Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-02-04

This SRU number: 2016-02-04-001
Previous SRU number: 2016-02-01-001

Applies to:

This SEU number: 1418
Previous SEU: 1416

Applies to:

This is the complete list of rules added in SRU 2016-02-04-001 and SEU 1418.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
137528EXPLOIT-KITNuclear exploit kit outbound uri request attemptoffdropdrop
137529EXPLOIT-KITNuclear exploit kit iframe injection attemptoffdropdrop
137534MALWARE-CNCWin.Trojan.Sality variant outbound connectionoffdropdrop
137535MALWARE-CNCWin.Trojan.Derusbi outbound connectionoffoffdrop
137536MALWARE-CNCWin.Trojan.Derusbi outbound connectionoffoffdrop
137537BROWSER-PLUGINSSiemens Solid Edge SEListCtrlX ActiveX clsid access attemptoffoffdrop
137538BROWSER-PLUGINSSiemens Solid Edge SEListCtrlX ActiveX clsid access attemptoffoffdrop
137539BROWSER-PLUGINSSiemens Solid Edge WebPartHelper ActiveX clsid access attemptoffoffdrop
137540BROWSER-PLUGINSSiemens Solid Edge WebPartHelper ActiveX clsid access attemptoffoffdrop
137541BROWSER-PLUGINSSiemens Solid Edge SEListCtrlX ActiveX clsid access attemptoffoffdrop
137542BROWSER-PLUGINSSiemens Solid Edge SEListCtrlX ActiveX clsid access attemptoffoffdrop
137543BROWSER-PLUGINSSiemens Solid Edge WebPartHelper ActiveX clsid access attemptoffoffdrop
137544BROWSER-PLUGINSSiemens Solid Edge WebPartHelper ActiveX clsid access attemptoffoffdrop
137545POLICY-OTHERNetcore/Netis firmware hard-coded backdoor account access attemptoffoffoff
137547SERVER-WEBAPPeClinicalWorks portalUserService.jsp SQL injection attemptoffoffdrop
137548EXPLOIT-KITMalicious iFrame redirection injection attemptoffdropdrop
137549EXPLOIT-KITMalicious iFrame injection outbound URI request attemptoffoffdrop
137550EXPLOIT-KITNuclear landing page detectedoffdropdrop
137551EXPLOIT-KITNuclear landing page detectedoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
137530FILE-PDFAdobe Acrobat Reader pdfshell preview mode - possible denial of service attemptoffdropdrop
137531FILE-PDFAdobe Acrobat Reader pdfshell preview mode - possible denial of service attemptoffdropdrop
137532FILE-PDFAdobe Acrobat Reader pdfshell preview mode - possible denial of service attemptoffdropdrop
137533FILE-PDFAdobe Acrobat Reader pdfshell preview mode - possible denial of service attemptoffdropdrop
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
137546SERVER-OTHERVeritas NetBackup Volume Manager connection attemptoffoffoff

Updated Rules:

Updated rules can be found at this link.