Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-11-15

This SRU number: 2016-11-14-001
Previous SRU number: 2016-11-10-001

Applies to:

This SEU number: 1573
Previous SEU: 1572

Applies to:

This is the complete list of rules added in SRU 2016-11-14-001 and SEU 1573.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
140761MALWARE-CNCWin.Trojan.Syscan outbound connectionoffdropdrop
140762MALWARE-CNCAndroid.Trojan.SpyNote RAT variant inbound connectionoffdropdrop
140763MALWARE-CNCAndroid.Trojan.SpyNote RAT variant getSMS command responseoffdropdrop
140764MALWARE-CNCAndroid.Trojan.SpyNote RAT variant getContacts command responseoffdropdrop
140766SERVER-OTHERIBM Tivoli Storage Manager FastBack directory traversal attemptdropdropdrop
340767FILE-OTHERCisco IOS-XE update directory traversal attemptoffdropdrop
340768FILE-OTHERCisco IOS-XE update directory traversal attemptoffdropdrop
340769FILE-OTHERCisco IOS-XE update directory traversal attemptoffdropdrop
340770FILE-OTHERCisco IOS-XE update directory traversal attemptoffdropdrop
140771MALWARE-CNCWin.Trojan.Miuref variant outbound connectionoffdropdrop
340773FILE-PDFTRUFFLEHUNTER TALOS-2016-0198 attack attemptoffoffoff
340774FILE-PDFTRUFFLEHUNTER TALOS-2016-0198 attack attemptoffoffoff
140775MALWARE-CNCWin.Trojan.Banker variant outbound connectionoffdropdrop
340776FILE-PDFTRUFFLEHUNTER TALOS-2016-0218 attack attemptoffdropdrop
340777FILE-PDFTRUFFLEHUNTER TALOS-2016-0218 attack attemptoffdropdrop
140778FILE-PDFAcrobat Reader Open Cascade Library memory corruption attemptoffdropdrop
140779FILE-PDFAcrobat Reader Open Cascade Library memory corruption attemptoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
140759OS-WINDOWSMicrosoft Windows LSASS GSS-API DER decoding null pointer dereference attemptoffoffdrop
140760SERVER-OTHEROpenLDAP deref control denial of service attemptoffoffoff
140765SERVER-OTHERMultiple products ICMP denial of service attemptoffoffoff
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
140772PUA-ADWAREWin.Trojan.Miuref variant outbound connectionoffoffdrop

Updated Rules:

Updated rules can be found at this link.