Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-06-02

This SRU number: 2016-06-02-001
Previous SRU number: 2016-05-31-001

Applies to:

This SEU number: 1491
Previous SEU: 1489

Applies to:

This is the complete list of rules added in SRU 2016-06-02-001 and SEU 1491.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
139112FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139113FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139114FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139115FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139116MALWARE-CNCWin.Trojan.DMALocker variant outbound connectionoffdropdrop
139117MALWARE-CNCWin.Trojan.Symmi variant outbound connection attemptoffdropdrop
339118SERVER-WEBAPPCisco Prime Network Analysis Module command injection attemptoffoffdrop
339119SERVER-WEBAPPCisco Prime Network Analysis Module command injection attemptoffoffdrop
339120SERVER-WEBAPPCisco Prime Network Analysis Module command injection attemptoffoffdrop
339121SERVER-WEBAPPCisco Prime Network Analysis Module command injection attemptoffoffdrop
339122SERVER-WEBAPPCisco Prime Network Analysis Module command injection attemptoffoffdrop
339123SERVER-WEBAPPCisco Prime Network Analysis Module command injection attemptoffoffdrop
339124SERVER-WEBAPPCisco Prime Network Analysis Module command injection attemptoffoffdrop
339125SERVER-WEBAPPCisco Prime Network Analysis Module command injection attemptoffoffdrop
339126SERVER-WEBAPPCisco Prime Network Analysis Module command injection attemptoffoffdrop
339127SERVER-WEBAPPCisco Prime Network Analysis Module command injection attemptoffoffdrop
139128EXPLOIT-KITNuclear landing page detectedoffoffdrop
139129EXPLOIT-KITNuclear gate redirect attemptoffoffdrop
139130EXPLOIT-KITObfuscated exploit download attemptoffoffdrop
139131FILE-PDFAdobe Acrobat Reader Acroform engine memory corruption attemptoffdropdrop
139132FILE-PDFAdobe Acrobat Reader Acroform engine memory corruption attemptoffdropdrop
139133SERVER-WEBAPPUbiquiti Networks XM Firmware scr.cgi command injection attemptoffoffoff
139134SERVER-WEBAPPUbiquiti Networks XM Firmware scr.cgi command injection attemptoffoffoff
139135SERVER-WEBAPPUbiquiti Networks XM Firmware scr.cgi directory traversal attemptoffoffoff
139136FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139137FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139138FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139139FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139140FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139141FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139142FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139143FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139144FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139145FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139146FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139147FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop

There are no modified rules in this release.