Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-02-18

This SRU number: 2016-02-18-003
Previous SRU number: 2016-02-15-001

Applies to:

This SEU number: 1428
Previous SEU: 1425

Applies to:

This is the complete list of rules added in SRU 2016-02-18-003 and SEU 1428.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
137688FILE-FLASHAdobe Flash Player remote code execution attemptoffoffdrop
137689FILE-FLASHAdobe Flash Player remote code execution attemptoffoffdrop
137690FILE-FLASHAdobe Flash Player invalid object reference code execution attemptoffoffoff
137691FILE-OFFICEMicrosoft Office Outlook SMB attach by reference code execution attemptoffoffdrop
137692FILE-OFFICEMicrosoft Office Outlook SMB attach by reference code execution attemptoffoffdrop
137693FILE-OFFICEMicrosoft Office Outlook AttachMethods local file execution attemptoffoffdrop
137694FILE-OFFICEMicrosoft Office Outlook AttachMethods local file execution attemptoffoffdrop
137695FILE-OFFICEMicrosoft Office Outlook SMB attach by reference code execution attemptoffoffdrop
137696FILE-OFFICEMicrosoft Office Outlook SMB attach by reference code execution attemptoffoffdrop
137697FILE-OFFICEMicrosoft Office Outlook AttachMethods local file execution attemptoffoffoff
137698FILE-OFFICEMicrosoft Office Outlook AttachMethods local file execution attemptoffoffoff
137699FILE-OFFICEMicrosoft Office Outlook SMB attach by reference code execution attemptoffoffdrop
137700FILE-OFFICEMicrosoft Office ole object external file loading attemptoffdropdrop
137701FILE-OFFICEMicrosoft Office ole object external file loading attemptoffdropdrop
137702FILE-OFFICEMicrosoft Office ole object external file loading attemptoffdropdrop
137703FILE-OFFICEMicrosoft Office ole object external file loading attemptoffdropdrop
137704FILE-OFFICEMicrosoft Office ole object external file loading attemptoffdropdrop
137705FILE-OFFICEMicrosoft Office ole object external file loading attemptoffdropdrop
137706FILE-OFFICEMicrosoft Office ole object external file loading attemptoffdropdrop
137707FILE-OFFICEMicrosoft Office ole object external file loading attemptoffdropdrop
137708FILE-FLASHAdobe Flash copyPixelsToByteArray integer overflow attemptdropdropdrop
137709FILE-FLASHAdobe Flash copyPixelsToByteArray integer overflow attemptdropdropdrop
137710FILE-FLASHAdobe Flash copyPixelsToByteArray integer overflow attemptdropdropdrop
137711FILE-FLASHAdobe Flash copyPixelsToByteArray integer overflow attemptdropdropdrop
137712FILE-PDFAdobe Acrobat and Adobe Acrobat Reader U3D RHAdobeMeta buffer overflow attemptoffoffoff
137713BROWSER-PLUGINSUnitronics VisiLogic TeeChart Pro ActiveX clsid access attemptoffoffoff
137714BROWSER-PLUGINSUnitronics VisiLogic TeeChart Pro ActiveX clsid access attemptoffoffoff
137715BROWSER-IEMicrosoft Internet Explorer onscroll DOS attemptoffoffoff
137716BROWSER-IEMicrosoft Internet Explorer onscroll DOS attemptoffoffoff
137717MALWARE-CNCWin.Trojan.Teslacrypt outbound POST attemptoffdropdrop
137718MALWARE-CNCWin.Trojan.Teslacrypt outbound POST attemptoffdropdrop
137719MALWARE-CNCWin.Trojan.Teslacrypt outbound POST attemptoffdropdrop
137720FILE-FLASHAdobe Flash Player atomicCompareAndSwapLength integer overflow attemptoffoffdrop
137721FILE-FLASHAdobe Flash Player atomicCompareAndSwapLength integer overflow attemptoffoffdrop
137722FILE-FLASHAdobe Flash Player atomicCompareAndSwapLength integer overflow attemptoffdropdrop
137723FILE-FLASHAdobe Flash Player atomicCompareAndSwapLength integer overflow attemptoffdropdrop
137724BROWSER-IEMicrosoft Internet Explorer form selection reset attemptoffoffoff
137725SERVER-OTHERCA message queuing server buffer overflow attemptoffoffoff
137726FILE-OTHERMicrosoft Office ole object external file loading attemptoffdropdrop
137727FILE-OTHERMicrosoft Office ole object external file loading attemptoffdropdrop
137728INDICATOR-OBFUSCATIONSWF with large binary bloboffoffoff
137729INDICATOR-OBFUSCATIONAdobe Flash file with SecureSwfLoader packer detectedoffoffoff
137730PROTOCOL-DNSglibc getaddrinfo A record stack buffer overflow attemptoffoffdrop
137731PROTOCOL-DNSglibc getaddrinfo AAAA record stack buffer overflow attemptoffoffdrop
137733MALWARE-CNCWin.Trojan.Dridex dropper variant outbound connectionoffdropdrop
137734FILE-FLASHAdobe Flash Player Point object integer overflow attemptoffdropdrop
137735FILE-FLASHAdobe Flash Player Point object integer overflow attemptoffdropdrop
137736FILE-FLASHAdobe Flash Player Point object integer overflow attemptoffdropdrop
137737FILE-FLASHAdobe Flash Player Point object integer overflow attemptoffdropdrop
137738FILE-FLASHAdobe Flash Player BlurFilter memory corruption attemptoffdropdrop
137739FILE-FLASHAdobe Flash Player BlurFilter memory corruption attemptoffdropdrop
137740FILE-FLASHAdobe Flash Player BlurFilter memory corruption attemptoffdropdrop
137741FILE-FLASHAdobe Flash Player BlurFilter memory corruption attemptoffdropdrop
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
137732POLICY-OTHEReicar test string download attemptoffoffoff

Updated Rules:

Updated rules can be found at this link.