Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-09-22

This SRU number: 2016-09-21-001
Previous SRU number: 2016-09-19-001

Applies to:

This SEU number: 1548
Previous SEU: 1547

Applies to:

This is the complete list of rules added in SRU 2016-09-21-001 and SEU 1548.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
140253SERVER-MYSQLMultiple SQL products privilege escalation attemptoffoffdrop
140254SERVER-MYSQLMultiple SQL products privilege escalation attemptoffoffdrop
140255SERVER-WEBAPPFreePBX Music Module ajax.php command injection attemptoffoffdrop
140256SERVER-WEBAPPIdera Up.Time Monitoring Station post2file.php arbitrary PHP file upload attemptoffoffoff
340257SERVER-WEBAPPCisco Cloud Services Platform dnslookup command injection attemptoffoffdrop
140258MALWARE-CNCOsx.Trojan.Keydnap variant backdoor detectedoffdropdrop
140259MALWARE-CNCOsx.Trojan.Keydnap variant backdoor detectedoffdropdrop
140260MALWARE-CNCOsx.Trojan.Keydnap variant initial backdoor download attemptoffdropdrop
140261MALWARE-CNCOsx.Trojan.Keydnap variant backdoor detectedoffdropdrop
140262MALWARE-CNCOsx.Trojan.Keydnap variant backdoor detectedoffdropdrop
140263MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140264MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140265MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140266MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140267MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140268MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140269MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140270MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140271MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140272MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140273MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
140274MALWARE-CNCOsx.Trojan.Keydnap variant dropper detectedoffdropdrop
340275SERVER-WEBAPPCisco ESA internal testing interface access attemptdropdropdrop

Updated Rules:

Updated rules can be found at this link.