Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-03-23

This SRU number: 2016-03-23-001
Previous SRU number: 2016-03-21-001

Applies to:

This SEU number: 1454
Previous SEU: 1453

Applies to:

This is the complete list of rules added in SRU 2016-03-23-001 and SEU 1454.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
137934PROTOCOL-FTPComputer Associates eTrust Secure Content Manager LIST stack overflow attemptoffoffoff
338289FILE-PDFTRUFFLEHUNTER TALOS-CAN-0098 attack attemptoffoffoff
338290FILE-PDFTRUFFLEHUNTER TALOS-CAN-0098 attack attemptoffoffoff
338293FILE-OTHERTRUFFLEHUNTER TALOS-CAN-0094 attack attemptoffoffoff
338294FILE-OTHERTRUFFLEHUNTER TALOS-CAN-0094 attack attemptoffoffoff
338295FILE-OTHERTRUFFLEHUNTER TALOS-CAN-0094 attack attemptoffoffoff
338296FILE-OTHERTRUFFLEHUNTER TALOS-CAN-0094 attack attemptoffoffoff
138297BLACKLISTDNS request for known malware domain agent.wizztrakys.com - SpywareJarloffdropdrop
138298BLACKLISTDNS request for known malware domain dl.auhazard.com - SpywareJarloffdropdrop
138299BLACKLISTDNS request for known malware domain dl.wizzuniquify.com - SpywareJarloffdropdrop
138300BLACKLISTDNS request for known malware domain wizzmonetize-factory-windows.wizzdevs.com - SpywareJarloffdropdrop
138301BLACKLISTDNS request for known malware domain www.csdimonetize.com - SpywareJarloffdropdrop
138303SERVER-WEBAPPBonita BPM themeResource directory traversal attemptoffoffdrop
138304BLACKLISTUser-Agent known malicious user-agent string - JexBossoffdropdrop
138305EXPLOIT-KITAngler Gate redirect attemptoffdropdrop
138308BROWSER-IEMicrosoft Internet Explorer VBScript engine use after free attemptoffdropdrop
138309BROWSER-IEMicrosoft Internet Explorer VBScript engine use after free attemptoffdropdrop
138310FILE-FLASHAdobe Flash Player integer underflow attemptoffdropdrop
138311FILE-FLASHAdobe Flash Player integer underflow attemptoffdropdrop
138312SERVER-OTHERRedis lua script integer overflow attemptoffdropdrop
138313SERVER-OTHERRedis lua script integer overflow attemptoffdropdrop
138314SERVER-WEBAPPBorland AccuRev Reprise License Server directory traversal attemptoffoffoff
138315SERVER-WEBAPPBorland AccuRev Reprise License Server directory traversal attemptoffoffoff
138316SERVER-WEBAPPBorland AccuRev Reprise License Server directory traversal attemptoffoffoff
138317FILE-OTHERMicrosoft Edge Chakra JavaScript engine out of bounds read attemptoffdropdrop
138318FILE-OTHERMicrosoft Edge Chakra JavaScript engine out of bounds read attemptoffdropdrop
338323FILE-OTHERTRUFFLEHUNTER TALOS-CAN-0093 attack attemptoffoffoff
338324FILE-OTHERTRUFFLEHUNTER TALOS-CAN-0093 attack attemptoffoffoff
338325FILE-OTHERTRUFFLEHUNTER TALOS-CAN-0093 attack attemptoffoffoff
338326FILE-OTHERTRUFFLEHUNTER TALOS-CAN-0093 attack attemptoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
338302SERVER-OTHERCisco IOS DHCPv6 relay denial of service attemptoffoffoff
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
138291FILE-IDENTIFYUDF file magic detectedoffoffoff
138292FILE-IDENTIFYUDF file magic detectedoffoffoff
138306FILE-IDENTIFYDMG com.apple.decmpfs file magic detectedoffoffoff
138307FILE-IDENTIFYDMG com.apple.decmpfs file magic detectedoffoffoff
138319NETBIOSSMB winreg named pipe creation attemptoffoffoff
138320NETBIOSSMB srvsvc named pipe creation attemptoffoffoff
138321NETBIOSSMB svcctl named pipe creation attemptoffoffoff
138322NETBIOSSMB samr named pipe creation attemptoffoffoff
138327MALWARE-BACKDOORReGeorg proxy read attemptoffdropdrop
138328MALWARE-BACKDOORReGeorg socks proxy connection attemptoffdropdrop
138329MALWARE-BACKDOORReGeorg socks proxy initial connection attemptoffdropdrop

Updated Rules:

Updated rules can be found at this link.