* Talos combines our security experts from TRAC, SecApps, and VRT teams.
This SRU number: 2016-08-03-001
Previous SRU number: 2016-08-01-001
Applies to:
This SEU number: 1522
Previous SEU: 1521
Applies to:
This is the complete list of rules added in SRU 2016-08-03-001 and SEU 1522.
The format of the file is:
GID - SID - Rule Group - Rule Message - Policy State
The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.
The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.
Note: Unless stated explicitly, the rules are for the series of products listed above.
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 39779 | FILE-OTHER | Ubisoft Heroes of Might and Magic III .h3m map file buffer overflow attempt | off | off | off |
1 | 39780 | FILE-OTHER | Ubisoft Heroes of Might and Magic III .h3m map file buffer overflow attempt | off | off | off |
1 | 39781 | FILE-OTHER | Ubisoft Heroes of Might and Magic III .h3m map file buffer overflow attempt | off | off | off |
1 | 39782 | BLACKLIST | DNS request for known malware domain file.anyoffice.info - Win.Trojan.Lientchtp | off | drop | drop |
1 | 39783 | BLACKLIST | DNS request for known malware domain tech.decipherment.net - Win.Trojan.Lientchtp | off | drop | drop |
1 | 39784 | BLACKLIST | DNS request for known malware domain yejia.blackbeny.com - Win.Trojan.Lientchtp | off | drop | drop |
1 | 39785 | MALWARE-CNC | Win.Trojan.Qarallax initial outbound connection | off | drop | drop |
1 | 39786 | PUA-ADWARE | Win.Dowadmin.Adware outbound connection detected | off | off | off |
1 | 39787 | PUA-ADWARE | Win.Dowadmin.Adware outbound connection detected | off | off | off |
1 | 39788 | FILE-FLASH | Adobe Flash Player AS2 TextField gridFitType use after free attempt | off | drop | drop |
1 | 39789 | FILE-FLASH | Adobe Flash Player AS2 TextField gridFitType use after free attempt | off | drop | drop |
3 | 39790 | SERVER-WEBAPP | Cisco RV180 VPN Router platform.cgi command injection attempt | off | off | drop |
3 | 39791 | SERVER-WEBAPP | Cisco RV180 VPN Router platform.cgi command injection attempt | off | off | drop |
3 | 39792 | SERVER-WEBAPP | Cisco RV180 VPN Router platform.cgi command injection attempt | off | off | drop |
3 | 39793 | SERVER-WEBAPP | Cisco RV180 VPN Router platform.cgi directory traversal attempt | off | off | drop |
3 | 39794 | SERVER-WEBAPP | Cisco RV180 VPN Router platform.cgi directory traversal attempt | off | off | drop |
3 | 39795 | SERVER-WEBAPP | Cisco RV Series Routers insecure guest account login attempt | off | off | off |
1 | 39798 | FILE-PDF | Adobe Acrobat Reader raster image memory corruption attempt | off | drop | drop |
1 | 39799 | FILE-PDF | Adobe Acrobat Reader raster image memory corruption attempt | off | drop | drop |
1 | 39800 | MALWARE-CNC | Win.Trojan.Hancitor variant outbound connection | off | drop | drop |
1 | 39801 | MALWARE-CNC | Win.Trojan.Spyrat variant outbound connection | off | drop | drop |
1 | 39802 | EXPLOIT-KIT | Neutrino Exploit Kit Flash exploit download attempt | off | off | drop |
1 | 39803 | MALWARE-OTHER | Win.Adware.Dlhelper outbound connection detected | off | drop | drop |
1 | 39804 | MALWARE-OTHER | Win.Adware.Dlhelper outbound connection detected | off | drop | drop |
1 | 39805 | MALWARE-OTHER | Win.Adware.Dlhelper outbound connection detected | off | drop | drop |
1 | 39806 | MALWARE-OTHER | Win.Adware.Dlhelper outbound connection detected | off | drop | drop |
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
3 | 39796 | PROTOCOL-VOIP | Cisco Unified Communications Manager null pointer dereference attempt | off | off | off |
3 | 39797 | PROTOCOL-VOIP | Cisco Unified Communications Manager null pointer dereference attempt | off | off | off |
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 39776 | FILE-IDENTIFY | Heroes of Might and Magic III map file attachment detected | off | off | off |
1 | 39777 | FILE-IDENTIFY | Heroes of Might and Magic III map file attachment detected | off | off | off |
1 | 39778 | FILE-IDENTIFY | Heroes of Might and Magic III map file download request | off | off | off |
Updated rules can be found at this link.