Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2015-09-01

This SRU number: 2015-08-31-001
Previous SRU number: 2015-08-27-001

Applies to:

This SEU number: 1343
Previous SEU: 1341

Applies to:

This is the complete list of rules added in SRU 2015-08-31-001 and SEU 1343.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
135826FILE-OTHERTAR archive with absolute path detectedoffoffoff
135827FILE-OTHERTAR archive with absolute path detectedoffoffoff
135836BROWSER-IEMicrosoft Internet Explorer CLabelElement object use after free attemptoffdropdrop
135837BROWSER-IEMicrosoft Internet Explorer CLabelElement object use after free attemptoffdropdrop
135838BLACKLISTDNS request for known malware domain drop-into.hol.es - Win.Trojan.Namospuoffdropdrop
135839BLACKLISTDNS request for known malware domain exonapps.nl - Win.Trojan.Namospuoffdropdrop
135840BLACKLISTDNS request for known malware domain vbooter.tk - Win.Trojan.Namospuoffdropdrop
135841BLACKLISTDNS request for known malware domain xenbooter.tk - Win.Trojan.Namospuoffdropdrop
135842MALWARE-CNCWin.Trojan.Namospu variant outbound connectionoffdropdrop
135843SERVER-WEBAPPOracle Endeca Server MoveFile method directory traversal attemptoffoffdrop
135844SERVER-WEBAPPOracle Endeca Server MoveFile method directory traversal attemptoffoffdrop
135845EXPLOIT-KITNuclear exploit kit landing page detectedoffdropdrop
135846SERVER-WEBAPPNavis DocumentCloud WordPress plugin window.php cross site scripting attemptoffoffoff
135847SERVER-WEBAPPOracle Endeca server CopyFile method directory traversal attemptoffoffdrop
135848FILE-IMAGEMicrosoft Windows Bitmap width integer overflow attemptoffoffoff
135849POLICY-OTHEREMC Documentum Content Server remote access attemptoffoffoff
135850SERVER-OTHEREMC Documentum Content Server privilege escalation attemptoffdropdrop
135851SERVER-OTHERQEMU VNC set-pixel-format memory corruption attemptoffoffoff

Updated Rules:

Updated rules can be found at this link.