Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-07-21

This SRU number: 2016-07-21-001
Previous SRU number: 2016-07-18-001

Applies to:

This SEU number: 1518
Previous SEU: 1516

Applies to:

This is the complete list of rules added in SRU 2016-07-21-001 and SEU 1518.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
139677EXPLOIT-KITPseudo-Darkleech gate redirect attemptoffdropdrop
339678SERVER-WEBAPPCisco UCS Performance Manager command injection attemptoffoffdrop
339679SERVER-WEBAPPCisco UCS Performance Manager command injection attemptoffoffdrop
139680BROWSER-IEMicrosoft Internet Explorer VBScript toString redim array use after free attemptoffdropdrop
139681BROWSER-IEMicrosoft Internet Explorer VBScript toString redim array use after free attemptoffdropdrop
139682PUA-ADWAREWin.Adware.EoRezo outbound ad download attemptoffoffoff
339683FILE-IMAGETRUFFLEHUNTER TALOS-CAN-0186 attack attemptoffdropdrop
339684FILE-IMAGETRUFFLEHUNTER TALOS-CAN-0186 attack attemptoffdropdrop
139685MALWARE-CNCWin.Trojan.Tinba variant outbound connectionoffdropdrop
139686MALWARE-CNCWin.Trojan.Ursnif variant outbound connectionoffdropdrop
139687FILE-PDFAdobe Acrobat Reader malformed embeded TTF file memory corruption attemptoffdropdrop
139688FILE-PDFAdobe Acrobat Reader malformed embeded TTF file memory corruption attemptoffdropdrop
139689FILE-FLASHAdobe Flash Player ABRControlParameters access memory corruption attemptoffdropdrop
139690FILE-FLASHAdobe Flash Player ABRControlParameters access memory corruption attemptoffdropdrop
139691FILE-FLASHAdobe Flash Player ABRControlParameters access memory corruption attemptoffdropdrop
139692FILE-FLASHAdobe Flash Player ABRControlParameters access memory corruption attemptoffdropdrop
139693FILE-FLASHAdobe Flash Player ABRControlParameters access memory corruption attemptoffdropdrop
139694FILE-FLASHAdobe Flash Player ABRControlParameters access memory corruption attemptoffdropdrop
139695FILE-FLASHAdobe Flash Player ABRControlParameters access memory corruption attemptoffdropdrop
139696FILE-FLASHAdobe Flash Player ABRControlParameters access memory corruption attemptoffdropdrop
139697FILE-FLASHAdobe Flash Player ABRControlParameters access memory corruption attemptoffdropdrop
139698FILE-FLASHAdobe Flash Player ABRControlParameters access memory corruption attemptoffdropdrop
139699FILE-PDFAdobe Acrobat Reader malformed embeded TTF file memory corruption attemptoffdropdrop
139700FILE-PDFAdobe Acrobat Reader malformed embeded TTF file memory corruption attemptoffdropdrop
139701FILE-FLASHAdobe Flash Player MediaPlayerItemLoader out of bounds memory access attemptoffdropdrop
139702FILE-FLASHAdobe Flash Player MediaPlayerItemLoader out of bounds memory access attemptoffdropdrop
139703FILE-PDFAdobe Flash Player ActionScript setFocus use after free attemptoffdropdrop
139704FILE-PDFAdobe Flash Player ActionScript setFocus use after free attemptoffdropdrop
139705MALWARE-CNCWin.Trojan.Zeus variant inbound connection attemptoffdropdrop
139706BROWSER-OTHERNovell Messenger Client folder name buffer overflow attemptoffoffoff
139707BROWSER-OTHERNovell Messenger Client folder name buffer overflow attemptoffoffoff
139708BROWSER-OTHERNovell Messenger Client folder name buffer overflow attemptoffoffoff
139709BROWSER-OTHERNovell Messenger Client folder name buffer overflow attemptoffoffoff
139710BLACKLISTUser-Agent known malicious user-agent string mozilla/2.0offdropdrop
139711FILE-FLASHAdobe Flash Player PrintJobOptions use-after-free attemptoffdropdrop
139712FILE-FLASHAdobe Flash Player PrintJobOptions use-after-free attemptoffdropdrop

Updated Rules:

Updated rules can be found at this link.