Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-10-20

This SRU number: 2016-10-20-001
Previous SRU number: 2016-10-17-001

Applies to:

This SEU number: 1559
Previous SEU: 1557

Applies to:

This is the complete list of rules modified in SRU 2016-10-20-001 and SEU 1559.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
116301BROWSER-IEMicrosoft Internet Explorer HTML DOM invalid DHTML textnode creation attemptoffoffoff
119551MALWARE-OTHERself-signed SSL certificate with default Internet Widgits Pty Ltd organization nameoffoffdrop
121108EXPLOIT-KITunknown exploit kit obfuscated landing pageoffoffdrop
123905INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123906INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123907INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123908INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123909INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123910INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123911INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123912INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123913INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123914INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123915INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123916INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123917INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123918INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123919INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123920INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123921INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123922INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123923INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123924INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123925INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123926INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123927INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123928INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123929INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123930INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123931INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123932INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
123933INDICATOR-COMPROMISEWin.Trojan.DistTrack propagation - execute dropped fileoffoffoff
128069APP-DETECTDNS request for potential malware SafeGuard to domain 360.cnoffoffoff
128070APP-DETECTDNS request for potential malware SafeGuard to domain 360safe.comoffoffoff
128071APP-DETECT360.cn SafeGuard local HTTP management console access attemptoffoffoff
128795EXPLOIT-KITGoon/Infinity exploit kit payload download attemptoffdropdrop
128796EXPLOIT-KITiFRAMEr successful cnt.php redirectionoffalertalert
128797EXPLOIT-KITMultiple exploit kit binkey xored binary download attemptoffdropdrop
129213INDICATOR-OBFUSCATIONpotential math library debuggingoffdropdrop
131299MALWARE-CNCWin.Trojan.Necurs or Win.Trojan.Locky variant outbound detectionoffoffoff
140404BROWSER-IEMicrosoft Internet Explorer eval type confusion attemptoffoffdrop
140405BROWSER-IEMicrosoft Internet Explorer eval type confusion attemptoffoffdrop
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
123113INDICATOR-OBFUSCATIONeval gzinflate base64_decode call - likely maliciousoffoffoff
123114INDICATOR-OBFUSCATIONGIF header with PHP tags - likely maliciousoffoffoff
128039INDICATOR-COMPROMISESuspicious .pw dns queryoffoffdrop
128068APP-DETECT360.cn Safeguard runtime outbound communicationoffoffoff
139362BLACKLISTUser-Agent known malicious user-agent string - Win.Trojan.Batlopmaoffoffdrop
139866INDICATOR-COMPROMISESuspicious .ml dns queryoffoffdrop
139867INDICATOR-COMPROMISESuspicious .tk dns queryoffoffdrop
140081BLACKLISTUser-Agent known PUA user-agent string - TopTools100offoffdrop