Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-08-02

This SRU number: 2016-08-01-001
Previous SRU number: 2016-07-27-001

Applies to:

This SEU number: 1521
Previous SEU: 1520

Applies to:

This is the complete list of rules modified in SRU 2016-08-01-001 and SEU 1521.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
122048MALWARE-CNCWin.Trojan.Zeus P2P outbound connectionoffalertdrop
123492MALWARE-CNCWin.Trojan.ZeroAccess outbound connectionoffdropdrop
123493MALWARE-CNCWin.Trojan.ZeroAccess outbound connectiondropdropdrop
123606MALWARE-CNCWin.Trojan.Sofacy.A outbound connectionoffoffdrop
123607MALWARE-CNCWin.Trojan.Sofacy.A outbound connectionoffoffdrop
123780MALWARE-CNCWin.Trojan.Begfanit.A outbound connectionoffoffoff
124224MALWARE-CNCWin.Trojan.Spy variant outbound connectionoffdropdrop
124341MALWARE-CNCWin.Trojan.Spy variant outbound connectionoffoffoff
124349MALWARE-CNCWin.Trojan.Spy variant outbound connectionoffoffoff
124350MALWARE-CNCWin.Trojan.Spy variant outbound connectionoffoffoff
124381MALWARE-CNCWin.Trojan.VB variant outbound connectionoffdropdrop
124382MALWARE-CNCWin.Trojan.VB variant outbound connectionoffdropdrop
124383MALWARE-CNCWin.Trojan.Dipwit outbound connectionoffoffdrop
124384MALWARE-CNCWin.Trojan.Tracur variant outbound connectionoffoffdrop
124385MALWARE-CNCWin.Trojan.Tracur variant outbound connectionoffoffdrop
125627MALWARE-CNCWin.Trojan.Reventon variant outbound connectionoffdropdrop
125807MALWARE-CNCWin.Trojan.Urausy Botnet variant outbound connectionoffdropdrop
126911MALWARE-CNCWin.Trojan.Rombrast Trojan outbound connectionoffdropdrop
126912MALWARE-CNCWin.Trojan.Rombrast Trojan outbound connectionoffdropdrop
127022MALWARE-CNCWin.Trojan.Netweird.A outbound connectionoffoffoff
127023MALWARE-CNCWin.Trojan.Netweird.A outbound connectionoffoffdrop
127150BROWSER-IEMicrosoft Internet Explorer use after free attemptoffdropdrop
127152BROWSER-IEMicrosoft Internet Explorer use after free attemptoffdropdrop
127201MALWARE-CNCWin.Trojan.Neurevt variant outbound connectionoffdropdrop
127545MALWARE-CNCOsx.Trojan.Janicab outbound connectionoffdropdrop
127546MALWARE-CNCOsx.Trojan.Janicab outbound connectionoffdropdrop
127547MALWARE-CNCOsx.Trojan.Janicab outbound connectionoffdropdrop
127867MALWARE-CNCWin.Trojan.Dropper outbound connectiondropdropdrop
128072MALWARE-CNCWin.Trojan.Omexo outbound connectionoffdropdrop
128096MALWARE-CNCWin.Trojan.Spynet variant connectionoffoffdrop
128141MALWARE-CNCWin.Trojan.banker outbound connectionoffdropdrop
128143MALWARE-CNCWin.Trojan.Medfos outbound connectionoffdropdrop
128209MALWARE-CNCWin.Worm.IRCbot outbound connectionoffdropdrop
128210MALWARE-CNCWin.Worm.IRCbot outbound connectionoffdropdrop
128211MALWARE-CNCWin.Worm.IRCbot outbound connectionoffdropdrop
128234MALWARE-CNCWin.Trojan.Hdslogger outbound connectionoffdropdrop
128239MALWARE-CNCWin.Trojan.Tuxido outbound connectionoffdropdrop
128807MALWARE-CNCWin.Trojan.Injector variant outbound connectionoffdropdrop
128809MALWARE-CNCWin.Trojan.Dofoil inbound connectionoffdropdrop
129031MALWARE-CNCWin.Trojan.Banload variant inbound connectionoffdropdrop
129149MALWARE-CNCWin.Trojan.Janicab outbound connectionoffdropdrop
129155MALWARE-CNCWin.Trojan.Vwealer outbound connectionoffdropdrop
129289MALWARE-CNCWin.Trojan.Kmnokay outbound connectionoffdropdrop
129302MALWARE-CNCWin.Trojan.Diswenshow outbound connectionoffdropdrop
129307MALWARE-CNCWin.Trojan.Fraxytime outbound connectionoffdropdrop
129325MALWARE-CNCWin.Trojan.Horsamaz outbound connectionoffdropdrop
129331MALWARE-CNCWin.Trojan.Aokaspid outbound connection using modemoffdropdrop
129332MALWARE-CNCWin.Trojan.Aokaspid outbound connection using lanoffdropdrop
129333MALWARE-CNCWin.Trojan.Aokaspid outbound connection using proxy serveroffdropdrop
129334MALWARE-CNCWin.Trojan.Aokaspid outbound connection using otheroffdropdrop
129340MALWARE-CNCWin.Trojan.Plusau outbound connectionoffdropdrop
129353MALWARE-CNCWin.Trojan.Zeagle outbound connectionoffdropdrop
129440MALWARE-CNCWin.Trojan.Chewbacca outbound connectionoffdropdrop
129615MALWARE-CNCWin.Trojan.Keylogger outbound connectionoffdropdrop
129616MALWARE-CNCWin.Trojan.Keylogger inbound connectionoffdropdrop
129644MALWARE-CNCWin.Trojan.Sdconsent outbound connectionoffdropdrop
129670MALWARE-CNCWin.Trojan.Caphaw outbound connectionoffdropdrop
129924MALWARE-CNCWin.Trojan.Farfli outbound connectionoffdropdrop
129980MALWARE-CNCWin.Trojan.Fucom outbound connectionoffdropdrop
130063MALWARE-CNCWin.Trojan.Zbot outbound connectionoffdropdrop
130064MALWARE-CNCWin.Trojan.Zbot outbound connectionoffdropdrop
130334MALWARE-CNCWin.Trojan.ProjectHook initial outbound connectionoffdropdrop
130482MALWARE-CNCWin.Trojan.Zbot/Bublik inbound connectionoffdropdrop
130551MALWARE-CNCMalicious BitCoiner Miner download - Win.Trojan.Minerdoffdropdrop
130552MALWARE-CNCMalicious BitCoiner Miner download - Win.Trojan.Systemaoffdropdrop
130752MALWARE-CNCWin.Trojan.Tesyong outbound connectionoffdropdrop
130804MALWARE-CNCWin.Trojan.Hulpob outbound connectionoffdropdrop
130805MALWARE-CNCWin.Trojan.Hulpob outbound connectionoffdropdrop
130806MALWARE-CNCWin.Trojan.Hulpob outbound connectionoffdropdrop
130807MALWARE-CNCWin.Trojan.Hulpob outbound connectionoffdropdrop
130808MALWARE-CNCWin.Trojan.Hulpob outbound connectionoffdropdrop
130809MALWARE-CNCWin.Trojan.Hulpob outbound connectionoffdropdrop
130810MALWARE-CNCWin.Trojan.Hulpob outbound connectionoffdropdrop
130811MALWARE-CNCWin.Trojan.Hulpob outbound connectionoffdropdrop
130812MALWARE-CNCWin.Trojan.Hulpob outbound connectionoffdropdrop
130882MALWARE-CNCWin.Trojan.Rbrute inbound connectionoffdropdrop
130883MALWARE-CNCWin.Trojan.Rbrute inbound connectionoffdropdrop
130923MALWARE-CNCWin.Trojan.Sefnit outbound connectionoffdropdrop
130924MALWARE-CNCWin.Trojan.Hd backdoor inbound connectionoffoffdrop
130926MALWARE-CNCWin.Trojan.Hd backdoor outbound secure-connectionoffoffdrop
130978MALWARE-CNCWin.Trojan.Rbrute inbound connectionoffdropdrop
130984MALWARE-CNCWin.Trojan.Vonriamt outbound connectionoffdropdrop
131014MALWARE-CNCWin.Trojan.Cryptowall variant outbound connectionoffdropdrop
131081MALWARE-CNCWin.Trojan.WinSpy variant outbound connectionoffdropdrop
131123MALWARE-CNCWin.Trojan.Gigade variant inbound connectionoffoffoff
131124MALWARE-CNCWin.Trojan.Pyrtomsop outbound connectionoffdropdrop
131136MALWARE-CNCWin.Trojan.ZeroAccess inbound connectiondropdropdrop
131168MALWARE-CNCWin.Trojan.Guise outbound connectionoffdropdrop
131224MALWARE-CNCWin.Trojan.Cryptor outbound connectionoffdropdrop
131236MALWARE-CNCWin.Trojan.Hidead outbound connectionoffdropdrop
131290MALWARE-CNCWin.Trojan.Vextstl outbound connectionoffdropdrop
131293MALWARE-CNCWin.Trojan.Dyre publickey outbound connectionoffoffdrop
131319MALWARE-CNCWin.Trojan.Zediv outbound connectionoffdropdrop
131459MALWARE-CNCWin.Trojan.Jaktinier outbound connectionoffdropdrop
131548MALWARE-CNCWin.Trojan.Yakes variant inbound connectionoffoffdrop
131693MALWARE-CNCWin.Trojan.Korplug Poisoned Hurricane Malware outbound connectionoffdropdrop
131706MALWARE-CNCWin.Trojan.Korgapam outbound connectionoffdropdrop
131718MALWARE-CNCWin.Trojan.Critroni outbound connectionoffdropdrop
131744MALWARE-CNCWin.Trojan.Eratoma outbound connectionoffdropdrop
131748MALWARE-CNCWin.Trojan.Qulkonwi outbound connectionoffdropdrop
131753MALWARE-CNCWin.Trojan.Elpapok outbound connectionoffdropdrop
131768MALWARE-CNCWin.Trojan.Ecsudown outbound connectionoffdropdrop
131813MALWARE-CNCWin.Trojan.Expiro outbound connectionoffdropdrop
131832MALWARE-CNCWin.Trojan.Pfinet outbound connectionoffdropdrop
131833MALWARE-CNCWin.Trojan.Chkbot outbound connectionoffdropdrop
131883MALWARE-CNCWin.Trojan.Waterspout outbound connectionoffdropdrop
131925MALWARE-CNCLinux.Trojan.Jynxkit outbound connectionoffdropdrop
131944MALWARE-CNCWin.Trojan.Tavdig outbound connectionoffdropdrop
132065MALWARE-CNCWin.Trojan.Asprox inbound connectionoffdropdrop
132126MALWARE-CNCWin.Trojan.Lizarbot outbound connectionoffdropdrop
132163BROWSER-IEMicrosoft Internet Explorer GetUpdatedLayout partial table declaration use-after-free attemptoffoffoff
132164BROWSER-IEMicrosoft Internet Explorer GetUpdatedLayout partial table declaration use-after-free attemptoffoffoff
132188MALWARE-CNCWin.Trojan.BlackEnergy3 outbound connectionoffdropdrop
132189MALWARE-CNCWin.Trojan.BlackEnergy2 outbound connectionoffdropdrop
132198MALWARE-CNCWin.Trojan.Mujormel outbound connectionoffdropdrop
132311MALWARE-CNCWin.Trojan.Rehtesyk outbound connectionoffdropdrop
132792MALWARE-CNCWin.Virus.Ransomlock inbound connectionoffdropdrop
132908MALWARE-CNCWin.Trojan.TinyZBot outbound connectionoffdropdrop
132909MALWARE-CNCWin.Trojan.TinyZBot outbound connectionoffdropdrop
132910MALWARE-CNCWin.Trojan.TinyZBot outbound connectionoffdropdrop
133145MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133165MALWARE-CNCWin.Trojan.Poweliks outbound connectionoffdropdrop
133646MALWARE-CNCLinux.Trojan.XORDDoS outbound connectionoffdropdrop
133647MALWARE-CNCLinux.Trojan.XORDDoS outbound connectionoffdropdrop
133648MALWARE-CNCLinux.Trojan.XORDDoS outbound connectionoffdropdrop
133650MALWARE-CNCWin.Trojan.Tinba outbound connectionoffdropdrop
133678MALWARE-CNCWin.Trojan.Athena variant outbound connectionoffdropdrop
133704MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133745MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133746MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133747MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133748MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133749MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133750MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133751MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133752MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133753MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133754MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133755MALWARE-CNCWin.Trojan.Dridex initial outbound connectionoffdropdrop
133756MALWARE-CNCWin.Ransomware.CTB-Locker outbound connectionoffdropdrop
133757MALWARE-CNCWin.Ransomware.CTB-Locker outbound connectionoffdropdrop
133859MALWARE-CNCWin.Trojan.Dridex3 initial outbound connectionoffdropdrop
133860MALWARE-CNCWin.Trojan.Dridex3 initial outbound connectionoffdropdrop
133861MALWARE-CNCWin.Trojan.Dridex3 initial outbound connectionoffdropdrop
133862MALWARE-CNCWin.Trojan.Dridex3 initial outbound connectionoffdropdrop
133863MALWARE-CNCWin.Trojan.Dridex3 initial outbound connectionoffdropdrop
133864MALWARE-CNCWin.Trojan.Dridex3 initial outbound connectionoffdropdrop
133865MALWARE-CNCWin.Trojan.Dridex3 initial outbound connectionoffdropdrop
133866MALWARE-CNCWin.Trojan.Dridex3 initial outbound connectionoffdropdrop
133867MALWARE-CNCWin.Trojan.Dridex3 initial outbound connectionoffdropdrop
133868MALWARE-CNCWin.Trojan.Dridex3 initial outbound connectionoffdropdrop
133880MALWARE-CNCWin.Backdoor.Casper outbound connectionoffdropdrop
133893MALWARE-CNCWin.Trojan.Xerq outbound connectionoffdropdrop
133931MALWARE-CNCWin.Worm.Goldrv variant outbound connectionoffdropdrop
133933MALWARE-CNCWin.Trojan.Penget variant outbound connectionoffdropdrop
133966MALWARE-CNCWin.Worm.Mafusc variant outbound connectionoffdropdrop
133996MALWARE-CNCWin.Trojan.Pwexes variant outbound connectionoffdropdrop
133997MALWARE-CNCWin.Trojan.Pwexes variant outbound connectionoffdropdrop
134001MALWARE-CNCWin.Trojan.Picommex outbound connectionoffdropdrop
134002MALWARE-CNCWin.Trojan.Picommex outbound connectionoffdropdrop
134003MALWARE-CNCWin.Trojan.Picommex outbound connectionoffdropdrop
134004MALWARE-CNCWin.Trojan.Explosive variant outbound connectionoffdropdrop
134005MALWARE-CNCWin.Trojan.Explosive variant outbound connectionoffdropdrop
134006MALWARE-CNCWin.Trojan.Explosive variant outbound connectionoffdropdrop
134007MALWARE-CNCWin.Trojan.Explosive variant outbound connectionoffdropdrop
134008MALWARE-CNCWin.Trojan.Explosive variant outbound connectionoffdropdrop
134009MALWARE-CNCWin.Trojan.Explosive variant outbound connectionoffdropdrop
134010MALWARE-CNCWin.Trojan.Explosive variant outbound connectionoffdropdrop
134011MALWARE-CNCWin.Trojan.Explosive variant outbound connectionoffdropdrop
134012MALWARE-CNCWin.Trojan.Explosive variant outbound connectionoffdropdrop
134013MALWARE-CNCWin.Trojan.Ayuther variant outbound connectionoffdropdrop
134025MALWARE-CNCWin.Trojan.Ayuther variant outbound connectionoffdropdrop
134026MALWARE-CNCWin.Trojan.Endstar variant outbound connectionoffdropdrop
134029MALWARE-CNCWin.Worm.Tuscas variant outbound connectionoffdropdrop
134030MALWARE-CNCWin.Trojan.Dridex4 initial outbound connectionoffdropdrop
134031MALWARE-CNCWin.Trojan.Dridex4 initial outbound connectionoffdropdrop
134032MALWARE-CNCWin.Trojan.Dridex4 initial outbound connectionoffdropdrop
134033MALWARE-CNCWin.Trojan.Dridex4 initial outbound connectionoffdropdrop
134034MALWARE-CNCWin.Trojan.Dridex4 initial outbound connectionoffdropdrop
134035MALWARE-CNCWin.Trojan.Dridex4 initial outbound connectionoffdropdrop
134036MALWARE-CNCWin.Trojan.Dridex4 initial outbound connectionoffdropdrop
134037MALWARE-CNCWin.Trojan.Dridex4 initial outbound connectionoffdropdrop
134038MALWARE-CNCWin.Trojan.Dridex4 initial outbound connectionoffdropdrop
134045MALWARE-CNCWin.Trojan.Eitenckay initial outbound connectionoffdropdrop
134049MALWARE-CNCWin.Backdoor.EvilBunny variant outbound connectionoffdropdrop
134050MALWARE-CNCWin.Backdoor.Nepigon variant outbound connectionoffdropdrop
134115MALWARE-CNCMacOS.Trojan.Wirelurker variant outbound connectionoffdropdrop
134116MALWARE-CNCMacOS.Trojan.Wirelurker variant outbound connectionoffdropdrop
134117MALWARE-CNCWin.Backdoor.Zupdax variant outbound connectionoffdropdrop
134128MALWARE-CNCWin.Trojan.WIntruder outbound connectionoffdropdrop
134132MALWARE-CNCWin.Backdoor.Erotimpact variant outbound connectionoffdropdrop
134140MALWARE-CNCWin.Trojan.Dyre publickey outbound connectionoffoffdrop
134155MALWARE-CNCMacOS.Backdoor.Xslcmd outbound connectionoffdropdrop
134219MALWARE-CNCWin.Trojan.Nanocore variant outbound connectionoffdropdrop
134246MALWARE-CNCWin.Backdoor.Yebot variant outbound connectionoffoffdrop
134261MALWARE-CNCLinux.Trojan.XORDDoS outbound connectionoffdropdrop
134262MALWARE-CNCLinux.Trojan.XORDDoS outbound connectionoffdropdrop
134263MALWARE-CNCLinux.Trojan.XORDDoS outbound connectionoffdropdrop
134286MALWARE-CNCWin.Trojan.Mudrop variant outbound connectionoffdropdrop
134296MALWARE-CNCWin.Trojan.Kraken outbound connectionoffdropdrop
134297MALWARE-CNCWin.Trojan.Kraken outbound connectionoffdropdrop
134319MALWARE-CNCWin.Worm.Klogwjds variant outbound connectionoffdropdrop
134322MALWARE-CNCWin.Worm.Klogwjds variant outbound connectionoffdropdrop
134327MALWARE-CNCWin.Trojan.Bedepshel variant outbound connectionoffdropdrop
134329MALWARE-CNCCryptolocker variant inbound connectionoffoffoff
134346MALWARE-CNCWin.Trojan.Backspace outbound connectionoffdropdrop
134347MALWARE-CNCWin.Trojan.Cheprobnk variant outbound connectionoffdropdrop
134362MALWARE-CNCWin.Trojan.Mantal variant outbound connectionoffdropdrop
134366MALWARE-CNCWin.Trojan.Mantal variant outbound connectionoffdropdrop
134459MALWARE-CNCWin.Trojan.Pvzin variant outbound connectionoffdropdrop
134460MALWARE-CNCWin.Worm.Mozibe variant outbound connectionoffdropdrop
134461MALWARE-CNCLinux.Trojan.Mumblehard variant outbound connectionoffdropdrop
134462MALWARE-CNCLinux.Trojan.Mumblehard variant outbound connectionoffdropdrop
134469MALWARE-CNCWin.Backdoor.Nirunte variant outbound connectionoffdropdrop
134470MALWARE-CNCWin.Backdoor.Nirunte variant outbound connectionoffdropdrop
134476MALWARE-CNCWin.Trojan.Kriptovor variant outbound connectionoffdropdrop
134489MALWARE-CNCWin.Trojan.Nalodew variant outbound connectionoffdropdrop
134491MALWARE-CNCWin.Trojan.MalPutty variant outbound connectionoffoffdrop
134567MALWARE-CNCMacOS.Trojan.MacVX outbound connectionoffdropdrop
134572MALWARE-CNCWin.Trojan.Zinnemls variant outbound connectionoffdropdrop
134608MALWARE-CNCWin.Trojan.Punkey variant outbound connectionoffdropdrop
134609MALWARE-CNCTrojan.NitLove variant outbound connectionoffdropdrop
134624MALWARE-CNCWin.Trojan.Crypaura variant outbound connectionoffdropdrop
134818MALWARE-CNCWin.Trojan.Emdivi outbound connectionoffdropdrop
134869MALWARE-CNCWin.Trojan.XTalker outbound connectionoffdropdrop
134872MALWARE-CNCWin.Trojan.Compfolder variant outbound connectionoffdropdrop
134965MALWARE-CNCWin.Trojan.Cryptolocker outbound connectionoffdropdrop
135031MALWARE-CNCWin.Trojan.Konus outbound connectionoffdropdrop
135050MALWARE-CNCWin.Trojan.Scar variant outbound connectionoffdropdrop
135127BROWSER-IEMicrosoft Internet Explorer local file information disclosure attemptoffoffoff
135128BROWSER-IEMicrosoft Internet Explorer local file information disclosure attemptoffoffoff
135254MALWARE-CNCWin.Dropper.Agent inbound connectionoffdropdrop
135312MALWARE-CNCWin.Trojan.Ursnif outbound connectionoffdropdrop
135386MALWARE-CNCWin.Trojan.Bedep initial outbound connectionoffdropdrop
135387MALWARE-CNCWin.Trojan.Andromeda initial outbound connectionoffdropdrop
135733MALWARE-CNCWin.Trojan.Potao outbound connectionoffdropdrop
135749MALWARE-CNCWin.Backdoor.IsSpace outbound connectionoffdropdrop
135750MALWARE-CNCWin.Backdoor.IsSpace initial outbound connectionoffdropdrop
135794MALWARE-CNCWin.Trojan.TeslaCrypt outbound connectionoffdropdrop
135967BROWSER-IEMicrosoft Edge sandbox CreateFileW arbitrary file delete attemptoffoffoff
135968BROWSER-IEMicrosoft Edge sandbox CreateFileW arbitrary file delete attemptoffoffoff
136054MALWARE-CNCIos.Backdoor.SYNful inbound connectionoffdropdrop
136106MALWARE-CNCWin.Trojan.Hodoor APT variant outbound connectionoffdropdrop
136294MALWARE-CNCWin.Backdoor.Nisinul variant outbound connectionoffdropdrop
136471MALWARE-CNCAndr.Trojan.Kemoge outbound connectionoffdropdrop
136522MALWARE-CNCWin.Trojan.Banker.NWT variant outbound connectionoffdropdrop
136639MALWARE-CNCWin.Trojan.Tavex outbound connectionoffdropdrop
136732MALWARE-CNCWin.Trojan.Sefnit variant outbound connectionoffdropdrop
136765MALWARE-CNCWin.Trojan.Stupeval variant outbound connectionoffdropdrop
136807MALWARE-CNCWin.Trojan.Nodslit variant outbound connectionoffdropdrop
137036MALWARE-CNCWin.Trojan.Alina variant outbound connectionoffdropdrop
137047MALWARE-CNCWin.Trojan.Vonterra outbound connectionoffdropdrop
137052MALWARE-CNCATSEngine credit card number sent via URL parameteroffdropdrop
137212MALWARE-CNCWin.Trojan.Pmabot outbound connectionoffdropdrop
137213MALWARE-CNCWin.Trojan.Pmabot outbound connectionoffdropdrop
137214MALWARE-CNCWin.Trojan.Pmabot outbound connectionoffdropdrop
137215MALWARE-CNCWin.Trojan.Pmabot outbound connectionoffdropdrop
137225MALWARE-CNCWin.Trojan.Isniffer outbound connectionoffdropdrop
137226MALWARE-CNCWin.Trojan.Isniffer outbound connectionoffdropdrop
137227MALWARE-CNCWin.Trojan.Isniffer outbound connectionoffdropdrop
137228MALWARE-CNCWin.Trojan.Isniffer outbound connectionoffdropdrop
137296MALWARE-CNCWin.Trojan.Sesramot variant outbound connectionoffdropdrop
137297MALWARE-CNCWin.Trojan.Sesramot variant outbound connectionoffdropdrop
137317MALWARE-CNCWin.Trojan.Radamant inbound connectionoffdropdrop
137323MALWARE-CNCWin.Trojan.Direvex variant outbound connectionoffdropdrop
137457MALWARE-CNCWin.Trojan.Sovfo variant outbound connectionoffdropdrop
137636MALWARE-CNCWin.Trojan.Graftor outbound connectionoffdropdrop
137637MALWARE-CNCWin.Trojan.Graftor outbound connectionoffdropdrop
138018MALWARE-CNCWin.Trojan.Dridex outbound connectionoffdropdrop
138067BROWSER-IEMicrosoft Internet Explorer CTreePos type confusion attemptoffdropdrop
138068BROWSER-IEMicrosoft Internet Explorer CTreePos type confusion attemptoffdropdrop
138069BROWSER-IEMicrosoft Internet Explorer CTreePos type confusion attemptoffdropdrop
138070BROWSER-IEMicrosoft Internet Explorer CTreePos type confusion attemptoffdropdrop
138116MALWARE-CNCOsx.Trojan.Keranger outbound connectionoffdropdrop
138255MALWARE-CNCWin-Linux.Trojan.Derusbi variant outbound connectionoffdropdrop
138256MALWARE-CNCWin-Linux.Trojan.Derusbi variant outbound connectionoffdropdrop
138257MALWARE-CNCWin-Linux.Trojan.Derusbi variant outbound connectionoffdropdrop
138258MALWARE-CNCWin-Linux.Trojan.Derusbi variant outbound connectionoffdropdrop
138514MALWARE-CNCWin.Trojan.Sweeper outbound connectionoffdropdrop
138515MALWARE-CNCWin.Trojan.Sweeper outbound connectionoffdropdrop
138516MALWARE-CNCWin.Trojan.Sweeper outbound connectionoffdropdrop
138557MALWARE-CNCWin.Trojan.GateKeylogger outbound connectionoffdropdrop
138585MALWARE-CNCWin.Backdoor.DFSCook variant outbound connectionoffdropdrop
138586MALWARE-CNCWin.Backdoor.DFSCook variant outbound connectionoffdropdrop
138588MALWARE-CNCWin.Backdoor.DFSCook variant outbound connectionoffdropdrop
138607MALWARE-CNCWin.Trojan.Qakbot variant outbound connectionoffdropdrop
138643MALWARE-CNCWin.Trojan.Jadowndec outbound connectionoffdropdrop
138644MALWARE-CNCWin.Trojan.Jadowndec outbound connectionoffdropdrop
138645MALWARE-CNCWin.Trojan.Jadowndec outbound connectionoffdropdrop
138646MALWARE-CNCWin.Trojan.Jadowndec outbound connectionoffdropdrop
138647MALWARE-CNCWin.Trojan.Jadowndec outbound connectionoffdropdrop
138886MALWARE-CNCWin.Trojan.Bayrob variant outbound connectionoffdropdrop
139052MALWARE-CNCWin.Trojan.Adialer variant outbound connectionoffdropdrop
139064MALWARE-CNCWin.Trojan.Sinrin initial JS dropper outbound connectionoffdropdrop
139084MALWARE-CNCWin.Trojan.Cript outbound connectionoffdropdrop
139085MALWARE-CNCWin.Trojan.Cript outbound connectionoffdropdrop
139086MALWARE-CNCWin.Trojan.Cript outbound connectionoffdropdrop
139117MALWARE-CNCWin.Trojan.Symmi variant outbound connectionoffdropdrop
139465MALWARE-CNCWin.Trojan.Unlock92 outbound connectionoffdropdrop
139573MALWARE-CNCWin.Backdoor.NanoBot variant outbound connectionoffdropdrop
139574MALWARE-CNCWin.Backdoor.NanoBot variant outbound connectionoffdropdrop
139575MALWARE-CNCWin.Backdoor.NanoBot variant outbound connectionoffdropdrop
139576MALWARE-CNCWin.Backdoor.NanoBot variant outbound connectionoffdropdrop
139577MALWARE-CNCWin.Backdoor.NanoBot variant outbound connectionoffdropdrop
139578MALWARE-CNCWin.Backdoor.NanoBot variant inbound connectionoffdropdrop
139579MALWARE-CNCWin.Backdoor.NanoBot variant outbound connectionoffdropdrop
139580MALWARE-CNCWin.Backdoor.NanoBot variant outbound connectionoffdropdrop
139581MALWARE-CNCWin.Trojan.NanoBot/Perseus initial outbound connectionoffdropdrop
139705MALWARE-CNCWin.Trojan.Zeus variant inbound connectionoffdropdrop
139730MALWARE-CNCWin.Adware.Xiazai outbound connectionoffdropdrop
139735FILE-OTHERVideoCharge buffer overflow SEH attemptoffoffoff
139736FILE-OTHERVideoCharge buffer overflow SEH attemptoffoffoff
139738MALWARE-CNCWin.Trojan.Trans variant outbound connectionoffdropdrop