | off |
1 | 28680 | FILE-FLASH | Adobe Flash Player ASnative command execution attempt | off | off | off |
1 | 28681 | FILE-FLASH | Adobe Flash Player ASnative command execution attempt | off | off | off |
1 | 28682 | FILE-FLASH | Adobe Flash Player ASnative command execution attempt | off | off | off |
1 | 28683 | FILE-FLASH | Adobe Flash Player ASnative command execution attempt | off | off | off |
1 | 28684 | FILE-FLASH | Adobe Flash Player ASnative command execution attempt | off | off | off |
1 | 28685 | FILE-FLASH | Adobe Flash Player ASnative command execution attempt | off | off | off |
1 | 28687 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | drop | drop | drop |
1 | 28688 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | drop | drop | drop |
1 | 28689 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | off | drop | drop |
1 | 28690 | FILE-FLASH | Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt | off | drop | drop |
1 | 28691 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 28692 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 28693 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 28694 | FILE-FLASH | Adobe Flash Player memory corruption attempt | off | drop | drop |
1 | 28695 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt | off | drop | drop |
1 | 28696 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt | off | drop | drop |
1 | 28697 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt | off | drop | drop |
1 | 28698 | FILE-FLASH | Adobe Flash Player ActionScript callMethod type confusion attempt | off | drop | drop |
1 | 28699 | FILE-FLASH | Adobe Flash malformed regular expression exploit attempt | off | drop | drop |
1 | 28700 | FILE-FLASH | Adobe Flash malformed regular expression exploit attempt | off | drop | drop |
1 | 28701 | FILE-FLASH | Adobe Flash malformed regular expression exploit attempt | off | drop | drop |
1 | 28702 | FILE-FLASH | Adobe Flash malformed regular expression exploit attempt | off | drop | drop |
1 | 28703 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption attempt | off | drop | drop |
1 | 28704 | FILE-FLASH | Adobe Flash ActionScript float index array memory corruption attempt | off | drop | drop |
1 | 28705 | FILE-FLASH | Adobe Flash OpenType font memory corruption attempt | off | drop | drop |
1 | 28706 | FILE-FLASH | Adobe Flash OpenType font memory corruption attempt | off | drop | drop |
1 | 28707 | FILE-FLASH | Adobe Flash OpenType font memory corruption attempt | off | drop | drop |
1 | 28708 | FILE-FLASH | Adobe Flash OpenType font memory corruption attempt | off | drop | drop |
1 | 28709 | FILE-PDF | Adobe Acrobat Universal 3D stream memory corruption attempt | off | off | drop |
1 | 28710 | FILE-PDF | Adobe Acrobat Reader embedded TTF integer overflow attempt | drop | drop | drop |
1 | 28711 | FILE-PDF | Adobe Acrobat Reader embedded TTF integer overflow attempt | drop | drop | drop |
1 | 28712 | FILE-PDF | Adobe Acrobat Reader embedded TTF integer overflow attempt | off | drop | drop |
1 | 28713 | FILE-PDF | Adobe Acrobat Reader embedded TTF integer overflow attempt | off | drop | drop |
1 | 28714 | FILE-PDF | Adobe Acrobat Reader embedded TTF integer overflow attempt | off | drop | drop |
1 | 28715 | FILE-PDF | Adobe Acrobat Reader embedded TTF integer overflow attempt | off | drop | drop |
1 | 28716 | FILE-PDF | Adobe Acrobat Reader compact font format memory corruption attempt | off | off | drop |
1 | 28717 | FILE-PDF | Adobe Acrobat Reader compact font format memory corruption attempt | off | off | drop |
1 | 28718 | FILE-PDF | Adobe Acrobat Reader memory corruption attempt | off | off | drop |
1 | 28719 | FILE-PDF | Adobe Acrobat Reader memory corruption attempt | off | off | drop |
1 | 28720 | FILE-PDF | Adobe Acrobat Reader memory corruption attempt | off | off | drop |
1 | 28721 | FILE-PDF | Adobe Acrobat Reader memory corruption attempt | off | off | drop |
1 | 28722 | FILE-PDF | Adobe Acrobat Reader invalid PDF JavaScript printSeps extension call attempt | off | off | drop |
1 | 28723 | FILE-PDF | Adobe Acrobat Reader invalid PDF JavaScript printSeps extension call attempt | off | off | drop |
1 | 28725 | FILE-PDF | Adobe Acrobat Reader ICC mluc integer overflow attempt | off | off | drop |
1 | 28726 | FILE-PDF | Adobe Acrobat Reader ICC mluc integer overflow attempt | off | off | off |
1 | 28727 | FILE-PDF | Adobe Acrobat Reader ICC mluc integer overflow attempt | off | off | off |
1 | 28728 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28729 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28730 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28731 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28732 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28733 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28734 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28735 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28736 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28737 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28738 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28739 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28740 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28741 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28742 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28743 | FILE-PDF | Adobe Acrobat Reader media.newPlayer memory corruption attempt | off | off | off |
1 | 28744 | FILE-FLASH | Adobe Flash Player Matrix3D copyRawDataTo integer overflow attempt | off | drop | drop |
1 | 28745 | FILE-FLASH | Adobe Flash Player Matrix3D copyRawDataTo integer overflow attempt | off | drop | drop |
1 | 28746 | SERVER-WEBAPP | SAP NetWeaver SXPG_CALL_SYSTEM remote code execution attempt | off | off | off |
1 | 28747 | FILE-PDF | Adobe Acrobat Reader universal 3D format memory corruption attempt | off | off | drop |
1 | 28748 | FILE-PDF | Adobe Acrobat Reader universal 3D format memory corruption attempt | off | off | drop |
1 | 28749 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28750 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28751 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28752 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28753 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28754 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28755 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28756 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28757 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28758 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28759 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28760 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28761 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28762 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28763 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28764 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28765 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28766 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28767 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28768 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28769 | BROWSER-PLUGINS | Novell GroupWise ActiveX clsid access attempt | off | off | off |
1 | 28770 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28771 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28772 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28773 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28774 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28775 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28776 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28777 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28778 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28779 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28780 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28781 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28782 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28783 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28784 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28785 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28786 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28787 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28788 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28789 | BROWSER-PLUGINS | Novell GroupWise ActiveX function call access attempt | off | off | off |
1 | 28790 | FILE-PDF | Adobe Acrobat Reader universal 3D stream memory corruption attempt | off | off | drop |
1 | 28843 | FILE-PDF | Adobe Acrobat Reader javascript toolbar button use after free attempt | drop | drop | drop |
1 | 28844 | FILE-PDF | Adobe Acrobat Reader javascript toolbar button use after free attempt | off | drop | drop |
1 | 28845 | FILE-PDF | Adobe Acrobat Reader javascript toolbar button use after free attempt | drop | drop | drop |
1 | 28846 | FILE-PDF | Adobe Acrobat Reader javascript toolbar button use after free attempt | off | drop | drop |
1 | 28875 | BROWSER-IE | Microsoft Internet Explorer GetClassObject use after free attempt | off | drop | drop |
1 | 28876 | BROWSER-IE | Microsoft Internet Explorer GetClassObject use after free attempt | off | drop | drop |
1 | 28877 | BROWSER-IE | Microsoft Internet Explorer GetClassObject use after free attempt | off | drop | drop |
1 | 28878 | BROWSER-IE | Microsoft Internet Explorer GetClassObject use after free attempt | off | drop | drop |
1 | 28915 | FILE-JAVA | Oracle Java IntegerInterleavedRaster.verify method integer overflow attempt | off | drop | drop |
1 | 28916 | FILE-JAVA | Oracle Java IntegerInterleavedRaster.verify method integer overflow attempt | off | drop | drop |
1 | 28937 | SERVER-WEBAPP | HP SiteScope issuesiebelcmd soap request code execution attempt | off | off | off |
1 | 28961 | FILE-MULTIMEDIA | RealNetworks RealPlayer RealMedia URL length buffer overflow attempt | drop | drop | drop |
1 | 28962 | FILE-MULTIMEDIA | RealNetworks RealPlayer RealMedia URL length buffer overflow attempt | off | drop | drop |
1 | 29017 | SERVER-WEBAPP | HP LoadRunner Virtual User Generator EmulationAdmin directory traversal attempt | drop | drop | drop |
1 | 29018 | SERVER-WEBAPP | HP LoadRunner Virtual User Generator EmulationAdmin getReport SQL injection attempt | off | off | drop |
1 | 29019 | SERVER-WEBAPP | HP LoadRunner Virtual User Generator EmulationAdmin directory traversal attempt | drop | drop | drop |
1 | 29027 | SERVER-WEBAPP | Zimbra remote code execution attempt | off | drop | drop |
1 | 29034 | BROWSER-IE | Microsoft Internet Explorer CDisplayPointer use after free attempt | off | drop | drop |
1 | 29035 | BROWSER-IE | Microsoft Internet Explorer CDisplayPointer use after free attempt | off | drop | drop |
1 | 29040 | SERVER-WEBAPP | Zimbra remote code execution attempt | off | drop | drop |
1 | 29041 | SERVER-WEBAPP | Cisco Prime Data Center Network Manager processImageSave.jsp directory traversal attempt | drop | drop | drop |
1 | 29042 | SERVER-WEBAPP | Cisco Prime Data Center Network Manager processImageSave.jsp directory traversal attempt | drop | drop | drop |
1 | 29059 | BROWSER-PLUGINS | CYME Power Engineering ChartFX.ClientServer ActiveX clsid access | off | off | drop |
1 | 29060 | BROWSER-PLUGINS | CYME Power Engineering ChartFX.ClientServer ActiveX function call access | off | off | drop |
1 | 29105 | SERVER-WEBAPP | ManageEngine DesktopCentral agentLogUploader servlet directory traversal attempt | off | off | drop |
1 | 29141 | SERVER-WEBAPP | Cisco Prime Data Center Network Manager FileUploadServlet arbitrary file upload attempt | drop | drop | drop |
1 | 29142 | SERVER-WEBAPP | Cisco Prime Data Center Network Manager FileUploadServlet arbitrary file upload attempt | drop | drop | drop |
1 | 29192 | SERVER-WEBAPP | Zimbra remote code execution attempt | off | drop | drop |
1 | 29193 | SERVER-WEBAPP | Zimbra remote code execution attempt | off | drop | drop |
1 | 29270 | FILE-JAVA | Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt | drop | drop | drop |
1 | 29271 | FILE-JAVA | Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt | drop | drop | drop |
1 | 29272 | FILE-JAVA | Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt | off | drop | drop |
1 | 29273 | FILE-JAVA | Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt | off | drop | drop |
1 | 29277 | FILE-OTHER | IBM Forms Viewer XFDL form processing stack buffer overflow attempt | off | off | off |
1 | 29278 | FILE-OTHER | IBM Forms Viewer XFDL form processing stack buffer overflow attempt | off | off | off |
1 | 29279 | FILE-OTHER | IBM Forms Viewer XFDL form processing stack buffer overflow attempt | off | off | off |
1 | 29280 | FILE-OTHER | IBM Forms Viewer XFDL form processing stack buffer overflow attempt | off | off | off |
1 | 29390 | SERVER-WEBAPP | EMC Connectrix Manager FileUploadController directory traversal attempt | drop | drop | drop |
1 | 29391 | SERVER-WEBAPP | EMC Connectrix Manager FileUploadController directory traversal attempt | drop | drop | drop |
1 | 29392 | SERVER-WEBAPP | EMC Connectrix Manager FileUploadController directory traversal attempt | drop | drop | drop |
1 | 29394 | BROWSER-WEBKIT | Apple WebKit QuickTime plugin content-type http header buffer overflow attempt | off | off | off |
1 | 29443 | EXPLOIT-KIT | Fiesta exploit kit outbound connection attempt | off | off | off |
1 | 29465 | FILE-OTHER | Corel PDF fusion XPS stack buffer overflow attempt | off | off | drop |
1 | 29466 | FILE-OTHER | Corel PDF fusion XPS stack buffer overflow attempt | off | off | drop |
1 | 29467 | FILE-OTHER | Corel PDF fusion XPS stack buffer overflow attempt | off | off | drop |
1 | 29468 | FILE-OTHER | Corel PDF fusion XPS stack buffer overflow attempt | off | off | drop |
1 | 29485 | SERVER-WEBAPP | EMC Connectrix Manager ManualBootImageUpload directory traversal attempt | drop | drop | drop |
1 | 29486 | SERVER-WEBAPP | EMC Connectrix Manager ManualBootImageUpload directory traversal attempt | drop | drop | drop |
1 | 29487 | SERVER-WEBAPP | EMC Connectrix Manager ManualBootImageUpload directory traversal attempt | drop | drop | drop |
1 | 29488 | SERVER-WEBAPP | EMC Connectrix Manager ManualBootImageUpload directory traversal attempt | drop | drop | drop |
1 | 29509 | INDICATOR-OBFUSCATION | Multiple character encodings detected | off | off | off |
1 | 29519 | INDICATOR-OBFUSCATION | Javascript obfuscation using split reverse join | off | off | off |
1 | 29549 | SERVER-WEBAPP | PineApp Mail-SeCure test_li_connection.php command injection | off | off | off |
1 | 29570 | FILE-OTHER | Oracle Outside In OS2 metafile parser stack buffer overflow attempt | drop | drop | drop |
1 | 29571 | FILE-OTHER | Oracle Outside In OS2 metafile parser stack buffer overflow attempt | drop | drop | drop |
1 | 29572 | FILE-OTHER | Oracle Outside In OS2 metafile parser stack buffer overflow attempt | drop | drop | drop |
1 | 29573 | FILE-OTHER | Oracle Outside In OS2 metafile parser stack buffer overflow attempt | drop | drop | drop |
1 | 29574 | FILE-OTHER | Oracle Outside In OS2 metafile parser stack buffer overflow attempt | off | drop | drop |
1 | 29575 | FILE-OTHER | Oracle Outside In OS2 metafile parser stack buffer overflow attempt | off | drop | drop |
1 | 29576 | FILE-OTHER | Oracle Outside In OS2 metafile parser stack buffer overflow attempt | off | drop | drop |
1 | 29577 | FILE-OTHER | Oracle Outside In OS2 metafile parser stack buffer overflow attempt | off | drop | drop |
1 | 29596 | SERVER-WEBAPP | HP SiteScope soap request code execution attempt | off | off | off |
1 | 29597 | SERVER-WEBAPP | HP SiteScope soap request code execution attempt | off | off | off |
1 | 29615 | MALWARE-CNC | Win.Trojan.Keylogger outbound communication | off | drop | drop |
1 | 29616 | MALWARE-CNC | Win.Trojan.Keylogger inbound communication | off | drop | drop |
1 | 29631 | FILE-FLASH | Adobe Flash Player integer underflow attempt | off | drop | drop |
1 | 29632 | FILE-FLASH | Adobe Flash Player integer underflow attempt | off | drop | drop |
1 | 29633 | FILE-FLASH | Adobe Flash Player integer underflow attempt | off | drop | drop |
1 | 29634 | FILE-FLASH | Adobe Flash Player integer underflow attempt | off | drop | drop |
1 | 29647 | SERVER-APACHE | Apache Roller OGNL injection remote code execution attempt | off | off | drop |
1 | 29648 | SERVER-APACHE | Apache Roller OGNL injection remote code execution attempt | off | off | drop |
1 | 29649 | SERVER-APACHE | Apache Roller allowStaticMethodAccess invocation attempt | off | off | drop |
1 | 29650 | BROWSER-IE | Microsoft Internet Explorer MoveToMarkupPointer call with CControlTracker OnExitTree use-after-free attempt | off | drop | drop |
1 | 29651 | BROWSER-IE | Microsoft Internet Explorer MoveToMarkupPointer call with CControlTracker OnExitTree use-after-free attempt | off | drop | drop |
1 | 29656 | BLACKLIST | DNS request for known malware domain javaupdate.flashserv.net - Adobe 0day C&C | off | drop | drop |
1 | 29657 | BLACKLIST | DNS request for known malware domain sales.eu5.org - Adobe 0day C&C | off | drop | drop |
1 | 29658 | BLACKLIST | DNS request for known malware domain thirdbase.bugs3.com - Adobe 0day C&C | off | drop | drop |
1 | 29659 | BLACKLIST | DNS request for known malware domain www.mobilitysvc.com - Adobe 0day C&C | off | drop | drop |
1 | 29733 | BROWSER-IE | Microsoft Internet Explorer overlapping object boundaries memory corruption attempt | off | drop | drop |
1 | 29734 | BROWSER-IE | Microsoft Internet Explorer overlapping object boundaries memory corruption attempt | off | drop | drop |
1 | 29735 | BROWSER-IE | Microsoft Internet Explorer selectall use after free | off | drop | drop |
1 | 29736 | BROWSER-IE | Microsoft Internet Explorer selectall use after free | off | drop | drop |
1 | 29743 | BROWSER-IE | Microsoft Internet Explorer CInput element user after free attempt | off | drop | drop |
1 | 29744 | BROWSER-IE | Microsoft Internet Explorer CInput element user after free attempt | off | drop | drop |
1 | 29747 | SERVER-APACHE | Apache Struts2 blacklisted method redirect | drop | drop | drop |
1 | 29748 | SERVER-APACHE | Apache Struts2 blacklisted method redirect | drop | drop | drop |
1 | 29756 | SERVER-WEBAPP | IBM Tivoli Provisioning Manager express user.updateUserValue sql injection attempt | off | drop | drop |
1 | 29819 | BROWSER-IE | Microsoft Internet Explorer 10 use after free attempt | off | drop | drop |
1 | 29820 | BROWSER-IE | Microsoft Internet Explorer 10 use after free attempt | off | drop | drop |
1 | 29859 | SERVER-APACHE | Apache Struts allowStaticMethodAccess invocation attempt | off | drop | drop |
1 | 29891 | MALWARE-CNC | Win.Trojan.Crypi.A outbound keylogger traffic | off | off | drop |
1 | 29928 | FILE-FLASH | Adobe Flash Player worker shared object use-after-free attempt | off | drop | drop |
1 | 29929 | FILE-FLASH | Adobe Flash Player worker shared object use-after-free attempt | off | drop | drop |
1 | 29930 | FILE-FLASH | Adobe Flash Player worker shared object use-after-free attempt | off | drop | drop |
1 | 29931 | FILE-FLASH | Adobe Flash Player worker shared object use-after-free attempt | off | drop | drop |
1 | 29946 | SERVER-OTHER | IBM DB2 Universal Database receiveDASMessage buffer overflow attempt | off | off | off |
1 | 29947 | SERVER-OTHER | IBM DB2 Universal Database receiveDASMessage buffer overflow attempt | off | off | off |
1 | 29948 | SERVER-OTHER | IBM DB2 Universal Database receiveDASMessage buffer overflow attempt | off | off | off |
1 | 29979 | SERVER-WEBAPP | Symantec Endpoint Protection Manager Unauthenticated XML External Entity Injection attempt | off | drop | drop |
1 | 30019 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30020 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30021 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30022 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30023 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30024 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30025 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30026 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30027 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30028 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30029 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30030 | FILE-OTHER | Oracle Outside In OS/2 Metafile parser stack overflow attempt | off | off | off |
1 | 30106 | BROWSER-IE | Microsoft Internet Explorer 10 use after free attempt | off | drop | drop |
1 | 30107 | BROWSER-IE | Microsoft Internet Explorer 10 use after free attempt | off | drop | drop |
1 | 30263 | SERVER-OTHER | HP OpenView Storage Data Protector opcode 42 directory traversal attempt | drop | drop | drop |
1 | 30264 | SERVER-OTHER | HP OpenView Storage Data Protector opcode 42 directory traversal attempt | drop | drop | drop |
1 | 30265 | SERVER-OTHER | HP OpenView Storage Data Protector opcode 42 directory traversal attempt | drop | drop | drop |
1 | 30266 | SERVER-OTHER | HP OpenView Storage Data Protector opcode 42 directory traversal attempt | drop | drop | drop |
1 | 30267 | SERVER-OTHER | HP OpenView Storage Data Protector opcode 42 directory traversal attempt | drop | drop | drop |
1 | 30268 | SERVER-OTHER | HP OpenView Storage Data Protector opcode 42 directory traversal attempt | drop | drop | drop |
1 | 30503 | BROWSER-IE | Microsoft Internet Explorer GetClassObject use after free attempt | off | drop | drop |
1 | 30504 | BROWSER-IE | Microsoft Internet Explorer GetClassObject use after free attempt | off | drop | drop |
1 | 30505 | BROWSER-IE | Microsoft Internet Explorer GetClassObject use after free attempt | off | drop | drop |
1 | 30506 | BROWSER-IE | Microsoft Internet Explorer GetClassObject use after free attempt | off | drop | drop |
1 | 30528 | FILE-PDF | Adobe Acrobat Reader javascript toolbar button use after free attempt | off | drop | drop |
1 | 30529 | FILE-PDF | Adobe Acrobat Reader javascript toolbar button use after free attempt | off | drop | drop |
1 | 30533 | FILE-OTHER | Kingsoft Writer long font name buffer overflow attempt | off | drop | drop |
1 | 30534 | FILE-OTHER | Kingsoft Writer long font name buffer overflow attempt | off | drop | drop |
1 | 30553 | SERVER-OTHER | HP Data Protector Backup Client Service directory traversal attempt | off | off | off |
1 | 30554 | SERVER-OTHER | HP Data Protector Backup Client Service UTF directory traversal attempt | off | off | off |
1 | 30555 | SERVER-OTHER | HP Data Protector Backup Client Service UTF directory traversal attempt | off | off | off |
1 | 30556 | SERVER-OTHER | HP Data Protector Backup Client Service directory traversal attempt | off | off | off |
1 | 31238 | SERVER-OTHER | Symantec pcAnywhere remote code execution attempt | off | off | drop |
1 | 31308 | FILE-MULTIMEDIA | Apple QuickTime pict image poly structure memory corruption attempt | off | off | off |
1 | 31309 | FILE-MULTIMEDIA | Apple QuickTime pict image poly structure memory corruption attempt | off | off | off |
1 | 31310 | FILE-OFFICE | Microsoft Office Word SmartTag record code execution attempt | off | off | off |
1 | 31311 | FILE-OFFICE | Microsoft Office Word SmartTag record code execution attempt | off | off | off |
1 | 31312 | FILE-OFFICE | Microsoft Office Word SmartTag record code execution attempt | off | off | off |
1 | 31320 | BROWSER-PLUGINS | Adobe Multiple Product AcroPDF.PDF ActiveX exploit attempt | off | off | off |
1 | 31321 | BROWSER-PLUGINS | Adobe Multiple Product AcroPDF.PDF ActiveX exploit attempt | off | off | off |
1 | 31322 | BROWSER-PLUGINS | Adobe Multiple Product AcroPDF.PDF ActiveX exploit attempt | off | off | off |
1 | 31323 | FILE-OTHER | Apple OSX Finder DMG volume name memory corruption attempt | off | off | off |
1 | 31324 | FILE-OTHER | Apple OSX Finder DMG volume name memory corruption attempt | off | off | off |
1 | 31325 | FILE-OTHER | Apple OSX Finder DMG volume name memory corruption attempt | off | drop | drop |
1 | 31366 | FILE-JAVA | Oracle Java sun.tracing.ProviderSkeleton sandbox bypass attempt | off | drop | drop |
1 | 31367 | FILE-JAVA | Oracle Java sun.tracing.ProviderSkeleton sandbox bypass attempt | off | drop | drop |
1 | 31540 | FILE-JAVA | Oracle Java IntegerInterleavedRaster integer overflow attempt | drop | drop | drop |
1 | 31541 | FILE-JAVA | Oracle Java IntegerInterleavedRaster integer overflow attempt | off | drop | drop |
1 | 31694 | EXPLOIT-KIT | Angler exploit kit encrypted binary download | off | drop | drop |
1 | 31877 | SERVER-OTHER | HP Application Life Cycle Management ActiveX arbitrary code execution attempt | off | off | drop |
1 | 31878 | SERVER-OTHER | HP Application Life Cycle Management ActiveX arbitrary code execution attempt | off | off | drop |
1 | 31879 | SERVER-OTHER | HP Application Life Cycle Management ActiveX arbitrary code execution attempt | off | off | drop |
1 | 31880 | SERVER-OTHER | HP Application Life Cycle Management ActiveX arbitrary code execution attempt | off | off | drop |
1 | 31881 | SERVER-OTHER | HP Application Life Cycle Management ActiveX arbitrary code execution attempt | off | off | drop |
1 | 31882 | SERVER-OTHER | HP Application Life Cycle Management ActiveX arbitrary code execution attempt | off | off | drop |
1 | 31889 | SERVER-MAIL | Exim Dovecot LDA sender_address command injection attempt | off | off | off |
1 | 31890 | SERVER-MAIL | Exim Dovecot LDA sender_address command injection attempt | off | off | off |
1 | 31901 | EXPLOIT-KIT | Angler exploit kit Oracle Java encoded shellcode detected | drop | drop | drop |
1 | 32102 | BROWSER-PLUGINS | Oracle WebCenter Content CheckOutAndOpen.dll ActiveX control code execution ActiveX clsid access | off | off | drop |
1 | 32103 | BROWSER-PLUGINS | Oracle WebCenter Content CheckOutAndOpen.dll ActiveX control code execution ActiveX clsid access | off | off | drop |
1 | 32104 | BROWSER-PLUGINS | Oracle WebCenter Content CheckOutAndOpen.dll ActiveX control code execution ActiveX function call access | off | off | drop |
1 | 32105 | BROWSER-PLUGINS | Oracle WebCenter Content CheckOutAndOpen.dll ActiveX control code execution ActiveX function call access | off | off | drop |
1 | 32128 | SERVER-WEBAPP | PineApp Mail-SeCure confpremenu.php command injection attempt | off | off | off |
1 | 32203 | SERVER-WEBAPP | PineApp Mail-SeCure ldapsyncnow.php command injection attempt | off | off | off |
1 | 32232 | FILE-JAVA | Oracle Java ServiceLoader exception handling exploit attempt | off | drop | drop |
1 | 32233 | FILE-JAVA | Oracle Java ServiceLoader exception handling exploit attempt | off | drop | drop |
1 | 32234 | FILE-JAVA | Oracle Java ServiceLoader exception handling exploit attempt | off | drop | drop |
1 | 32235 | FILE-JAVA | Oracle Java ServiceLoader exception handling exploit attempt | off | drop | drop |
1 | 32359 | FILE-FLASH | Adobe Flash Player worker shared object use-after-free attempt | off | drop | drop |
1 | 32364 | BROWSER-IE | Microsoft Internet Explorer overlapping object boundaries memory corruption attempt | off | drop | drop |
1 | 32762 | BROWSER-IE | Microsoft Internet Explorer TextRange after free attempt | off | off | off |
1 | 32763 | BROWSER-IE | Microsoft Internet Explorer TextRange after free attempt | off | off | off |
1 | 32971 | SERVER-WEBAPP | HP System Management iprange parameter buffer overflow attempt | off | off | off |
1 | 32991 | SERVER-OTHER | SAP NetWeaver SXPG_COMMAND_EXECUTE remote command execution attempt | off | off | off |
1 | 32992 | SERVER-OTHER | SAP NetWeaver SXPG_COMMAND_EXECUTE remote command execution attempt | off | off | off |
1 | 32993 | BROWSER-FIREFOX | Mozilla Firefox XMLSerializer serializeToStream use-after-free attempt | off | off | off |
1 | 32994 | BROWSER-FIREFOX | Mozilla Firefox XMLSerializer serializeToStream use-after-free attempt | off | off | off |
1 | 32996 | DELETED | SERVER-OTHER HP LoadRunner stack buffer overflow attempt | |||
1 | 32997 | SERVER-OTHER | Sophos Web Appliance arbitrary command execution attempt | off | off | drop |
1 | 32998 | SERVER-OTHER | Sophos Web Appliance arbitrary command execution attempt | off | off | drop |
1 | 32999 | PROTOCOL-SCADA | Advantech WebAccess SCADA command execution attempt | off | off | off |
1 | 33000 | PROTOCOL-SCADA | Advantech WebAccess SCADA command execution attempt | off | off | off |
1 | 33001 | PROTOCOL-SCADA | Advantech WebAccess SCADA command execution attempt | off | off | off |
1 | 33002 | PROTOCOL-SCADA | Advantech WebAccess SCADA command execution attempt | off | off | off |
1 | 33003 | BROWSER-PLUGINS | SolarWinds Orion Pepco32c ActiveX clsid access attempt | off | off | alert |
1 | 33004 | BROWSER-PLUGINS | SolarWinds Orion Pepco32c ActiveX clsid access attempt | off | off | alert |
1 | 33005 | SERVER-WEBAPP | Advantec WebAccess SCADA webvact.ocx NodeName buffer overflow attempt | off | off | drop |
1 | 33006 | SERVER-WEBAPP | Advantec WebAccess SCADA webvact.ocx NodeName buffer overflow attempt | off | off | drop |
1 | 33007 | SERVER-WEBAPP | Advantec WebAccess SCADA webvact.ocx NodeName buffer overflow attempt | off | off | drop |
1 | 33008 | SERVER-WEBAPP | Advantec WebAccess SCADA webvact.ocx NodeName buffer overflow attempt | off | off | drop |
1 | 33009 | SERVER-WEBAPP | Advantec WebAccess SCADA webvact.ocx UserName buffer overflow attempt | off | off | drop |
1 | 33010 | SERVER-WEBAPP | Advantec WebAccess SCADA webvact.ocx UserName buffer overflow attempt | off | off | off |
1 | 33011 | SERVER-WEBAPP | Advantec WebAccess SCADA webvact.ocx UserName buffer overflow attempt | off | off | drop |
1 | 33012 | SERVER-WEBAPP | Advantec WebAccess SCADA webvact.ocx UserName buffer overflow attempt | off | off | drop |
1 | 33013 | BROWSER-PLUGINS | HP LoadRunner ActiveX clsid access attempt | off | off | off |
1 | 33014 | BROWSER-PLUGINS | HP LoadRunner ActiveX clsid access attempt | off | off | off |
1 | 33015 | PROTOCOL-SCADA | ABB MicroSCADA wserver.exe EXECUTE remote code execution attempt | off | off | off |
1 | 33018 | BROWSER-IE | Oracle WebCenter BlackIceDevMode ActiveX buffer overflow attempt | off | off | off |
1 | 33019 | BROWSER-IE | Oracle WebCenter BlackIceDevMode ActiveX buffer overflow attempt | off | off | off |
1 | 33020 | BROWSER-IE | Oracle WebCenter BlackIceDevMode ActiveX buffer overflow attempt | off | off | off |
1 | 33021 | BROWSER-IE | Oracle WebCenter BlackIceDevMode ActiveX buffer overflow attempt | off | off | off |
1 | 33022 | FILE-OTHER | Apple Quicktime invalid atom length buffer overflow attempt | off | off | off |
1 | 33023 | FILE-OTHER | Apple Quicktime invalid atom length buffer overflow attempt | off | off | off |
1 | 33024 | SERVER-WEBAPP | Cisco Security Agent Management Center code execution attempt | off | off | off |
1 | 33025 | SERVER-WEBAPP | Cisco Security Agent Management Center code execution attempt | off | off | off |
1 | 33029 | FILE-OTHER | Poster Software Publish-It buffer overflow attempt | off | off | off |
1 | 33030 | FILE-OTHER | Poster Software Publish-It buffer overflow attempt | off | off | off |
1 | 33031 | FILE-OTHER | Poster Software Publish-It buffer overflow attempt | off | off | off |
1 | 33032 | FILE-OTHER | Poster Software Publish-It buffer overflow attempt | off | off | off |
1 | 33033 | FILE-OTHER | Poster Software Publish-It buffer overflow attempt | off | off | off |
1 | 33034 | FILE-OTHER | Poster Software Publish-It buffer overflow attempt | off | off | off |
1 | 33035 | FILE-OTHER | Poster Software Publish-It buffer overflow attempt | off | off | off |
1 | 33036 | FILE-OTHER | Poster Software Publish-It buffer overflow attempt | off | off | off |
1 | 33037 | FILE-OTHER | Poster Software Publish-It buffer overflow attempt | off | off | off |
1 | 33040 | FILE-OTHER | Poster Software Publish-It buffer overflow attempt | off | off | off |
1 | 33085 | BROWSER-IE | Microsoft Internet Explorer 10 use after free attempt | off | drop | drop |
1 | 33086 | BROWSER-IE | Microsoft Internet Explorer 10 use after free attempt | off | drop | drop |
1 | 33087 | FILE-PDF | Foxit Reader remote query string buffer overflow attempt | off | off | off |
1 | 33088 | BROWSER-FIREFOX | Mozilla Firefox 17 onreadystatechange memory corruption attempt | off | drop | drop |
1 | 33089 | BROWSER-FIREFOX | Mozilla Firefox 17 onreadystatechange memory corruption attempt | off | drop | drop |
1 | 33090 | BROWSER-FIREFOX | Mozilla Firefox 17 onreadystatechange memory corruption attempt | off | drop | drop |
1 | 33093 | BROWSER-IE | Microsoft Internet Explorer CInput element user after free attempt | off | drop | drop |
1 | 33094 | BROWSER-IE | Microsoft Internet Explorer CInput element user after free attempt | off | drop | drop |
1 | 33095 | BROWSER-IE | Microsoft Internet Explorer CTreePos Use After Free attempt | off | off | drop |
1 | 33096 | BROWSER-IE | Microsoft Internet Explorer CTreePos Use After Free attempt | off | off | drop |
1 | 33097 | BROWSER-IE | Microsoft Internet Explorer CTreePos Use After Free attempt | off | off | drop |
1 | 33098 | BROWSER-IE | Microsoft Internet Explorer CTreePos Use After Free attempt | off | off | drop |
1 | 33099 | BROWSER-IE | Microsoft Internet Explorer CAnchorElement use after free attempt | off | off | off |
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 335 | PROTOCOL-FTP | .rhosts | off | off | off |
1 | 591 | PROTOCOL-RPC | portmap ypupdated request TCP | off | off | off |
1 | 593 | PROTOCOL-RPC | portmap snmpXdmi request TCP | off | off | off |
1 | 598 | PROTOCOL-RPC | portmap listing TCP 111 | off | off | off |
1 | 835 | SERVER-WEBAPP | test-cgi access | off | off | off |
1 | 857 | SERVER-WEBAPP | faxsurvey access | off | off | off |
1 | 886 | SERVER-WEBAPP | phf access | off | off | off |
1 | 971 | SERVER-IIS | ISAPI .printer access | off | off | off |
1 | 1028 | SERVER-IIS | query.asp access | off | off | off |
1 | 1042 | SERVER-IIS | view source via translate header | off | off | off |
1 | 1147 | SERVER-WEBAPP | cat_ access | off | off | off |
1 | 1277 | PROTOCOL-RPC | portmap ypupdated request UDP | off | off | off |
1 | 1279 | PROTOCOL-RPC | portmap snmpXdmi request UDP | off | off | off |
1 | 1384 | OS-WINDOWS | Microsoft Windows UPnP malformed advertisement | off | off | off |
1 | 1500 | SERVER-WEBAPP | ExAir access | off | off | off |
1 | 1672 | PROTOCOL-FTP | CWD ~ attempt | off | off | off |
1 | 1882 | INDICATOR-COMPROMISE | id check returned userid | off | off | off |
1 | 1952 | PROTOCOL-RPC | mountd UDP mount request | off | off | off |
1 | 1993 | PROTOCOL-IMAP | login literal buffer overflow attempt | off | off | off |
1 | 2088 | PROTOCOL-RPC | ypupdated arbitrary command attempt UDP | off | off | off |
1 | 2089 | PROTOCOL-RPC | ypupdated arbitrary command attempt TCP | off | off | off |
1 | 2118 | PROTOCOL-IMAP | list overflow attempt | off | off | off |
1 | 2185 | PROTOCOL-RPC | mountd UDP mount path overflow attempt | off | off | off |
1 | 2278 | SERVER-WEBAPP | client negative Content-Length attempt | off | off | off |
1 | 2338 | PROTOCOL-FTP | LIST buffer overflow attempt | off | off | off |
1 | 2570 | SERVER-WEBAPP | Invalid HTTP Version String | off | off | off |
1 | 3007 | PROTOCOL-IMAP | command overflow attempt | off | off | off |
1 | 3072 | PROTOCOL-IMAP | status overflow attempt | off | off | off |
1 | 3441 | PROTOCOL-FTP | PORT bounce attempt | off | off | off |
1 | 3694 | SERVER-WEBAPP | Squid content length cache poisoning attempt | off | off | off |
1 | 3696 | SERVER-OTHER | Veritas Backup Agent DoS attempt | off | off | off |
1 | 4126 | SERVER-OTHER | Veritas Backup Exec root connection attempt using default password hash | off | off | off |
1 | 4130 | SERVER-OTHER | Novell ZenWorks Remote Management Agent buffer overflow Attempt | off | off | off |
1 | 4144 | OS-SOLARIS | Oracle Solaris lpd control file upload attempt | off | off | off |
1 | 5316 | SERVER-OTHER | CA CAM log_security overflow attempt | off | off | off |
1 | 5704 | PROTOCOL-IMAP | SELECT overflow attempt | off | off | off |
1 | 7021 | OS-LINUX | kernel SCTP chunkless packet denial of service attempt | off | off | off |
1 | 7022 | OS-WINDOWS | Microsoft Windows Explorer invalid url file overflow attempt | off | off | off |
1 | 8056 | SERVER-OTHER | ISC DHCP server 2 client_id length denial of service attempt | off | off | off |
1 | 8057 | SERVER-MYSQL | Date_Format denial of service attempt | off | off | off |
1 | 8449 | OS-WINDOWS | SMB Rename invalid buffer type andx attempt | off | off | off |
1 | 8450 | OS-WINDOWS | SMB Rename invalid buffer type attempt | off | off | off |
1 | 8451 | OS-WINDOWS | SMB Rename invalid buffer type unicode andx attempt | off | off | off |
1 | 8452 | OS-WINDOWS | SMB Rename invalid buffer type unicode attempt | off | off | off |
1 | 8453 | OS-WINDOWS | SMB-DS Rename invalid buffer type andx attempt | off | off | off |
1 | 8454 | OS-WINDOWS | SMB-DS Rename invalid buffer type attempt | off | off | off |
1 | 8455 | OS-WINDOWS | SMB-DS Rename invalid buffer type unicode andx attempt | off | off | off |
1 | 8456 | OS-WINDOWS | SMB-DS Rename invalid buffer type unicode attempt | off | off | off |
1 | 8457 | OS-WINDOWS | SMB Rename invalid buffer type andx attempt | off | off | off |
1 | 8458 | OS-WINDOWS | SMB Rename invalid buffer type attempt | off | off | off |
1 | 8459 | OS-WINDOWS | SMB Rename invalid buffer type unicode andx attempt | off | off | off |
1 | 8460 | OS-WINDOWS | SMB Rename invalid buffer type unicode attempt | off | off | off |
1 | 9325 | SERVER-OTHER | Citrix IMA DOS event data length denial of service attempt | off | off | off |
1 | 10011 | SERVER-MAIL | Novell NetMail APPEND command buffer overflow attempt | off | off | off |
1 | 10116 | POLICY-SOCIAL | AIM GoChat URL access attempt | off | off | off |
1 | 10132 | PROTOCOL-RPC | portmap BrightStor ARCserve denial of service attempt | off | off | off |
1 | 10133 | PROTOCOL-RPC | portmap BrightStor ARCserve denial of service attempt | off | off | off |
1 | 10135 | SERVER-OTHER | Squid proxy FTP denial of service attempt | off | off | off |
1 | 10482 | PROTOCOL-RPC | portmap CA BrightStor ARCserve tcp request | off | off | off |
1 | 11185 | SERVER-OTHER | CA eTrust key handling dos via username attempt | off | off | off |
1 | 11288 | PROTOCOL-RPC | portmap mountd tcp request | off | off | off |
1 | 11289 | PROTOCOL-RPC | portmap mountd tcp zero-length payload denial of service attempt | off | off | off |
1 | 11834 | BROWSER-IE | Microsoft Internet Explorer navcancl.htm url spoofing attempt | off | off | off |
1 | 11970 | PROTOCOL-VOIP | Cisco 7940/7960 INVITE Remote-Party-ID header denial of service attempt | off | off | off |
1 | 12076 | SERVER-OTHER | Ipswitch WS_FTP log server long unicode string | off | off | off |
1 | 12187 | PROTOCOL-RPC | portmap 2112 tcp rename_principal attempt | off | off | off |
1 | 12199 | SERVER-OTHER | RIM BlackBerry SRP negative string size | off | off | off |
1 | 12591 | SERVER-APACHE | Apache mod_cache denial of service attempt | off | off | off |
1 | 12635 | OS-WINDOWS | RPC NTLMSSP malformed credentials attempt | off | off | off |
1 | 12807 | FILE-IDENTIFY | Lotus 123 file attachment | off | off | off |
1 | 13252 | PROTOCOL-RPC | portmap 390113 tcp procedure 4 attempt | off | off | off |
1 | 13573 | FILE-OFFICE | Microsoft Office Outlook arbitrary command line attempt | off | off | off |
1 | 13827 | OS-WINDOWS | Microsoft Windows PGM denial of service attempt | off | off | off |
1 | 13839 | SERVER-OTHER | CA ARCServ NetBackup remote file upload attempt | off | off | off |
1 | 13894 | SERVER-MAIL | Microsoft Office Outlook Web Access From field cross-site scripting attempt | off | off | off |
1 | 13895 | SERVER-MAIL | Microsoft Office Outlook Web Access invalid CSS escape sequence script execution attempt | off | off | off |
1 | 13949 | PROTOCOL-DNS | excessive outbound NXDOMAIN replies - possible spoof of domain run by local DNS servers | off | off | off |
1 | 13951 | SERVER-WEBAPP | Oracle Database Server buffer overflow attempt | off | off | off |
1 | 13990 | SQL | union select - possible sql injection attempt - GET parameter | off | off | drop |
1 | 14743 | PROTOCOL-FTP | RNTO directory traversal attempt | off | off | off |
1 | 15106 | FILE-OFFICE | Microsoft Office Word .rtf file integer overflow attempt | off | off | off |
1 | 15302 | SERVER-MAIL | Microsoft Windows Exchange System Attendant denial of service attempt | off | off | off |
1 | 15387 | OS-WINDOWS | udp WINS WPAD registration attempt | off | off | off |
1 | 15443 | SERVER-MYSQL | XML Functions UpdateXML Scalar XPath denial of service attempt | off | off | off |
1 | 15477 | SERVER-WEBAPP | Oracle BEA WebLogic overlong JESSIONID buffer overflow attempt | off | off | off |
1 | 15488 | SERVER-ORACLE | Oracle Database Application Express Component APEX password hash disclosure attempt | off | off | off |
1 | 15509 | SERVER-OTHER | IBM DB2 database server CONNECT denial of service attempt | off | off | off |
1 | 15580 | SERVER-OTHER | Squid oversized reply header handling exploit attempt | off | off | off |
1 | 15702 | NETBIOS | DCERPC NCACN-IP-TCP brightstor opcode 0x13 overflow attempt | off | off | off |
1 | 15710 | NETBIOS | DCERPC NCACN-IP-TCP brightstor opcode 0x3B null strings attempt | off | off | off |
1 | 15896 | SERVER-OTHER | Firebird SQL op_connect_request denial of service attempt | off | off | off |
1 | 15906 | OS-LINUX | Linux Kernel DCCP Protocol Handler dccp_setsockopt_change integer overflow attempt | off | off | off |
1 | 15944 | OS-WINDOWS | Microsoft Windows Active Directory crafted LDAP request denial of service attempt | off | off | off |
1 | 15954 | SERVER-MAIL | SpamAssassin malformed email header DoS attempt | off | off | off |
1 | 15957 | FILE-OTHER | Sophos Anti-Virus zip file handling DoS attempt | off | off | off |
1 | 15960 | SERVER-OTHER | Novell eDirectory MS-DOS device name DoS attempt | off | off | off |
1 | 15961 | SERVER-OTHER | 3Com Network Supervisor directory traversal attempt | off | off | off |
1 | 15994 | SERVER-OTHER | Squid strListGetItem denial of service attempt | off | off | off |
1 | 16014 | SERVER-OTHER | Novell eDirectory HTTP headers denial of service attempt | off | off | off |
1 | 16039 | SERVER-OTHER | EMC Dantz Retrospect Backup Agent denial of service attempt | off | off | off |
1 | 16048 | SERVER-OTHER | Microsoft ASP.NET application folder info disclosure attempt | off | off | off |
1 | 16052 | SERVER-OTHER | Novell iManager Tree parameter denial of service attempt | off | off | off |
1 | 16060 | SERVER-OTHER | IBM Lotus Domino LDAP server memory exception attempt | off | off | off |
1 | 16066 | OS-WINDOWS | Microsoft Windows Server driver crafted SMB data denial of service | off | off | off |
1 | 16071 | SERVER-OTHER | CA ARCServe Backup Discovery Service denial of service attempt | off | off | off |
1 | 16083 | PROTOCOL-RPC | portmap 395650 tcp request | off | off | off |
1 | 16087 | FILE-OTHER | Multiple vendor AV gateway virus detection bypass attempt | off | off | off |
1 | 16091 | SERVER-OTHER | Macromedia Flash Media Server administration service denial of service attempt | off | off | off |
1 | 16147 | SERVER-IIS | Microsoft Windows IIS malformed URL .dll denial of service attempt | off | off | off |
1 | 16197 | SERVER-OTHER | OpenLDAP ber_get_next BER decoding denial of service attempt | off | off | off |
1 | 16199 | SERVER-MAIL | SpamAssassin long message header denial of service attempt | off | off | off |
1 | 16206 | OS-WINDOWS | Microsoft Windows DNS server spoofing attempt | off | off | off |
1 | 16209 | SERVER-OTHER | FreeRADIUS RADIUS server rad_decode remote denial of service attempt | off | off | off |
1 | 16214 | SERVER-OTHER | Squid Proxy invalid HTTP response code denial of service attempt | off | off | off |
1 | 16294 | OS-WINDOWS | Microsoft Windows TCP stack zero window size exploit attempt | off | off | off |
1 | 16341 | SERVER-OTHER | IBM DB2 Database Server invalid data stream denial of service attempt | off | off | off |
1 | 16351 | PROTOCOL-VOIP | CSeq buffer overflow attempt | off | off | off |
1 | 16352 | OS-LINUX | Linux Kernel NFSD Subsystem overflow attempt | off | off | off |
1 | 16384 | SERVER-OTHER | VMware Server ISAPI Extension remote denial of service attempt | off | off | off |
1 | 16445 | PROTOCOL-VOIP | Digium Asterisk IAX2 ack response denial of service attempt | off | off | off |
1 | 16447 | PROTOCOL-RPC | Solaris UDP portmap sadmin request attempt | off | off | off |
1 | 16660 | SERVER-WEBAPP | Microsoft Office SharePoint Server 2007 help.aspx denial of service attempt | off | off | off |
1 | 16684 | SERVER-SAMBA | Samba smbd Session Setup AndX security blob length dos attempt | off | off | off |
1 | 16694 | SERVER-OTHER | RealNetworks Helix Server RTSP SETUP request denial of service attempt | off | off | off |
1 | 16699 | PROTOCOL-RPC | Linux Kernel nfsd v2 udp CAP_MKNOD security bypass attempt | off | off | off |
1 | 16700 | PROTOCOL-RPC | Linux Kernel nfsd v2 tcp CAP_MKNOD security bypass attempt | off | off | off |
1 | 16701 | PROTOCOL-RPC | Linux Kernel nfsd v3 udp CAP_MKNOD security bypass attempt | off | off | off |
1 | 16702 | PROTOCOL-RPC | Linux Kernel nfsd v3 tcp CAP_MKNOD security bypass attempt | off | off | off |
1 | 16709 | SERVER-OTHER | RealNetworks Helix Server RTSP SET_PARAMETERS empty DataConvertBuffer header denial of service attempt | off | off | off |
1 | 17055 | SERVER-ORACLE | Oracle Database DBMS TNS Listener denial of service attempt | off | off | off |
1 | 17129 | BROWSER-IE | Microsoft Internet Explorer use-after-free memory corruption attempt | off | off | off |
1 | 17133 | OS-WINDOWS | Microsoft Windows MSXML2 ActiveX malformed HTTP response | off | off | drop |
1 | 17137 | SERVER-WEBAPP | HP Intelligent Management Center information disclosure attempt | off | off | off |
1 | 17152 | SERVER-SAMBA | Samba smbd flags2 header parsing denial of service attempt | off | off | off |
1 | 17208 | SERVER-OTHER | Squid Proxy HTCP packet processing denial of service attempt | off | off | off |
1 | 17225 | SERVER-OTHER | Alt-N MDaemon WorldClient invalid user | off | off | off |
1 | 17254 | SERVER-IIS | Microsoft Windows IIS stack exhaustion DoS attempt | off | off | off |
1 | 17275 | SERVER-MAIL | Symantec Brightmail AntiSpam nested Zip handling denial of service attempt | off | off | off |
1 | 17287 | SERVER-WEBAPP | Cisco IOS HTTP service HTML injection attempt | off | off | off |
1 | 17294 | OS-WINDOWS | Microsoft Windows NAT Helper DNS query denial of service attempt | off | off | off |
1 | 17297 | SERVER-OTHER | McAfee VirusScan on-access scanner long unicode filename handling buffer overflow attempt | off | off | off |
1 | 17299 | SERVER-OTHER | ISC BIND RRSIG query denial of service attempt | off | off | off |
1 | 17302 | OS-LINUX | Linux kernel SCTP Unknown Chunk Types denial of service attempt | off | off | off |
1 | 17306 | OS-WINDOWS | Microsoft Malware Protection Engine file processing denial of service attempt | off | off | off |
1 | 17353 | OS-SOLARIS | Oracle Solaris printd Daemon Arbitrary File Deletion attempt | off | off | off |
1 | 17354 | SERVER-APACHE | Apache Byte-Range Filter denial of service attempt | off | off | off |
1 | 17371 | SERVER-WEBAPP | Squid authentication headers handling denial of service attempt | off | off | off |
1 | 17387 | SERVER-APACHE | Apache Tomcat allowLinking URIencoding directory traversal attempt | off | off | off |
1 | 17390 | FILE-IMAGE | ClamAV Antivirus Function Denial of Service attempt | off | off | off |
1 | 17416 | SERVER-ORACLE | Database Intermedia Denial of Service Attempt | off | off | off |
1 | 17432 | SERVER-WEBAPP | Squid Gopher protocol handling buffer overflow attempt | off | off | off |
1 | 17439 | OS-WINDOWS | Microsoft Distributed Transaction Controller TIP DoS attempt | off | off | off |
1 | 17448 | BROWSER-IE | Microsoft Internet Explorer HTTPS proxy information disclosure vulnerability | off | off | off |
1 | 17473 | SERVER-ORACLE | DBMS_CDC_SUBSCRIBE.EXTEND_WINDOW arbitrary command execution attempt | off | off | off |
1 | 17483 | PROTOCOL-DNS | squid proxy dns A record response denial of service attempt | off | off | off |
1 | 17484 | PROTOCOL-DNS | squid proxy dns PTR record response denial of service attempt | off | off | off |
1 | 17485 | PROTOCOL-DNS | Symantec Gateway products DNS cache poisoning attempt | off | off | off |
1 | 17487 | BROWSER-IE | Microsoft Internet Explorer Script Engine Stack Exhaustion Denial of Service attempt | off | off | off |
1 | 17533 | SERVER-APACHE | Apache Struts Information Disclosure Attempt | off | off | off |
1 | 17544 | SERVER-OTHER | Wireshark LWRES Dissector getaddrsbyname buffer overflow attempt | off | off | off |
1 | 17556 | SERVER-OTHER | Firebird database invalid state integer overflow attempt | off | off | off |
1 | 17562 | FILE-JAVA | Oracle Java Runtime Environment Pack200 Decompression Integer Overflow attempt | off | off | off |
1 | 17572 | OS-WINDOWS | Microsoft XML Core Services cross-site information disclosure attempt | off | off | off |
1 | 17584 | SERVER-ORACLE | UTL_FILE directory traversal attempt | off | off | off |
1 | 17590 | SERVER-ORACLE | DBMS_ASSERT.simple_sql_name double quote SQL injection attempt | off | off | off |
1 | 17598 | SERVER-OTHER | IBM DB2 Universal Database accsec command without rdbnam | off | off | off |
1 | 17599 | SERVER-OTHER | IBM DB2 Universal Database rdbname denial of service attempt | off | off | off |
1 | 17602 | FILE-OTHER | ClamAV antivirus CHM file handling DOS | off | off | off |
1 | 17625 | SERVER-ORACLE | Database Core RDBMS component denial of service attempt | off | off | off |
1 | 17639 | SERVER-SAMBA | Samba Root File System access bypass attempt | off | off | off |
1 | 17653 | SERVER-IIS | Microsoft Windows IIS source code disclosure attempt | off | off | off |
1 | 17680 | SERVER-OTHER | ISC BIND DNSSEC Validation Multiple RRsets DoS | off | off | off |
1 | 17702 | OS-WINDOWS | DCERPC NCACN-IP-TCP srvsvc NetrDfsCreateExitPoint dos attempt | off | off | off |
1 | 17738 | SERVER-OTHER | Linux Kernel SNMP Netfilter Memory Corruption attempt | off | off | off |
1 | 17749 | PROTOCOL-RPC | Linux Kernel nfsd v4 CAP_MKNOD security bypass attempt | off | off | off |
1 | 17750 | SERVER-IIS | Microsoft IIS 7.5 client verify null pointer attempt | off | off | off |
1 | 18511 | SERVER-OTHER | Sourcefire Snort packet fragmentation reassembly denial of service attempt | off | off | off |
1 | 18524 | SERVER-OTHER | Multiple vendor anti-virus extended ASCII filename scan bypass attempt | off | off | off |
1 | 18528 | SERVER-ORACLE | Oracle TimesTen In-Memory Database HTTP request denial of service attempt | off | off | off |
1 | 18533 | SERVER-OTHER | MIT Kerberos KDC authentication denial of service attempt | off | off | off |
1 | 18534 | SERVER-OTHER | MIT Kerberos KDC authentication denial of service attempt | off | off | off |
1 | 18713 | SERVER-OTHER | OpenSSL TLS connection record handling denial of service attempt | off | off | off |
1 | 18714 | SERVER-OTHER | OpenSSL TLS connection record handling denial of service attempt | off | off | off |
1 | 18754 | SERVER-OTHER | HP Data Protector Backup Client Service code execution attempt | drop | drop | drop |
1 | 18777 | SERVER-OTHER | HP data protector OmniInet service NULL dereference denial of service attempt | off | off | off |
1 | 18798 | SERVER-OTHER | HP Data Protector Media Operations denial of service attempt | off | off | off |
1 | 18799 | SERVER-OTHER | HP Data Protector Media Operations denial of service attempt | off | off | off |
1 | 18807 | SERVER-OTHER | OpenLDAP Modrdn RDN NULL string denial of service attempt | off | off | off |
1 | 18935 | SERVER-OTHER | ISC DHCP server zero length client ID denial of service attempt | off | off | off |
1 | 18961 | OS-WINDOWS | Microsoft Windows MSXML2 ActiveX malformed HTTP response | off | off | drop |
1 | 18985 | POLICY-OTHER | CA ARCserve Axis2 default credential login attempt | off | off | drop |
1 | 18997 | OS-LINUX | Linux kernel sctp_rcv_ootb invalid chunk length DoS attempt | off | off | off |
1 | 19000 | SERVER-MYSQL | Database CASE NULL argument denial of service attempt | off | off | off |
1 | 19001 | SERVER-MYSQL | IN NULL argument denial of service attempt | off | off | off |
1 | 19073 | SERVER-OTHER | Squid Proxy Expect header null pointer denial of service attempt | off | off | off |
1 | 19093 | SERVER-MYSQL | Database unique set column denial of service attempt | off | off | off |
1 | 19094 | SERVER-MYSQL | Database unique set column denial of service attempt | off | off | off |
1 | 19101 | SERVER-ORACLE | Oracle Java Web Server Admin Server denial of service attempt | off | off | off |
1 | 19110 | SERVER-WEBAPP | IBM Rational Quality Manager and Test Lab Manager policy bypass attempt | off | off | off |
1 | 19159 | SERVER-OTHER | HP Data Protector Manager RDS attempt | off | off | off |
1 | 19192 | SERVER-IIS | Microsoft Windows IIS stack exhaustion DoS attempt | off | off | off |
1 | 19205 | SERVER-OTHER | Novell iManager Tree parameter denial of service attempt | off | off | off |
1 | 19313 | SERVER-OTHER | Symantec Antivirus Intel Service DoS Attempt | off | drop | drop |
1 | 19322 | BROWSER-IE | Microsoft Internet Explorer and SharePoint toStaticHTML information disclosure attempt | off | off | off |
1 | 19818 | OS-WINDOWS | Microsoft XML core services cross-domain information disclosure attempt | off | off | off |
1 | 19825 | SERVER-APACHE | Apache Killer denial of service tool exploit attempt | off | off | off |
1 | 20216 | PROTOCOL-SCADA | Beckhoff TwinCAT DoS | off | off | off |
1 | 20391 | PROTOCOL-VOIP | Digium Asterisk Attribute header rtpmap field buffer overflow attempt | off | off | off |
1 | 20392 | PROTOCOL-VOIP | Digium Asterisk Attribute header rtpmap field buffer overflow attempt | off | off | off |
1 | 20425 | PROTOCOL-VOIP | Cisco 7940/7960 INVITE Remote-Party-ID header denial of service attempt | off | off | off |
1 | 20528 | SERVER-APACHE | Apache mod_proxy reverse proxy information disclosure attempt | off | off | off |
1 | 20530 | SERVER-WEBAPP | HP OpenView Storage Data Protector directory traversal attempt | off | off | drop |
1 | 20531 | SERVER-WEBAPP | HP OpenView Storage Data Protector directory traversal attempt | off | off | drop |
1 | 20692 | POLICY-OTHER | Cisco network registrar default credentials authentication attempt | off | off | drop |
1 | 20824 | OS-WINDOWS | generic web server hashing collision attack | off | off | off |
1 | 20829 | SERVER-IIS | Microsoft Windows IIS .NET null character username truncation attempt | off | off | drop |
1 | 20999 | BROWSER-WEBKIT | Microsoft Windows 7 x64 Apple Safari abnormally long iframe exploit attempt | off | drop | drop |
1 | 21101 | PROTOCOL-VOIP | Digium Asterisk channel driver denial of service attempt | off | off | off |
1 | 21214 | SERVER-APACHE | Apache server mod_proxy reverse proxy bypass attempt | off | off | off |
1 | 21260 | SERVER-APACHE | Apache Byte-Range Filter denial of service attempt | off | off | off |
1 | 21292 | BROWSER-IE | Microsoft Internet Explorer style.position use-after-free memory corruption attempt | off | drop | drop |
1 | 21300 | BROWSER-IE | Microsoft Internet Explorer 9 null character in string information disclosure attempt | off | off | off |
1 | 21516 | SERVER-WEBAPP | JBoss JMX console access attempt | off | off | off |
1 | 21568 | OS-WINDOWS | Microsoft Windows RDP RST denial of service attempt | off | off | off |
1 | 21776 | SERVER-MAIL | Microsoft Windows Exchange MODPROPS denial of service attempt | off | off | off |
1 | 21913 | SERVER-OTHER | EMC data protection advisor DOS attempt | off | off | off |
1 | 22952 | SERVER-OTHER | Iron Mountain connected backup opcode 13 processing command injection attempt | drop | drop | drop |
1 | 23060 | BROWSER-IE | Microsoft Internet Explorer style.position use-after-free memory corruption attempt | off | drop | drop |
1 | 23097 | SERVER-OTHER | IBM solidDB SELECT statement denial of service attempt | off | off | off |
1 | 23099 | SERVER-OTHER | SAP NetWeaver Dispatcher DiagTraceHex denial of service attempt | off | drop | drop |
1 | 23112 | SERVER-OTHER | SAP NetWeaver Dispatcher denial of service attempt | off | off | off |
1 | 23368 | PROTOCOL-DNS | Tftpd32 DNS server denial of service attempt | off | off | off |
1 | 23392 | SERVER-OTHER | IBM SolidDB redundant where clause DoS attempt | off | off | off |
1 | 23839 | OS-WINDOWS | SMB Microsoft Windows RAP API NetServerEnum2 long server name buffer overflow attempt | off | off | off |
1 | 23889 | FILE-PDF | Adobe Acrobat Reader getAnnotsRichMedia return type confusion attempt | drop | drop | drop |
1 | 23890 | FILE-PDF | Adobe Acrobat Reader getAnnotsRichMedia return type confusion attempt | drop | drop | drop |
1 | 24007 | OS-WINDOWS | SMB Microsoft Windows RAP API NetServerEnum2 long server name buffer overflow attempt | alert | alert | drop |
1 | 24291 | SERVER-WEBAPP | HP SiteScope APISiteScopeImpl information disclosure attempt | drop | drop | drop |
1 | 24292 | SERVER-WEBAPP | HP SiteScope APISiteScopeImpl information disclosure attempt | drop | drop | drop |
1 | 24337 | SERVER-OTHER | Novell Remote Manager off-by-one denial of service attempt | off | off | off |
1 | 24339 | SERVER-WEBAPP | XML entity parsing information disclosure attempt | off | off | off |
1 | 24503 | PROTOCOL-RPC | xdrDecodeString caller_name stack overflow attempt | off | off | off |
1 | 24677 | SERVER-OTHER | RealNetworks Helix server open PDU denial of service attempt | off | off | off |
1 | 24697 | SERVER-APACHE | Apache mod_log_config cookie handling denial of service attempt | off | off | off |
1 | 24698 | SERVER-APACHE | Apache mod_log_config cookie handling denial of service attempt | off | off | off |
1 | 24702 | FILE-OTHER | Adobe Director rcsL chunk parsing denial of service attempt | drop | drop | drop |
1 | 24719 | PROTOCOL-VOIP | Digium Asterisk SCCP call state message offhook | off | off | off |
1 | 24720 | PROTOCOL-VOIP | Digium Asterisk SCCP keypad button message denial of service attempt | off | off | off |
1 | 24761 | FILE-OTHER | Adobe Director rcsL chunk parsing denial of service attempt | drop | drop | drop |
1 | 24964 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 24965 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 24966 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 24967 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 24968 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 24969 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 24970 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 25036 | BROWSER-WEBKIT | Apple Safari WebKit form elements virtual function DoS attempt | off | off | off |
1 | 25250 | SERVER-IIS | Microsoft Windows IIS .NET null character username truncation attempt | off | off | drop |
1 | 25314 | OS-LINUX | Linux kernel IGMP queries denial of service attempt | off | off | off |
1 | 25320 | BROWSER-IE | Microsoft Internet Explorer nonexistent attribute removal memory corruption attempt | off | drop | drop |
1 | 25342 | SERVER-OTHER | ISC dhcpd bootp request missing options field DOS attempt | off | off | off |
1 | 26374 | FILE-IMAGE | ClamAV Antivirus Function Denial of Service attempt | off | off | off |
1 | 26643 | OS-WINDOWS | Microsoft Windows SMB malformed process ID high field denial of service attempt | off | off | off |
1 | 26980 | SERVER-OTHER | RealNetworks Helix snmp master agent denial of service attempt | off | off | off |
1 | 28112 | BROWSER-IE | Microsoft Internet Explorer 9 null character in string information disclosure attempt | off | off | off |
1 | 28331 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28332 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28333 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28334 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28335 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28336 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28337 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28338 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28339 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28340 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28341 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28342 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28343 | FILE-OFFICE | Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access | off | drop | drop |
1 | 28447 | BROWSER-IE | Microsoft Internet Explorer style.position use-after-free memory corruption attempt | off | off | off |
1 | 28851 | SERVER-OTHER | HP ProCurve Manager EJBInvokerServlet remote code execution attempt | off | drop | drop |
1 | 29518 | SERVER-OTHER | HP Data Protector Backup Client Service code execution attempt | drop | drop | drop |
1 | 29801 | SERVER-OTHER | HP Data Protector Backup Client Service code execution attempt | drop | drop | drop |
1 | 29821 | INDICATOR-COMPROMISE | Windows Internet Explorer EMET check and garbage collection | off | drop | drop |
1 | 29822 | INDICATOR-COMPROMISE | Windows Internet Explorer EMET check and garbage collection | off | drop | drop |
1 | 29909 | SERVER-OTHER | HP ProCurve Manager JMXInvokerServlet remote code execution attempt | off | drop | drop |
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 402 | PROTOCOL-ICMP | Destination Unreachable Port Unreachable | off | off | off |
1 | 404 | PROTOCOL-ICMP | Destination Unreachable Protocol Unreachable | off | off | off |
1 | 489 | PROTOCOL-FTP | no password | off | off | off |
1 | 1226 | X11 | xopen | off | off | off |
1 | 1917 | INDICATOR-SCAN | UPnP service discover attempt | off | off | off |
1 | 2419 | FILE-IDENTIFY | RealNetworks Realplayer .ram playlist file download request | off | off | off |
1 | 2420 | FILE-IDENTIFY | RealNetworks Realplayer .rmp playlist file download request | off | off | off |
1 | 2422 | FILE-IDENTIFY | RealNetworks Realplayer .rt playlist file download request | off | off | off |
1 | 2423 | FILE-IDENTIFY | RealNetworks Realplayer .rp playlist file download request | off | off | off |
1 | 2435 | FILE-IDENTIFY | Microsoft emf file download request | off | off | off |
1 | 2436 | FILE-IDENTIFY | Microsoft Windows Audio wmf file download request | off | off | off |
1 | 3143 | OS-WINDOWS | SMB Trans2 FIND_FIRST2 command response overflow attempt | off | off | off |
1 | 3144 | OS-WINDOWS | SMB Trans2 FIND_FIRST2 response andx overflow attempt | off | off | off |
1 | 3145 | OS-WINDOWS | SMB-DS Trans2 FIND_FIRST2 response overflow attempt | off | off | off |
1 | 3146 | OS-WINDOWS | SMB-DS Trans2 FIND_FIRST2 response andx overflow attempt | off | off | off |
1 | 3528 | SERVER-MYSQL | create function access attempt | off | off | off |
1 | 3551 | FILE-IDENTIFY | HTA file download request | off | off | off |
1 | 3627 | SERVER-MAIL | X-LINK2STATE CHUNK command attempt | off | off | off |
1 | 3697 | NETBIOS | DCERPC NCACN-IP-TCP veritas bind attempt | off | off | off |
1 | 3819 | FILE-IDENTIFY | CHM file download request | off | off | off |
1 | 3967 | OS-WINDOWS | DCERPC NCACN-IP-TCP umpnpmgr PNP_QueryResConfList attempt | off | off | off |
1 | 4143 | SERVER-OTHER | lpd receive printer job cascade adaptor protocol request | off | off | off |
1 | 4334 | OS-WINDOWS | DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt | off | off | off |
1 | 4358 | OS-WINDOWS | DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt | off | off | off |
1 | 4918 | OS-WINDOWS | DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList dos attempt | off | off | off |
1 | 5708 | POLICY-OTHER | web server file upload attempt | off | off | off |
1 | 6404 | SERVER-OTHER | Veritas NetBackup Volume Manager connection attempt | off | off | off |
1 | 6469 | SERVER-OTHER | RealVNC connection attempt | off | off | off |
1 | 6470 | SERVER-OTHER | RealVNC authentication types without None type sent attempt | off | off | off |
1 | 8478 | FILE-IDENTIFY | Microsoft Office Publisher file magic detected | off | off | off |
1 | 9840 | FILE-MULTIMEDIA | Apple QuickTime HREF Track Detected | off | off | off |
1 | 9845 | FILE-IDENTIFY | M3U file magic detected | off | off | off |
1 | 10018 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc ReserveGroup attempt | off | off | off |
1 | 10024 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc ClientDBMiniAgentClose attempt | off | off | off |
1 | 10130 | POLICY-OTHER | VERITAS NetBackup system - execution function call access | off | off | off |
1 | 10202 | NETBIOS | DCERPC NCACN-IP-TCP trend-serverprotect _SetRealTimeScanConfigInfo attempt | off | off | off |
1 | 10208 | NETBIOS | DCERPC NCACN-IP-TCP trend-serverprotect COMN_NetTestConnection attempt | off | off | off |
1 | 10486 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc function 15,16,17 attempt | off | off | off |
1 | 11004 | PROTOCOL-IMAP | CRAM-MD5 authentication request detected | off | off | off |
1 | 11836 | FILE-OFFICE | Microsoft Office Visio version number anomaly | off | off | off |
1 | 12182 | FILE-IDENTIFY | Adobe Flash Video file magic detected | off | off | off |
1 | 12278 | FILE-IDENTIFY | Microsoft Media Player compressed skin download request | off | off | off |
1 | 12283 | FILE-IDENTIFY | Microsoft Office Excel xlw file magic detected | off | off | off |
1 | 12307 | NETBIOS | DCERPC NCACN-IP-TCP trend-serverprotect _SetPagerNotifyConfig attempt | off | off | off |
1 | 12317 | NETBIOS | DCERPC NCACN-IP-TCP trend-serverprotect-earthagent RPCFN_CopyAUSrc attempt | off | off | off |
1 | 12326 | NETBIOS | DCERPC NCACN-IP-TCP trend-serverprotect _AddTaskExportLogItem attempt | off | off | off |
1 | 12347 | NETBIOS | DCERPC NCACN-IP-TCP trend-serverprotect _SetSvcImpersonateUser attempt | off | off | off |
1 | 12454 | FILE-IDENTIFY | Microsoft Windows Media ASF file magic detected | off | off | off |
1 | 12455 | FILE-IDENTIFY | SAP Crystal Reports file download request | off | off | off |
1 | 12456 | FILE-IDENTIFY | SAP Crystal Reports file magic detected | off | off | off |
1 | 12489 | NETBIOS | DCERPC NCACN-IP-TCP wkssvc NetrWkstaGetInfo attempt | off | off | off |
1 | 12641 | FILE-IDENTIFY | Microsoft Word for Mac 5 file magic detected | off | off | off |
1 | 12910 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 4 attempt | off | off | off |
1 | 12916 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 12 attempt | off | off | off |
1 | 12922 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 16 attempt | off | off | off |
1 | 12928 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 18 attempt | off | off | off |
1 | 12934 | NETBIOS | DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 19 attempt | off | off | off |
1 | 12972 | FILE-IDENTIFY | Microsoft Media Player asf/wmv/wma file magic detected | off | off | off |
1 | 12984 | NETBIOS | DCERPC NCACN-IP-TCP srvsvc NetSetFileSecurity integer overflow attempt | off | off | off |
1 | 13465 | FILE-IDENTIFY | Microsoft Works file download request | off | off | off |
1 | 13473 | FILE-IDENTIFY | Microsoft Office Publisher file download request | off | off | off |
1 | 13515 | FILE-MULTIMEDIA | Apple QuickTime user agent | off | off | off |
1 | 13583 | FILE-IDENTIFY | Microsoft SYmbolic LinK file download request | off | off | off |
1 | 13585 | FILE-IDENTIFY | Microsoft SYmbolic LinK file magic detected | off | off | off |
1 | 13626 | FILE-IDENTIFY | Microsoft Office Access file magic detected | off | off | off |
1 | 13801 | FILE-IDENTIFY | RTF file download request | off | off | off |
1 | 13834 | BROWSER-IE | Microsoft Internet Explorer request header overwrite | off | off | off |
1 | 13896 | SERVER-MSSQL | Microsoft SQL server MTF file download | off | off | off |
1 | 13911 | FILE-IDENTIFY | Microsoft search file download request | off | off | off |
1 | 14017 | FILE-IDENTIFY | MPEG Layer 3 playlist file download request | off | off | off |
1 | 14018 | FILE-IDENTIFY | PLS multimedia playlist file download request | off | off | off |
1 | 14264 | FILE-IDENTIFY | Microsoft Windows Media Player playlist download | off | off | off |
1 | 14649 | OS-WINDOWS | SMB Search Search filename size integer underflow attempt | off | off | off |
1 | 14710 | OS-WINDOWS | DCERPC NCACN-IP-TCP spoolss EnumJobs attempt | off | off | off |
1 | 14737 | OS-WINDOWS | DCERPC NCACN-IP-TCP host-integration bind attempt | off | off | off |
1 | 15013 | FILE-IDENTIFY | PDF file download request | off | off | off |
1 | 15079 | FILE-IDENTIFY | WAV file download request | off | off | off |
1 | 15080 | FILE-MULTIMEDIA | VideoLAN VLC Media Player WAV processing integer overflow attempt | off | off | off |
1 | 15158 | FILE-IDENTIFY | XML Shareable Playlist Format file download request | off | off | off |
1 | 15196 | OS-WINDOWS | SMB NT Trans NT CREATE unicode param_count underflow attempt | off | off | off |
1 | 15220 | OS-WINDOWS | SMB Trans2 OPEN2 unicode param_count underflow attempt | off | off | off |
1 | 15237 | FILE-IDENTIFY | Java .class file download request | off | off | off |
1 | 15239 | FILE-IDENTIFY | RealNetworks RealMedia format file download request | off | off | off |
1 | 15240 | FILE-IDENTIFY | RealNetworks RealMedia format file download request | off | off | off |
1 | 15294 | FILE-IDENTIFY | Microsoft Office Visio file download request | off | off | off |
1 | 15385 | FILE-IDENTIFY | TwinVQ file download request | off | off | off |
1 | 15427 | FILE-IDENTIFY | SVG file download request | off | off | off |
1 | 15463 | FILE-IDENTIFY | Microsoft Office Excel file download request | off | off | off |
1 | 15464 | FILE-IDENTIFY | Microsoft Office Excel file download request | off | off | off |
1 | 15483 | FILE-IDENTIFY | Adobe Shockwave Flash file download request | off | off | off |
1 | 15516 | FILE-IDENTIFY | AVI multimedia file download request | off | off | off |
1 | 15518 | FILE-IDENTIFY | Embedded Open Type Font file download request | off | off | off |
1 | 15575 | FILE-IDENTIFY | WordPerfect file magic detected | off | off | off |
1 | 15586 | FILE-IDENTIFY | Microsoft Office PowerPoint file download request | off | off | off |
1 | 15587 | FILE-IDENTIFY | Microsoft Office Word file download request | off | off | off |
1 | 15697 | INDICATOR-OBFUSCATION | rename of javascript unescape function detected | off | off | off |
1 | 15860 | OS-WINDOWS | DCERPC NCACN-IP-TCP wkssvc NetrGetJoinInformation attempt | off | off | off |
1 | 15865 | FILE-IDENTIFY | MP4 file download request | off | off | off |
1 | 15870 | FILE-IDENTIFY | 4XM file download request | off | off | off |
1 | 15900 | FILE-IDENTIFY | Audio Interchange file download request | off | off | off |
1 | 15921 | FILE-IDENTIFY | Microsoft multimedia format file download request | off | off | off |
1 | 15922 | FILE-IDENTIFY | MP3 file download request | off | off | off |
1 | 15945 | FILE-IDENTIFY | RSS file download request | off | off | off |
1 | 15987 | FILE-IDENTIFY | DXF file download request | off | off | off |
1 | 16008 | OS-WINDOWS | Multiple Products excessive HTTP 304 Not Modified responses exploit attempt | off | off | off |
1 | 16010 | BROWSER-IE | Microsoft Internet Explorer Javascript Page update race condition attempt | off | off | off |
1 | 16020 | SERVER-MYSQL | login handshake information disclosure attempt | off | off | off |
1 | 16061 | FILE-IDENTIFY | X PixMap file download request | off | off | off |
1 | 16064 | BROWSER-IE | Microsoft Internet Explorer onBeforeUnload address bar spoofing attempt | off | off | off |
1 | 16143 | FILE-IDENTIFY | Microsoft asf file magic detected | off | off | off |
1 | 16196 | SERVER-OTHER | Symantec Backup Exec System Recovery Manager unauthorized file upload attempt | off | off | off |
1 | 16205 | FILE-IDENTIFY | BMP file download request | off | off | off |
1 | 16219 | FILE-IDENTIFY | Adobe Director Movie file download request | off | off | off |
1 | 16286 | FILE-IDENTIFY | TrueType font file download request | off | off | off |
1 | 16377 | BROWSER-IE | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt | off | drop | drop |
1 | 16397 | OS-WINDOWS | SMB andx invalid server name share access | off | off | off |
1 | 16398 | OS-WINDOWS | SMB invalid server name share access | off | off | off |
1 | 16399 | OS-WINDOWS | SMB unicode andx invalid server name share access | off | off | off |
1 | 16400 | OS-WINDOWS | SMB unicode invalid server name share access | off | off | off |
1 | 16401 | OS-WINDOWS | SMB andx invalid server name share access | off | off | off |
1 | 16402 | OS-WINDOWS | SMB invalid server name share access | off | off | off |
1 | 16403 | OS-WINDOWS | SMB unicode andx invalid server name share access | off | off | off |
1 | 16404 | OS-WINDOWS | SMB unicode invalid server name share access | off | off | off |
1 | 16406 | FILE-IDENTIFY | JPEG file download request | off | off | off |
1 | 16407 | FILE-IDENTIFY | JPEG file download request | off | off | off |
1 | 16425 | FILE-IDENTIFY | Portable Executable binary file download request | off | off | off |
1 | 16435 | FILE-IDENTIFY | Ultimate Packer for Executables/UPX v0.62-v1.22 packed file magic detected | off | off | off |
1 | 16473 | FILE-IDENTIFY | Microsoft Windows Movie Maker project file download request | off | off | off |
1 | 16474 | FILE-IDENTIFY | Microsoft Compound File Binary v3 file magic detected | off | off | off |
1 | 16529 | FILE-IDENTIFY | JPEG file download request | off | off | off |
1 | 16754 | NETBIOS | SMB /PlughNTCommand andx create tree attempt | off | off | off |
1 | 16755 | NETBIOS | SMB /PlughNTCommand create tree attempt | off | off | off |
1 | 16756 | NETBIOS | SMB /PlughNTCommand unicode andx create tree attempt | off | off | off |
1 | 16757 | NETBIOS | SMB /PlughNTCommand unicode create tree attempt | off | off | off |
1 | 17113 | OS-WINDOWS | Microsoft SilverLight ImageSource redefine flowbit | off | off | off |
1 | 17116 | FILE-IDENTIFY | Microsoft Windows Media ASX file download request | off | off | off |
1 | 17151 | NETBIOS | SMB negotiate protocol request - ascii strings | off | off | off |
1 | 17223 | FILE-FLASH | Adobe Flash Player navigateToURL cross-site scripting attempt | off | off | off |
1 | 17229 | FILE-IDENTIFY | Tiff little endian file magic detected | off | off | off |
1 | 17230 | FILE-IDENTIFY | Tiff big endian file magic detected | off | off | off |
1 | 17241 | FILE-IDENTIFY | Microsoft Windows Media wmv file download request | off | off | off |
1 | 17259 | FILE-IDENTIFY | MOV file download request | off | off | off |
1 | 17314 | FILE-IDENTIFY | OLE document file magic detected | off | off | off |
1 | 17327 | SERVER-MAIL | Qualcomm WorldMail Server Response | off | off | off |
1 | 17332 | SERVER-MAIL | Content-Disposition attachment | off | off | off |
1 | 17346 | SERVER-OTHER | IBM Lotus Notes Cross Site Scripting attempt | off | off | off |
1 | 17359 | FILE-IDENTIFY | XBM image file download request | off | off | off |
1 | 17364 | FILE-IDENTIFY | Microsoft Windows Help Workshop CNT Help file download request | off | off | off |
1 | 17370 | SERVER-WEBAPP | Squid authentication headers handling denial of service attempt | off | off | off |
1 | 17380 | FILE-IDENTIFY | PNG file download request | off | off | off |
1 | 17394 | FILE-IDENTIFY | GIF file download request | off | off | off |
1 | 17396 | SERVER-OTHER | VNC client authentication response | off | off | off |
1 | 17400 | INDICATOR-OBFUSCATION | rename of javascript unescape function detected | off | off | off |
1 | 17407 | FILE-IDENTIFY | Microsoft Windows help file download request | off | off | off |
1 | 17426 | FILE-IDENTIFY | RAT file download request | off | off | off |
1 | 17428 | OS-WINDOWS | Microsoft Windows ASP.NET information disclosure attempt | off | off | off |
1 | 17429 | OS-WINDOWS | Microsoft Windows ASP.NET information disclosure attempt | off | off | off |
1 | 17431 | SERVER-IIS | Microsoft Windows IIS SChannel improper certificate verification | off | off | off |
1 | 17435 | OS-WINDOWS | DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt | off | off | off |
1 | 17436 | OS-WINDOWS | DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt | off | off | off |
1 | 17437 | OS-WINDOWS | DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt | off | off | off |
1 | 17438 | OS-WINDOWS | DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt | off | off | off |
1 | 17441 | FILE-IDENTIFY | LNK file download request | off | off | off |
1 | 17446 | BROWSER-IE | Microsoft Internet Explorer FTP client directory traversal attempt | off | off | off |
1 | 17509 | FILE-IDENTIFY | Microsoft Windows .NET Manifest file download request | off | off | off |
1 | 17510 | FILE-IDENTIFY | Microsoft Windows .NET Deploy file download request | off | off | off |
1 | 17520 | SERVER-OTHER | CA ARCserve Backup DB Engine Denial of Service | off | off | off |
1 | 17534 | SERVER-OTHER | IPP Application Content | off | off | off |
1 | 17540 | FILE-IDENTIFY | LZH file download request | off | off | off |
1 | 17547 | FILE-IDENTIFY | SMIL file download request | off | off | off |
1 | 17552 | FILE-IDENTIFY | Adobe Pagemaker file download request | off | off | off |
1 | 17600 | FILE-IDENTIFY | XUL file download request | off | off | off |
1 | 17659 | SERVER-ORACLE | xdb.dbms_xmlschema buffer overflow attempt | off | off | off |
1 | 17679 | FILE-IDENTIFY | Apple disk image file download request | off | off | off |
1 | 17703 | BROWSER-IE | Microsoft Internet Explorer popup title bar spoofing attempt | off | off | off |
1 | 17707 | NETBIOS | DCERPC NCACN-IP-TCP trend-serverprotect trend_req_num buffer overflow attempt | off | off | off |
1 | 17714 | NETBIOS | DCERPC NCACN-IP-TCP trend-serverprotect CMON_ActiveUpdate attempt | off | off | off |
1 | 17715 | NETBIOS | DCERPC NCACN-IP-TCP trend-serverprotect CMON_ActiveUpdate attempt | off | off | off |
1 | 17726 | BROWSER-IE | Microsoft Internet Explorer address bar spoofing attempt | off | off | off |
1 | 17732 | FILE-IDENTIFY | TIFF file download request | off | off | off |
1 | 17733 | FILE-IDENTIFY | XML file download request | off | off | off |
1 | 17739 | FILE-IDENTIFY | FlashPix file download request | off | off | off |
1 | 17751 | FILE-IDENTIFY | OpenType Font file download request | off | off | off |
1 | 17801 | FILE-IDENTIFY | Adobe Director Movie file magic detected | off | off | off |
1 | 17802 | FILE-IDENTIFY | Adobe Director Movie file download request | off | off | off |
1 | 17809 | FILE-IDENTIFY | Apple Quicktime qt file download request | off | off | off |
1 | 18234 | FILE-IDENTIFY | QuickDraw/PICT file download request | off | off | off |
1 | 18469 | CONTENT-REPLACE | Microsoft Windows Encrypted DCERPC request attempt | off | off | off |
1 | 18472 | NETBIOS | DCERPC NCACN-IP-TCP lsarpc LsarLookupSids lsa_io_trans_name heap overflow attempt | off | off | off |
1 | 18516 | FILE-IDENTIFY | Microsoft Office Word file download request | off | off | off |
1 | 18593 | FILE-IDENTIFY | BitTorrent torrent file download request | off | off | off |
1 | 18675 | FILE-IDENTIFY | Microsoft Windows Fax Cover page document file download request | off | off | off |
1 | 19074 | INDICATOR-OBFUSCATION | javascript uuencoded noop sled attempt | off | off | off |
1 | 19081 | INDICATOR-OBFUSCATION | known suspicious decryption routine | off | off | drop |
1 | 19111 | FILE-FLASH | Adobe Flash Media Server memory exhaustion | off | off | off |
1 | 19128 | FILE-IDENTIFY | RealNetworks Realplayer REC file magic detected | off | off | off |
1 | 19129 | FILE-IDENTIFY | RealNetworks Realplayer .r1m file magic detected | off | off | off |
1 | 19166 | FILE-IDENTIFY | Microsoft Office Excel file magic detected | off | off | off |
1 | 19211 | FILE-IDENTIFY | ZIP archive file download request | off | off | off |
1 | 19215 | FILE-IDENTIFY | Google Chrome extension file download request | off | off | off |
1 | 19218 | FILE-IDENTIFY | Microsoft Windows Fax Cover page document file download request | off | off | off |
1 | 19224 | FILE-IDENTIFY | Cisco Webex wrf file download request | off | off | off |
1 | 19422 | FILE-IDENTIFY | matroska file magic detected | off | off | off |
1 | 19423 | FILE-IDENTIFY | MKV file download request | off | off | off |
1 | 19424 | FILE-IDENTIFY | MKA file download request | off | off | off |
1 | 19425 | FILE-IDENTIFY | MKS file download request | off | off | off |
1 | 19430 | FILE-IDENTIFY | MIDI file download request | off | off | off |
1 | 19907 | FILE-IDENTIFY | PICT file magic detected | off | off | off |
1 | 20032 | FILE-IDENTIFY | MIME file type file download request | off | off | off |
1 | 20223 | FILE-IDENTIFY | SMI file download request | off | off | off |
1 | 20269 | FILE-IDENTIFY | FON font file download request | off | drop | drop |
1 | 20282 | FILE-IDENTIFY | S3M file download request | off | off | off |
1 | 20287 | FILE-IDENTIFY | QCP file download request | off | off | off |
1 | 20450 | FILE-IDENTIFY | MPEG video stream file magic detected | off | off | off |
1 | 20451 | FILE-IDENTIFY | MPEG sys stream file magic detected | off | off | off |
1 | 20456 | FILE-IDENTIFY | RealNetworks Real Media file magic detected | off | off | off |
1 | 20459 | FILE-IDENTIFY | GIF file magic detected | off | off | off |
1 | 20460 | FILE-IDENTIFY | MP3 file magic detected | off | off | off |
1 | 20463 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 20464 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 20465 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 20466 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 20467 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 20468 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 20469 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 20471 | FILE-IDENTIFY | RIFX file magic detected | off | off | off |
1 | 20472 | FILE-IDENTIFY | RAR file magic detected | off | off | off |
1 | 20478 | FILE-IDENTIFY | PNG file magic detected | off | off | off |
1 | 20480 | FILE-IDENTIFY | JPEG file magic detection | off | off | off |
1 | 20481 | FILE-IDENTIFY | MP3 file magic detected | off | off | off |
1 | 20483 | FILE-IDENTIFY | JPEG file magic detected | off | off | off |
1 | 20486 | FILE-IDENTIFY | RTF file magic detected | off | off | off |
1 | 20492 | FILE-IDENTIFY | Universal Binary/Java Bytecode file magic detected | off | off | off |
1 | 20493 | FILE-IDENTIFY | jarpack file magic detected | off | off | off |
1 | 20494 | FILE-IDENTIFY | PDF file magic detected | off | off | off |
1 | 20496 | FILE-IDENTIFY | Adobe Shockwave Flash file magic detected | off | off | off |
1 | 20497 | FILE-IDENTIFY | Adobe Shockwave Flash file magic detected | off | off | off |
1 | 20500 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20501 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20502 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20503 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20507 | FILE-IDENTIFY | Adobe Shockwave Flash file magic detected | off | off | off |
1 | 20514 | FILE-IDENTIFY | dmg file magic detected | off | off | off |
1 | 20518 | FILE-IDENTIFY | rmf file download request | off | off | off |
1 | 20521 | FILE-IDENTIFY | Flac file magic detected | off | off | off |
1 | 20522 | FILE-IDENTIFY | VideoLAN VLC file magic detected | off | off | off |
1 | 20544 | FILE-IDENTIFY | Adobe Flash Player FLV file download request | off | off | off |
1 | 20621 | FILE-IDENTIFY | JAR file download request | off | off | off |
1 | 20723 | FILE-IDENTIFY | Microsoft Office Word docx file download request | off | off | off |
1 | 20733 | FILE-IDENTIFY | Microsoft Windows Media Player DVR file download request | off | off | off |
1 | 20792 | FILE-IDENTIFY | Microsoft Office Excel file attachment detected | off | off | off |
1 | 20793 | FILE-IDENTIFY | Microsoft Office Excel file attachment detected | off | off | off |
1 | 20795 | FILE-IDENTIFY | Microsoft Office Word file attachment detected | off | off | off |
1 | 20796 | FILE-IDENTIFY | Microsoft Office Word file attachment detected | off | off | off |
1 | 20798 | FILE-IDENTIFY | Adobe Shockwave Flash file attachment detected | off | off | off |
1 | 20799 | FILE-IDENTIFY | Adobe Shockwave Flash file attachment detected | off | off | off |
1 | 20800 | FILE-IDENTIFY | MIME file type file attachment detected | off | off | off |
1 | 20801 | FILE-IDENTIFY | MIME file type file attachment detected | off | off | off |
1 | 20839 | FILE-IDENTIFY | eSignal .quo file download request | off | off | off |
1 | 20840 | FILE-IDENTIFY | eSignal .por file download request | off | off | off |
1 | 20841 | FILE-IDENTIFY | eSignal .sum file download request | off | off | off |
1 | 20854 | FILE-IDENTIFY | Microsoft Office Visio file attachment detected | off | off | off |
1 | 20855 | FILE-IDENTIFY | Microsoft Office Visio file attachment detected | off | off | off |
1 | 20856 | FILE-IDENTIFY | TwinVQ file attachment detected | off | off | off |
1 | 20857 | FILE-IDENTIFY | TwinVQ file attachment detected | off | off | off |
1 | 20874 | SERVER-OTHER | IBM Tivoli Storage Manager Express Backup initialization packet | off | off | off |
1 | 20897 | FILE-IDENTIFY | MIDI file magic detected | off | off | off |
1 | 20898 | FILE-IDENTIFY | MIDI file attachment detected | off | off | off |
1 | 20899 | FILE-IDENTIFY | MIDI file attachment detected | off | off | off |
1 | 20905 | FILE-IDENTIFY | X PixMap file attachment detected | off | off | off |
1 | 20906 | FILE-IDENTIFY | X PixMap file attachment detected | off | off | off |
1 | 20907 | FILE-IDENTIFY | DXF file attachment detected | off | off | off |
1 | 20908 | FILE-IDENTIFY | DXF file attachment detected | off | off | off |
1 | 20909 | FILE-IDENTIFY | Microsoft Windows Media ASF file attachment detected | off | off | off |
1 | 20910 | FILE-IDENTIFY | Microsoft Windows Media ASF file attachment detected | off | off | off |
1 | 20913 | FILE-IDENTIFY | XML Shareable Playlist Format file attachment detected | off | off | off |
1 | 20914 | FILE-IDENTIFY | XML Shareable Playlist Format file attachment detected | off | off | off |
1 | 20924 | FILE-IDENTIFY | PLS file magic detected | off | off | off |
1 | 20925 | FILE-IDENTIFY | Adobe Pagemaker file attachment detected | off | off | off |
1 | 20926 | FILE-IDENTIFY | Adobe Pagemaker file attachment detected | off | off | off |
1 | 20928 | FILE-IDENTIFY | SMIL file magic detected | off | off | off |
1 | 20929 | FILE-IDENTIFY | MKV file attachment detected | off | off | off |
1 | 20930 | FILE-IDENTIFY | MKV file attachment detected | off | off | off |
1 | 20931 | FILE-IDENTIFY | MKS file attachment detected | off | off | off |
1 | 20932 | FILE-IDENTIFY | MKS file attachment detected | off | off | off |
1 | 20933 | FILE-IDENTIFY | MKA file attachment detected | off | off | off |
1 | 20934 | FILE-IDENTIFY | MKA file attachment detected | off | off | off |
1 | 20935 | FILE-IDENTIFY | QCP file attachment detected | off | off | off |
1 | 20936 | FILE-IDENTIFY | QCP file attachment detected | off | off | off |
1 | 20937 | FILE-IDENTIFY | Adobe Shockwave Flash file download request | off | off | off |
1 | 20938 | FILE-IDENTIFY | Adobe Shockwave Flash file download request | off | off | off |
1 | 20939 | FILE-IDENTIFY | Adobe Shockwave Flash file download request | off | off | off |
1 | 20940 | FILE-IDENTIFY | Adobe Shockwave Flash file download request | off | off | off |
1 | 20941 | FILE-IDENTIFY | Adobe Shockwave Flash file attachment detected | off | off | off |
1 | 20942 | FILE-IDENTIFY | Adobe Shockwave Flash file attachment detected | off | off | off |
1 | 20943 | FILE-IDENTIFY | Adobe Shockwave Flash file attachment detected | off | off | off |
1 | 20944 | FILE-IDENTIFY | Adobe Shockwave Flash file attachment detected | off | off | off |
1 | 20945 | FILE-IDENTIFY | Adobe Shockwave Flash file attachment detected | off | off | off |
1 | 20946 | FILE-IDENTIFY | Adobe Shockwave Flash file attachment detected | off | off | off |
1 | 20947 | FILE-IDENTIFY | Adobe Shockwave Flash file attachment detected | off | off | off |
1 | 20948 | FILE-IDENTIFY | Adobe Shockwave Flash file attachment detected | off | off | off |
1 | 20950 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20951 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20952 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20953 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20954 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20955 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20956 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20957 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20958 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20959 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 20960 | FILE-IDENTIFY | Flac file download request | off | off | off |
1 | 20961 | FILE-IDENTIFY | TTE file download request | off | off | off |
1 | 20962 | FILE-IDENTIFY | OTF file download request | off | off | off |
1 | 20963 | FILE-IDENTIFY | DIB file download request | off | off | off |
1 | 20964 | FILE-IDENTIFY | SAMI file download request | off | off | off |
1 | 20965 | FILE-IDENTIFY | JPEG file download request | off | off | off |
1 | 20966 | FILE-IDENTIFY | JPEG file download request | off | off | off |
1 | 20967 | FILE-IDENTIFY | JPEG file download request | off | off | off |
1 | 20968 | FILE-IDENTIFY | Apple disk image file download request | off | off | off |
1 | 20969 | FILE-IDENTIFY | M4A file download request | off | off | off |
1 | 20970 | FILE-IDENTIFY | M4P file download request | off | off | off |
1 | 20971 | FILE-IDENTIFY | M4R file download request | off | off | off |
1 | 20972 | FILE-IDENTIFY | M4V file magic request | off | off | off |
1 | 20973 | FILE-IDENTIFY | M4B file download request | off | off | off |
1 | 20974 | FILE-IDENTIFY | 3GP file download request | off | off | off |
1 | 20975 | FILE-IDENTIFY | 3G2 file download request | off | off | off |
1 | 20976 | FILE-IDENTIFY | K3G file download request | off | off | off |
1 | 20977 | FILE-IDENTIFY | SKM file download request | off | off | off |
1 | 20978 | FILE-IDENTIFY | TTE file attachment detected | off | off | off |
1 | 20979 | FILE-IDENTIFY | TTE file attachment detected | off | off | off |
1 | 20980 | FILE-IDENTIFY | OTF file attachment detected | off | off | off |
1 | 20981 | FILE-IDENTIFY | OTF file attachment detected | off | off | off |
1 | 20982 | FILE-IDENTIFY | Microsoft Office PowerPoint file attachment detected | off | off | off |
1 | 20983 | FILE-IDENTIFY | Microsoft Office PowerPoint file attachment detected | off | off | off |
1 | 20986 | FILE-IDENTIFY | Microsoft Office Word docx file attachment detected | off | off | off |
1 | 20987 | FILE-IDENTIFY | Microsoft Office Word docx file attachment detected | off | off | off |
1 | 20991 | FILE-IDENTIFY | TTF file magic detected | off | off | off |
1 | 20992 | FILE-IDENTIFY | SAMI file magic detected | off | off | off |
1 | 21035 | FILE-IDENTIFY | PDF file attachment detected | off | off | off |
1 | 21036 | FILE-IDENTIFY | PDF file attachment detected | off | off | off |
1 | 21059 | FILE-IDENTIFY | AVI Video file magic detected | off | off | off |
1 | 21061 | FILE-IDENTIFY | AVI file attachment detected | off | off | off |
1 | 21062 | FILE-IDENTIFY | AVI file attachment detected | off | off | off |
1 | 21109 | FILE-IDENTIFY | MPEG video stream file download request | off | off | off |
1 | 21110 | FILE-IDENTIFY | MPEG video stream file attachment detected | off | off | off |
1 | 21111 | FILE-IDENTIFY | MPEG video stream file attachment detected | off | off | off |
1 | 21113 | FILE-IDENTIFY | Cisco Webex Player .wrf file magic detected | off | off | off |
1 | 21152 | FILE-IDENTIFY | S3M file attachment detected | off | off | off |
1 | 21153 | FILE-IDENTIFY | S3M file attachment detected | off | off | off |
1 | 21174 | FILE-IDENTIFY | RealNetworks RealPlayer realtext file download request | off | off | off |
1 | 21282 | FILE-IDENTIFY | XSL file download request | off | off | off |
1 | 21283 | FILE-IDENTIFY | XSL file attachment detected | off | off | off |
1 | 21284 | FILE-IDENTIFY | XSL file attachment detected | off | off | off |
1 | 21285 | FILE-IDENTIFY | XSLT file download request | off | off | off |
1 | 21286 | FILE-IDENTIFY | XSLT file attachment detected | off | off | off |
1 | 21287 | FILE-IDENTIFY | XSLT file attachment detected | off | off | off |
1 | 21288 | FILE-IDENTIFY | XML download detected | off | off | off |
1 | 21410 | FILE-IDENTIFY | paq8o file download request | off | off | off |
1 | 21411 | FILE-IDENTIFY | paq8o file attachment detected | off | off | off |
1 | 21412 | FILE-IDENTIFY | paq8o file attachment detected | off | off | off |
1 | 21478 | FILE-IDENTIFY | CHM file attachment detected | off | off | off |
1 | 21479 | FILE-IDENTIFY | CHM file attachment detected | off | off | off |
1 | 21480 | FILE-IDENTIFY | XML file magic detected | off | off | off |
1 | 21498 | FILE-IDENTIFY | XML file magic detected | off | off | off |
1 | 21499 | FILE-IDENTIFY | XML file attachment detected | off | off | off |
1 | 21500 | FILE-IDENTIFY | XML file attachment detected | off | off | off |
1 | 21611 | FILE-IDENTIFY | RAT file attachment detected | off | off | off |
1 | 21612 | FILE-IDENTIFY | RAT file attachment detected | off | off | off |
1 | 21613 | FILE-IDENTIFY | PNG file attachment detected | off | off | off |
1 | 21614 | FILE-IDENTIFY | PNG file attachment detected | off | off | off |
1 | 21615 | FILE-IDENTIFY | WMF file attachment detected | off | off | off |
1 | 21616 | FILE-IDENTIFY | WMF file attachment detected | off | off | off |
1 | 21617 | FILE-IDENTIFY | RT file attachment detected | off | off | off |
1 | 21618 | FILE-IDENTIFY | RT file attachment detected | off | off | off |
1 | 21620 | FILE-IDENTIFY | WAV file magic detected | off | off | off |
1 | 21621 | FILE-IDENTIFY | AVI file magic detected | off | off | off |
1 | 21623 | FILE-IDENTIFY | QUO file attachment detected | off | off | off |
1 | 21624 | FILE-IDENTIFY | QUO file attachment detected | off | off | off |
1 | 21625 | FILE-IDENTIFY | POR file attachment detected | off | off | off |
1 | 21626 | FILE-IDENTIFY | POR file attachment detected | off | off | off |
1 | 21627 | FILE-IDENTIFY | SUM file attachment detected | off | off | off |
1 | 21628 | FILE-IDENTIFY | SUM file attachment detected | off | off | off |
1 | 21648 | FILE-IDENTIFY | QuickDraw/PICT file attachment detected | off | off | off |
1 | 21649 | FILE-IDENTIFY | QuickDraw/PICT file attachment detected | off | off | off |
1 | 21650 | FILE-IDENTIFY | QuickDraw/PICT file download request | off | off | off |
1 | 21651 | FILE-IDENTIFY | QuickDraw/PICT file attachment detected | off | off | off |
1 | 21652 | FILE-IDENTIFY | QuickDraw/PICT file attachment detected | off | off | off |
1 | 21687 | FILE-IDENTIFY | PLS file attachment detected | off | off | off |
1 | 21688 | FILE-IDENTIFY | PLS file attachment detected | off | off | off |
1 | 21691 | FILE-IDENTIFY | SMIL file attachment detected | off | off | off |
1 | 21692 | FILE-IDENTIFY | SMIL file attachment detected | off | off | off |
1 | 21693 | FILE-IDENTIFY | FLAC file attachment detected | off | off | off |
1 | 21694 | FILE-IDENTIFY | FLAC file attachment detected | off | off | off |
1 | 21695 | FILE-IDENTIFY | SMI file attachment detected | off | off | off |
1 | 21696 | FILE-IDENTIFY | SMI file attachment detected | off | off | off |
1 | 21697 | FILE-IDENTIFY | SAMI file attachment detected | off | off | off |
1 | 21698 | FILE-IDENTIFY | SAMI file attachment detected | off | off | off |
1 | 21699 | FILE-IDENTIFY | Microsoft Office Excel xlw file attachment detected | off | off | off |
1 | 21700 | FILE-IDENTIFY | Microsoft Office Excel xlw file attachment detected | off | off | off |
1 | 21701 | FILE-IDENTIFY | FlashPix file attachment detected | off | off | off |
1 | 21702 | FILE-IDENTIFY | FlashPix file attachment detected | off | off | off |
1 | 21703 | FILE-IDENTIFY | 4XM file attachment detected | off | off | off |
1 | 21704 | FILE-IDENTIFY | 4XM file attachment detected | off | off | off |
1 | 21705 | FILE-IDENTIFY | BitTorrent torrent file attachment detected | off | off | off |
1 | 21706 | FILE-IDENTIFY | BitTorrent torrent file attachment detected | off | off | off |
1 | 21709 | FILE-IDENTIFY | AIFF file attachment detected | off | off | off |
1 | 21710 | FILE-IDENTIFY | AIFF file attachment detected | off | off | off |
1 | 21711 | FILE-IDENTIFY | PFA file download request | off | off | off |
1 | 21712 | FILE-IDENTIFY | PFA file magic detected | off | off | off |
1 | 21713 | FILE-IDENTIFY | PFA file attachment detected | off | off | off |
1 | 21714 | FILE-IDENTIFY | PFA file attachment detected | off | off | off |
1 | 21715 | FILE-IDENTIFY | PFB file download request | off | off | off |
1 | 21716 | FILE-IDENTIFY | PFB file attachment detected | off | off | off |
1 | 21717 | FILE-IDENTIFY | PFB file attachment detected | off | off | off |
1 | 21718 | FILE-IDENTIFY | PFM file download request | off | off | off |
1 | 21719 | FILE-IDENTIFY | PFM file attachment detected | off | off | off |
1 | 21720 | FILE-IDENTIFY | PFM file attachment detected | off | off | off |
1 | 21721 | FILE-IDENTIFY | AFM file download request | off | off | off |
1 | 21722 | FILE-IDENTIFY | AFM file attachment detected | off | off | off |
1 | 21723 | FILE-IDENTIFY | AFM file attachment detected | off | off | off |
1 | 21724 | FILE-IDENTIFY | ANI file download request | off | off | off |
1 | 21725 | FILE-IDENTIFY | ANI file attachment detected | off | off | off |
1 | 21726 | FILE-IDENTIFY | ANI file attachment detected | off | off | off |
1 | 21727 | FILE-IDENTIFY | ANI file magic detection | off | off | off |
1 | 21728 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21729 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21730 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21731 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21732 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21733 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21734 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21735 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21736 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21737 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21738 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21739 | FILE-IDENTIFY | JPG file attachment detected | off | off | off |
1 | 21740 | FILE-IDENTIFY | Microsoft Windows Media asx file attachment detected | off | off | off |
1 | 21741 | FILE-IDENTIFY | Microsoft Windows Media asx file attachment detected | off | off | off |
1 | 21742 | FILE-IDENTIFY | Embedded Open Type Font file attachment detected | off | off | off |
1 | 21743 | FILE-IDENTIFY | Embedded Open Type Font file attachment detected | off | off | off |
1 | 21744 | FILE-IDENTIFY | AVI file attachment detected | off | off | off |
1 | 21745 | FILE-IDENTIFY | AVI file attachment detected | off | off | off |
1 | 21746 | FILE-IDENTIFY | RTF file attachment detected | off | off | off |
1 | 21747 | FILE-IDENTIFY | RTF file attachment detected | off | off | off |
1 | 21748 | FILE-IDENTIFY | HPJ file download request | off | off | off |
1 | 21749 | FILE-IDENTIFY | HPJ file attachment detected | off | off | off |
1 | 21750 | FILE-IDENTIFY | HPJ file attachment detected | off | off | off |
1 | 21751 | FILE-IDENTIFY | HPJ file magic detected | off | off | off |
1 | 21807 | FILE-IDENTIFY | Adobe Download Manager aom file download request | off | off | off |
1 | 21808 | FILE-IDENTIFY | Adobe Download Manager aom file attachment detected | off | off | off |
1 | 21809 | FILE-IDENTIFY | Adobe Download Manager aom file attachment detected | off | off | off |
1 | 21810 | FILE-IDENTIFY | Adobe Download Manager aom file magic detected | off | off | off |
1 | 21811 | FILE-IDENTIFY | Apple Quicktime FLIC animation file file download request | off | off | off |
1 | 21812 | FILE-IDENTIFY | Apple Quicktime FLIC animation file file attachment detected | off | off | off |
1 | 21813 | FILE-IDENTIFY | Apple Quicktime FLIC animation file file attachment detected | off | off | off |
1 | 21814 | FILE-IDENTIFY | Apple Quicktime FLIC file magic detected | off | off | off |
1 | 21815 | FILE-IDENTIFY | LZH file attachment detected | off | off | off |
1 | 21816 | FILE-IDENTIFY | LZH file attachment detected | off | off | off |
1 | 21854 | FILE-IDENTIFY | LNK file attachment detected | off | off | off |
1 | 21855 | FILE-IDENTIFY | LNK file attachment detected | off | off | off |
1 | 21856 | FILE-IDENTIFY | ZIP file attachment detected | off | off | off |
1 | 21857 | FILE-IDENTIFY | ZIP file attachment detected | off | off | off |
1 | 21861 | FILE-IDENTIFY | WRF file attachment detected | off | off | off |
1 | 21862 | FILE-IDENTIFY | WRF file attachment detected | off | off | off |
1 | 21865 | FILE-IDENTIFY | Microsoft Windows Fax Cover page document file attachment detected | off | off | off |
1 | 21866 | FILE-IDENTIFY | Microsoft Windows Fax Cover page document file attachment detected | off | off | off |
1 | 21867 | FILE-IDENTIFY | Microsoft Windows Fax Cover page document file attachment detected | off | off | off |
1 | 21868 | FILE-IDENTIFY | Microsoft Windows Fax Cover page document file attachment detected | off | off | off |
1 | 21870 | FILE-IDENTIFY | CNT file attachment detected | off | off | off |
1 | 21871 | FILE-IDENTIFY | CNT file attachment detected | off | off | off |
1 | 21872 | FILE-IDENTIFY | GIF file attachment detected | off | off | off |
1 | 21873 | FILE-IDENTIFY | GIF file attachment detected | off | off | off |
1 | 21879 | FILE-IDENTIFY | Microsoft search file attachment detected | off | off | off |
1 | 21880 | FILE-IDENTIFY | Microsoft search file attachment detected | off | off | off |
1 | 21884 | FILE-IDENTIFY | Microsoft Office Publisher file attachment detected | off | off | off |
1 | 21885 | FILE-IDENTIFY | Microsoft Office Publisher file attachment detected | off | off | off |
1 | 21886 | FILE-IDENTIFY | OpenType Font file attachment detected | off | off | off |
1 | 21887 | FILE-IDENTIFY | OpenType Font file attachment detected | off | off | off |
1 | 21888 | FILE-IDENTIFY | Microsoft Windows Movie Maker file attachment detected | off | off | off |
1 | 21889 | FILE-IDENTIFY | Microsoft Windows Movie Maker file attachment detected | off | off | off |
1 | 21890 | FILE-IDENTIFY | Adobe Director Movie file attachment detected | off | off | off |
1 | 21891 | FILE-IDENTIFY | Adobe Director Movie file attachment detected | off | off | off |
1 | 21892 | FILE-IDENTIFY | Adobe Director Movie file attachment detected | off | off | off |
1 | 21893 | FILE-IDENTIFY | Adobe Director Movie file attachment detected | off | off | off |
1 | 21894 | FILE-IDENTIFY | SVG file attachment detected | off | off | off |
1 | 21895 | FILE-IDENTIFY | SVG file attachment detected | off | off | off |
1 | 21908 | FILE-IDENTIFY | Portable Executable file attachment detected | off | off | off |
1 | 21909 | FILE-IDENTIFY | Portable Executable file attachment detected | off | off | off |
1 | 21915 | SERVER-OTHER | Novell Groupwise HTTP login request | off | off | off |
1 | 21916 | SERVER-OTHER | Novell Groupwise HTTP login request | off | off | off |
1 | 21999 | FILE-IDENTIFY | OpenType Font file magic detection | off | off | off |
1 | 22943 | FILE-IDENTIFY | NAB file download request | off | off | off |
1 | 22944 | FILE-IDENTIFY | NAB file attachment detected | off | off | off |
1 | 22945 | FILE-IDENTIFY | NAB file attachment detected | off | off | off |
1 | 22946 | FILE-IDENTIFY | NAB file magic detected | off | off | off |
1 | 22961 | FILE-IDENTIFY | RealNetworks RealPlayer RAM file attachment detected | off | off | off |
1 | 22962 | FILE-IDENTIFY | RealNetworks RealPlayer RAM file attachment detected | off | off | off |
1 | 22965 | FILE-IDENTIFY | RealNetworks RealPlayer RT file attachment detected | off | off | off |
1 | 22966 | FILE-IDENTIFY | RealNetworks RealPlayer RT file attachment detected | off | off | off |
1 | 22971 | FILE-IDENTIFY | MPEG Layer 3 playlist file attachment detected | off | off | off |
1 | 22972 | FILE-IDENTIFY | m3u playlist file file attachment detected | off | off | off |
1 | 22979 | FILE-IDENTIFY | M4V file attachment detected | off | off | off |
1 | 22980 | FILE-IDENTIFY | M4V file attachment detected | off | off | off |
1 | 22993 | FILE-IDENTIFY | MP4 file attachment detected | off | off | off |
1 | 22994 | FILE-IDENTIFY | MP4 file attachment detected | off | off | off |
1 | 22995 | FILE-IDENTIFY | Apple QuickTime Movie file attachment detected | off | off | off |
1 | 22996 | FILE-IDENTIFY | Apple QuickTime Movie file attachment detected | off | off | off |
1 | 22999 | FILE-IDENTIFY | Microsoft Windows Audio wmf file magic detected | off | off | off |
1 | 23000 | FILE-IDENTIFY | Microsoft Windows Media Player DVR file attachment detected | off | off | off |
1 | 23001 | FILE-IDENTIFY | Microsoft Windows Media Player DVR file attachment detected | off | off | off |
1 | 23011 | FILE-IDENTIFY | Collada file download request | off | off | off |
1 | 23012 | FILE-IDENTIFY | Collada file attachment detected | off | off | off |
1 | 23013 | FILE-IDENTIFY | Collada file attachment detected | off | off | off |
1 | 23167 | FILE-IDENTIFY | MPG video stream file download request | off | off | off |
1 | 23168 | FILE-IDENTIFY | MPG video stream file attachment detected | off | off | off |
1 | 23169 | FILE-IDENTIFY | MPG video stream file attachment detected | off | off | off |
1 | 23188 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23189 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23190 | FILE-IDENTIFY | Windows Media Metafile file download request | off | off | off |
1 | 23191 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23192 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23193 | FILE-IDENTIFY | Windows Media Metafile file download request | off | off | off |
1 | 23194 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23195 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23196 | FILE-IDENTIFY | Windows Media Metafile file download request | off | off | off |
1 | 23197 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23198 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23199 | FILE-IDENTIFY | Windows Media Metafile file download request | off | off | off |
1 | 23200 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23201 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23202 | FILE-IDENTIFY | Windows Media Metafile file download request | off | off | off |
1 | 23203 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23204 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23205 | FILE-IDENTIFY | Windows Media Metafile file download request | off | off | off |
1 | 23206 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23207 | FILE-IDENTIFY | Windows Media Metafile file attachment detected | off | off | off |
1 | 23208 | PROTOCOL-VOIP | Digium Asterisk Manager Interface initial banner | off | off | off |
1 | 23347 | FILE-IDENTIFY | Lotus file download request | off | off | off |
1 | 23348 | FILE-IDENTIFY | Lotus file attachment detected | off | off | off |
1 | 23349 | FILE-IDENTIFY | Lotus file attachment detected | off | off | off |
1 | 23393 | SQL | IBM SolidDB initial banner | off | off | off |
1 | 23605 | FILE-IDENTIFY | Armadillo v1.xx - v2.xx file magic detected | off | off | off |
1 | 23637 | FILE-IDENTIFY | Java .class file attachment detected | off | off | off |
1 | 23638 | FILE-IDENTIFY | Java .class file attachment detected | off | off | off |
1 | 23639 | FILE-IDENTIFY | MPEG video stream file magic detected | off | off | off |
1 | 23640 | FILE-IDENTIFY | MPEG sys stream file magic detected | off | off | off |
1 | 23645 | FILE-IDENTIFY | RealNetworks Real Media file magic detected | off | off | off |
1 | 23647 | FILE-IDENTIFY | GIF file magic detected | off | off | off |
1 | 23648 | FILE-IDENTIFY | MP3 file magic detected | off | off | off |
1 | 23651 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 23652 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 23653 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 23654 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 23655 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 23656 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 23657 | FILE-IDENTIFY | JAR/ZIP file magic detected | off | off | off |
1 | 23658 | FILE-IDENTIFY | RIFX file magic detected | off | off | off |
1 | 23659 | FILE-IDENTIFY | RAR file magic detected | off | off | off |
1 | 23664 | FILE-IDENTIFY | PNG file magic detected | off | off | off |
1 | 23666 | FILE-IDENTIFY | MP3 file magic detected | off | off | off |
1 | 23667 | FILE-IDENTIFY | JPEG file magic detected | off | off | off |
1 | 23670 | FILE-IDENTIFY | RTF file magic detected | off | off | off |
1 | 23676 | FILE-IDENTIFY | Universal Binary/Java Bytecode file magic detected | off | off | off |
1 | 23677 | FILE-IDENTIFY | jarpack file magic detected | off | off | off |
1 | 23678 | FILE-IDENTIFY | PDF file magic detected | off | off | off |
1 | 23680 | FILE-IDENTIFY | Adobe Shockwave Flash file magic detected | off | off | off |
1 | 23681 | FILE-IDENTIFY | Adobe Shockwave Flash file magic detected | off | off | off |
1 | 23682 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23683 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23684 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23685 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23687 | FILE-IDENTIFY | Adobe Shockwave Flash file magic detected | off | off | off |
1 | 23691 | FILE-IDENTIFY | dmg file magic detected | off | off | off |
1 | 23695 | FILE-IDENTIFY | Flac file magic detected | off | off | off |
1 | 23696 | FILE-IDENTIFY | VideoLAN VLC file magic detected | off | off | off |
1 | 23697 | FILE-IDENTIFY | Microsoft Office Excel xlw file magic detected | off | off | off |
1 | 23698 | FILE-IDENTIFY | Microsoft Windows Media ASF file magic detected | off | off | off |
1 | 23701 | FILE-IDENTIFY | Microsoft SYmbolic LinK file magic detected | off | off | off |
1 | 23703 | FILE-IDENTIFY | Microsoft asf file magic detected | off | off | off |
1 | 23707 | FILE-IDENTIFY | Microsoft Compound File Binary v3 file magic detected | off | off | off |
1 | 23709 | FILE-IDENTIFY | Tiff little endian file magic detected | off | off | off |
1 | 23710 | FILE-IDENTIFY | Tiff big endian file magic detected | off | off | off |
1 | 23711 | FILE-IDENTIFY | OLE Document file magic detected | off | off | off |
1 | 23712 | FILE-IDENTIFY | Microsoft Office Excel file magic detected | off | off | off |
1 | 23714 | FILE-IDENTIFY | Microsoft Office Publisher file magic detected | off | off | off |
1 | 23720 | FILE-IDENTIFY | RealNetworks Realplayer REC file magic detected | off | off | off |
1 | 23721 | FILE-IDENTIFY | RealNetworks Realplayer .r1m file magic detected | off | off | off |
1 | 23723 | FILE-IDENTIFY | M3U file magic detected | off | off | off |
1 | 23724 | FILE-IDENTIFY | Adobe Director Movie file magic detected | off | off | off |
1 | 23725 | FILE-IDENTIFY | Portable Executable binary file magic detected | off | off | off |
1 | 23727 | FILE-IDENTIFY | Adobe Flash Video file magic detected | off | off | off |
1 | 23728 | FILE-IDENTIFY | matroska file magic detected | off | off | off |
1 | 23729 | FILE-IDENTIFY | PICT file magic detected | off | off | off |
1 | 23732 | FILE-IDENTIFY | Microsoft Media Player .asf file magic detected | off | off | off |
1 | 23735 | FILE-IDENTIFY | MIDI file magic detected | off | off | off |
1 | 23736 | FILE-IDENTIFY | PLS file magic detected | off | off | off |
1 | 23737 | FILE-IDENTIFY | SMIL file magic detected | off | off | off |
1 | 23738 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23739 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23740 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23741 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23742 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23743 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23744 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23745 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23746 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23747 | FILE-IDENTIFY | MOV file magic detected | off | off | off |
1 | 23748 | FILE-IDENTIFY | TTF file magic detected | off | off | off |
1 | 23749 | FILE-IDENTIFY | SAMI file magic detected | off | off | off |
1 | 23754 | FILE-IDENTIFY | AVI Video file magic detected | off | off | off |
1 | 23755 | FILE-IDENTIFY | Cisco Webex Player .wrf file magic detected | off | off | off |
1 | 23758 | FILE-IDENTIFY | XML file magic detected | off | off | off |
1 | 23759 | FILE-IDENTIFY | XML file magic detected | off | off | off |
1 | 23760 | FILE-IDENTIFY | WAV file magic detected | off | off | off |
1 | 23761 | FILE-IDENTIFY | AVI file magic detected | off | off | off |
1 | 23762 | FILE-IDENTIFY | PFA file magic detected | off | off | off |
1 | 23763 | FILE-IDENTIFY | HPJ file magic detected | off | off | off |
1 | 23764 | FILE-IDENTIFY | Adobe Download Manager aom file magic detected | off | off | off |
1 | 23765 | FILE-IDENTIFY | Apple Quicktime FLIC file magic detected | off | off | off |
1 | 23774 | FILE-IDENTIFY | NAB file magic detected | off | off | off |
1 | 23775 | FILE-IDENTIFY | Armadillo v1.71 packer file magic detected | off | off | off |
1 | 23777 | FILE-IDENTIFY | Armadillo v1.xx - v2.xx file magic detected | off | off | off |
1 | 23807 | FILE-IDENTIFY | JPEG2000 file download request | off | off | off |
1 | 23808 | FILE-IDENTIFY | JPEG2000 file attachment detected | off | off | off |
1 | 23809 | FILE-IDENTIFY | JPEG2000 file attachment detected | off | off | off |
1 | 23810 | FILE-IDENTIFY | JPEG2000 file download request | off | off | off |
1 | 23811 | FILE-IDENTIFY | JPEG2000 file attachment detected | off | off | off |
1 | 23812 | FILE-IDENTIFY | JPEG2000 file attachment detected | off | off | off |
1 | 23813 | FILE-IDENTIFY | JPEG2000 file download request | off | off | off |
1 | 23814 | FILE-IDENTIFY | JPEG2000 file attachment detected | off | off | off |
1 | 23815 | FILE-IDENTIFY | JPEG2000 file attachment detected | off | off | off |
1 | 23816 | FILE-IDENTIFY | JPEG2000 file download request | off | off | off |
1 | 23817 | FILE-IDENTIFY | JPEG2000 file attachment detected | off | off | off |
1 | 23818 | FILE-IDENTIFY | JPEG2000 file attachment detected | off | off | off |
1 | 23819 | FILE-IDENTIFY | JPEG2000 file download request | off | off | off |
1 | 23820 | FILE-IDENTIFY | JPEG2000 file attachment detected | off | off | off |
1 | 23821 | FILE-IDENTIFY | JPEG2000 file attachment detected | off | off | off |
1 | 23822 | FILE-IDENTIFY | JPEG2000 file magic detected | off | off | off |
1 | 23823 | FILE-IDENTIFY | JPEG2000 file magic detected | off | off | off |
1 | 24004 | FILE-OFFICE | Microsoft Office MSCOMCTL ActiveX control tabstrip method access | off | off | off |
1 | 24005 | FILE-OFFICE | Microsoft Office MSCOMCTL ActiveX control tabstrip method access | off | off | off |
1 | 24074 | FILE-IDENTIFY | MP3 file download request | off | off | off |
1 | 24075 | FILE-IDENTIFY | MP3 file attachment detected | off | off | off |
1 | 24076 | FILE-IDENTIFY | MP3 file attachment detected | off | off | off |
1 | 24078 | FILE-IDENTIFY | RMF file attachment detected | off | off | off |
1 | 24079 | FILE-IDENTIFY | RMF file attachment detected | off | off | off |
1 | 24080 | FILE-IDENTIFY | Microsoft Works file attachment detected | off | off | off |
1 | 24081 | FILE-IDENTIFY | Microsoft Works file attachment detected | off | off | off |
1 | 24138 | FILE-FLASH | Adobe Flash malformed RTMP response attempt | off | drop | drop |
1 | 24139 | FILE-FLASH | Adobe Flash malformed RTMP response attempt | off | drop | drop |
1 | 24140 | FILE-FLASH | Adobe Flash malformed RTMP response attempt | off | drop | drop |
1 | 24190 | FILE-IDENTIFY | X PixMap file magic detected | off | off | off |
1 | 24206 | FILE-IDENTIFY | LZH archive file magic detected | off | off | off |
1 | 24213 | FILE-IDENTIFY | MP4 file magic detected | off | off | off |
1 | 24218 | FILE-IDENTIFY | SMIL file magic detected | off | off | off |
1 | 24219 | FILE-IDENTIFY | SMIL file magic detected | off | off | off |
1 | 24263 | FILE-PDF | Overly large CreationDate within a pdf - likely malicious | off | off | off |
1 | 24303 | PROTOCOL-ICMP | IPv6 multicast neighbor add attempt | off | off | off |
1 | 24313 | SERVER-WEBAPP | HP OpenView Operations Agent request attempt | off | off | off |
1 | 24455 | FILE-IDENTIFY | JPEG file magic detected | off | off | off |
1 | 24456 | FILE-IDENTIFY | JPEG file magic detected | off | off | off |
1 | 24457 | FILE-IDENTIFY | JPEG file magic detected | off | off | off |
1 | 24458 | FILE-IDENTIFY | JPEG file magic detected | off | off | off |
1 | 24463 | FILE-IDENTIFY | TIFF file attachment detected | off | off | off |
1 | 24464 | FILE-IDENTIFY | TIFF file attachment detected | off | off | off |
1 | 24465 | FILE-IDENTIFY | Microsoft Windows Audio wmf file magic detected | off | off | off |
1 | 24472 | FILE-IDENTIFY | FLV file attachment detected | off | off | off |
1 | 24473 | FILE-IDENTIFY | FLV file attachment detected | off | off | off |
1 | 24483 | FILE-IDENTIFY | Embedded Open Type Font file magic detected | off | off | off |
1 | 24484 | FILE-IDENTIFY | Embedded Open Type Font file magic detected | off | off | off |
1 | 24708 | FILE-IDENTIFY | Netop Remote Control file download request | off | off | off |
1 | 24709 | FILE-IDENTIFY | Netop Remote Control file attachment detected | off | off | off |
1 | 24710 | FILE-IDENTIFY | Netop Remote Control file attachment detected | off | off | off |
1 | 24816 | FILE-IDENTIFY | MP4 file magic detected | off | off | off |
1 | 24817 | FILE-IDENTIFY | MP4 file magic detected | off | off | off |
1 | 24818 | FILE-IDENTIFY | M4V file magic detected | off | off | off |
1 | 24819 | FILE-IDENTIFY | M4V file magic detected | off | off | off |
1 | 24820 | FILE-IDENTIFY | Computer Graphics Metafile file download request | off | off | off |
1 | 24821 | FILE-IDENTIFY | Computer Graphics Metafile file attachment detected | off | off | off |
1 | 24822 | FILE-IDENTIFY | Computer Graphics Metafile file attachment detected | off | off | off |
1 | 24824 | FILE-IDENTIFY | RealPlayer skin file download request | off | off | off |
1 | 24825 | FILE-IDENTIFY | RealPlayer skin file attachment detected | off | off | off |
1 | 24826 | FILE-IDENTIFY | RealPlayer skin file attachment detected | off | off | off |
1 | 24869 | BROWSER-IE | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt | off | drop | drop |
1 | 24870 | BROWSER-IE | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt | off | drop | drop |
1 | 24871 | BROWSER-IE | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt | off | drop | drop |
1 | 24872 | BROWSER-IE | Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt | off | drop | drop |
1 | 24901 | FILE-IDENTIFY | JNLP file download request | off | off | off |
1 | 24902 | FILE-IDENTIFY | JNLP file attachment detected | off | off | off |
1 | 24903 | FILE-IDENTIFY | JNLP file attachment detected | off | off | off |
1 | 25032 | FILE-IDENTIFY | Microsoft Silverlight application file download request | off | off | off |
1 | 25033 | FILE-IDENTIFY | Microsoft Silverlight application file attachment detected | off | off | off |
1 | 25034 | FILE-IDENTIFY | Microsoft Silverlight application file attachment detected | off | off | off |
1 | 25062 | FILE-IDENTIFY | Microsoft Software Installer MSI binary file magic detected | off | off | off |
1 | 25305 | FILE-IDENTIFY | Adobe Audition Session file magic detected | off | off | off |
1 | 25306 | FILE-IDENTIFY | Adobe Audition Session file download request | off | off | off |
1 | 25307 | FILE-IDENTIFY | Adobe Audition Session file attachment detected | off | off | off |
1 | 25308 | FILE-IDENTIFY | Adobe Audition Session file attachment detected | off | off | off |
1 | 25513 | FILE-IDENTIFY | Portable Executable download detected | off | off | off |
1 | 25514 | FILE-IDENTIFY | Portable Executable download detected | off | off | off |
1 | 25515 | FILE-IDENTIFY | Portable Executable binary file magic detected | off | off | off |
1 | 25516 | FILE-IDENTIFY | Microsoft Software Installer MSI binary file magic detected | off | off | off |
1 | 25517 | FILE-IDENTIFY | Armadillo v1.71 packer file magic detected | off | off | off |
1 | 25680 | FILE-IDENTIFY | Adobe Flash Player embedded compact font detected | off | off | off |
1 | 25682 | FILE-IDENTIFY | Adobe Flash Player embedded compact font detected | off | off | off |
1 | 26057 | FILE-IDENTIFY | ZIP file download detected | off | off | off |
1 | 26058 | FILE-IDENTIFY | ZIP file attachment detected | off | off | off |
1 | 26251 | FILE-IDENTIFY | JPEG file magic detected | off | off | off |
1 | 26456 | FILE-IDENTIFY | Stream redirector file attachment detected | off | off | off |
1 | 26457 | FILE-IDENTIFY | Stream redirector file attachment detected | off | off | off |
1 | 26458 | FILE-IDENTIFY | Stream redirector file download request | off | off | off |
1 | 26465 | FILE-IDENTIFY | XUL file attachment detected | off | off | off |
1 | 26466 | FILE-IDENTIFY | XUL file attachment detected | off | off | off |
1 | 26492 | FILE-IDENTIFY | KingView KingMessage log file download request | off | off | off |
1 | 26493 | FILE-IDENTIFY | KingView KingMessage log file attachment detected | off | off | off |
1 | 26494 | FILE-IDENTIFY | KingView KingMessage log file attachment detected | off | off | off |
1 | 26879 | BROWSER-OTHER | local loopback address in html | off | off | off |
1 | 27121 | SERVER-OTHER | HP OpenView Storage Data Protector - initiate connection | off | off | off |
1 | 28425 | OS-WINDOWS | SMB Microsoft Windows Remote Administration Protocol usage attempt | off | off | off |
1 | 28629 | INDICATOR-OBFUSCATION | obfuscated script encoding detected | off | off | off |
1 | 28630 | INDICATOR-OBFUSCATION | obfuscated script encoding detected | off | off | off |
1 | 28894 | FILE-IDENTIFY | eSignal .ets file attachment detected | off | off | off |
1 | 28895 | FILE-IDENTIFY | eSignal .por file attachment detected | off | off | off |
1 | 28896 | FILE-IDENTIFY | eSignal .quo file attachment detected | off | off | off |
1 | 28897 | FILE-IDENTIFY | eSignal .sum file attachment detected | off | off | off |
1 | 28898 | FILE-IDENTIFY | eSignal .ets file attachment detected | off | off | off |
1 | 28899 | FILE-IDENTIFY | eSignal .por file attachment detected | off | off | off |
1 | 28900 | FILE-IDENTIFY | eSignal .sum file attachment detected | off | off | off |
1 | 28901 | FILE-IDENTIFY | eSignal .ets file download request | off | off | off |
1 | 29274 | FILE-IDENTIFY | XFDL file attachment detected | off | off | off |
1 | 29275 | FILE-IDENTIFY | XFDL file attachment detected | off | off | off |
1 | 29276 | FILE-IDENTIFY | XFDL file download request | off | off | off |
1 | 29384 | FILE-IDENTIFY | Adobe AIR file download request | off | off | off |
1 | 29385 | FILE-IDENTIFY | Adobe AIR file attachment detected | off | off | off |
1 | 29386 | FILE-IDENTIFY | Adobe AIR file attachment detected | off | off | off |
1 | 29405 | FILE-IDENTIFY | Microsoft Internet Shortcut file attachment detected | off | off | off |
1 | 29406 | FILE-IDENTIFY | Microsoft Internet Shortcut file attachment detected | off | off | off |
1 | 29407 | FILE-IDENTIFY | Microsoft Internet Shortcut file download request | off | off | off |
1 | 29439 | FILE-IDENTIFY | MSI file download request | off | off | off |
1 | 29514 | OS-WINDOWS | SMB Microsoft Windows Remote Administration Protocol usage attempt | off | off | off |
1 | 29612 | FILE-IDENTIFY | XPS file attachment detected | off | off | off |
1 | 29613 | FILE-IDENTIFY | XPS file attachment detected | off | off | off |
1 | 29614 | FILE-IDENTIFY | XPS file download request | off | off | off |
1 | 30014 | FILE-IDENTIFY | OS/2 Metafile file magic detected | off | off | off |
1 | 30015 | FILE-IDENTIFY | OS/2 Metafile file attachment detected | off | off | off |
1 | 30016 | FILE-IDENTIFY | OS/2 Metafile file attachment detected | off | off | off |
1 | 30017 | FILE-IDENTIFY | OS/2 Metafile file magic detected | off | off | off |
1 | 30018 | FILE-IDENTIFY | OS/2 Metafile file download request | off | off | off |
1 | 31702 | FILE-IDENTIFY | Microsoft Silverlight application file magic detected | off | off | off |
1 | 31703 | FILE-IDENTIFY | Microsoft Silverlight application file magic detected | off | off | off |
1 | 31773 | FILE-IDENTIFY | BitTorrent torrent file attachment detected | off | off | off |
1 | 31774 | FILE-IDENTIFY | BitTorrent torrent file attachment detected | off | off | off |
1 | 31775 | FILE-IDENTIFY | BitTorrent torrent file attachment detected | off | off | off |
1 | 31776 | FILE-IDENTIFY | BitTorrent torrent file attachment detected | off | off | off |
1 | 31871 | FILE-IDENTIFY | JPEG file magic detection | off | off | off |
1 | 32134 | FILE-IDENTIFY | XBM file attachment detected | off | off | off |
1 | 32135 | FILE-IDENTIFY | XBM file attachment detected | off | off | off |
1 | 32165 | FILE-IDENTIFY | SVG file magic detected | off | off | off |
1 | 32345 | SERVER-OTHER | HP OpenView Storage Data Protector - initiate connection | off | off | off |
1 | 32378 | FILE-IDENTIFY | bmp file attachment detected | off | off | off |
1 | 32380 | FILE-IDENTIFY | dib file attachment detected | off | off | off |
1 | 33026 | FILE-IDENTIFY | Publish-iT PUI file attachment detected | off | off | off |
1 | 33027 | FILE-IDENTIFY | Publish-iT PUI file attachment detected | off | off | off |
1 | 33028 | FILE-IDENTIFY | Publish-iT PUI file download request | off | off | off |