Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-02-09

This SRU number: 2017-02-09-001
Previous SRU number: 2017-02-06-001

Applies to:

This SEU number: 1613
Previous SEU: 1610

Applies to:

This is the complete list of rules modified in SRU 2017-02-09-001 and SEU 1613.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
14142SERVER-ORACLEOracle reports servlet command execution attemptoffoffoff
116809MALWARE-CNCWin.Trojan.FraudPack variant outbound connectionoffdropdrop
116810MALWARE-CNCknown command and control channel trafficoffdropdrop
116811MALWARE-CNCknown command and control channel trafficoffdropdrop
116812MALWARE-CNCknown command and control channel trafficoffdropdrop
116813MALWARE-CNCknown command and control channel trafficoffoffoff
116814MALWARE-CNCknown command and control channel trafficoffoffoff
116815MALWARE-CNCknown command and control channel trafficoffoffoff
116816MALWARE-CNCknown command and control channel trafficoffdropdrop
116817MALWARE-CNCknown command and control channel trafficoffdropdrop
116818MALWARE-CNCknown command and control channel trafficoffoffoff
116819MALWARE-CNCknown command and control channel trafficoffoffoff
116820MALWARE-CNCWin.Trojan.Kryptik variant outbound connectionoffdropdrop
116821MALWARE-CNCknown command and control channel trafficoffoffoff
116822MALWARE-CNCknown command and control channel trafficoffdropdrop
116823MALWARE-CNCWin.Trojan.FlyStudio known command and control channel trafficoffdropdrop
116824MALWARE-CNCknown command and control channel trafficoffdropdrop
116825MALWARE-CNCknown command and control channel trafficoffoffoff
116826MALWARE-CNCknown command and control channel trafficoffdropdrop
116827MALWARE-CNCknown command and control channel trafficoffdropdrop
116828MALWARE-CNCknown command and control channel trafficoffdropdrop
116829MALWARE-CNCknown command and control channel trafficoffoffoff
116830MALWARE-CNCknown command and control channel trafficoffoffoff
116831MALWARE-CNCknown command and control channel trafficoffoffoff
116832MALWARE-CNCknown command and control channel trafficoffdropdrop
116833MALWARE-CNCknown command and control channel trafficoffdropdrop
116834BLACKLISTDNS request for known malware domain qd.netkill.com.cn - Trojan-Downloader.Win32.Adload.rzxoffoffoff
116835BLACKLISTDNS request for known malware domain exe.146843.com - Trojan.Win32.Opeg.aoffoffoff
116836BLACKLISTDNS request for known malware domain ra03.e5732.com - Trojan-Clicker.Win32.Small.afgoffoffoff
116837BLACKLISTDNS request for known malware domain dangercheats.com.br - Trojan.Win32.Refroso.arnqoffoffoff
116838BLACKLISTDNS request for known malware domain xlm.ppvsr.com - Trojan-GameThief.Win32.OnLineGames.wwcfoffoffoff
116839BLACKLISTDNS request for known malware domain sh16.e8753.com - Trojan.Win32.Scar.ccqboffoffoff
116840BLACKLISTDNS request for known malware domain rx11.e6532.com - Trojan.Win32.Opeg.aoffoffoff
116841BLACKLISTDNS request for known malware domain podgorz.org - Trojan-Spy.Win32.Zbot.genoffoffoff
116842BLACKLISTDNS request for known malware domain sp19.e4578.com - Trojan-Downloader.Win32.Genome.njzoffoffoff
116843BLACKLISTDNS request for known malware domain 1.7zsm.com - Trojan-Downloader.Win32.Agent.dtuooffoffoff
116844BLACKLISTDNS request for known malware domain rm08.e4562.com - Trojan-Downloader.Win32.Agent.dngxoffoffoff
116845BLACKLISTDNS request for known malware domain rc04.e6532.com - Trojan-Downloader.Win32.Genome.awldoffoffoff
116846BLACKLISTDNS request for known malware domain bedayton.com - Trojan-Downloader.Win32.Agent.dlheoffoffoff
116847BLACKLISTDNS request for known malware domain rz12.e6805.com - Trojan-Downloader.Win32.Genome.awldoffoffoff
116849BLACKLISTDNS request for known malware domain re05.e6532.com - Trojan-Downloader.Win32.Genome.awldoffoffoff
116850BLACKLISTDNS request for known malware domain kldmten.net - Trojan-Spy.Win32.Zbot.akraoffoffoff
116851BLACKLISTDNS request for known malware domain forelc.cc - Trojan-Ransom.Win32.XBlocker.aheoffoffoff
116852BLACKLISTDNS request for known malware domain v.yao63.com - Trojan-Downloader.Win32.Agent.dqnsoffoffoff
116853BLACKLISTDNS request for known malware domain vh26.e4578.com - Trojan.Win32.Opeg.aoffoffoff
116854BLACKLISTDNS request for known malware domain up1.give2sms.com - Trojan-Downloader.Win32.Genome.estoffoffoff
116855BLACKLISTDNS request for known malware domain d.123kuaihuo.com - Trojan.Win32.Scar.clbxoffoffoff
116856BLACKLISTDNS request for known malware domain andy.cd - Backdoor.Win32.Agent.autooffoffoff
116858BLACKLISTDNS request for known malware domain charter-x.biz - Packed.Win32.Krap.aeoffoffoff
116859BLACKLISTDNS request for known malware domain gerherber.com - Trojan-Spy.Win32.Zbot.akdwoffoffoff
116860BLACKLISTDNS request for known malware domain urodinam.net - Trojan.Win32.TDSS.azsjoffoffoff
116861BLACKLISTDNS request for known malware domain gite-eguisheim.com - Trojan-Downloader.Win32.Piker.clpoffoffoff
116862BLACKLISTDNS request for known malware domain phaizeipeu.ru - Packed.Win32.Krap.gxoffoffoff
116863BLACKLISTDNS request for known malware domain teendx.com - Trojan-Spy.Win32.Zbot.genoffoffoff
116864BLACKLISTDNS request for known malware domain taiping2033.2288.org - Trojan-Downloader.Win32.Selvice.afyoffoffoff
116865BLACKLISTDNS request for known malware domain cnfg.maxsitesrevenues.net - Trojan.Win32.BHO.afkeoffoffoff
116868BLACKLISTDNS request for known malware domain hostshack.net - Trojan.Win32.Buzus.emploffoffoff
116869BLACKLISTDNS request for known malware domain tt.vv49.com - Trojan-GameThief.Win32.OnLineGames.bnkboffoffoff
116870BLACKLISTDNS request for known malware domain search.sidegreen.com - Backdoor.Win32.Agent.arqioffoffoff
116871BLACKLISTDNS request for known malware domain parfaitpournous.com - Trojan-Spy.Win32.Zbot.genoffoffoff
116872BLACKLISTDNS request for known malware domain postmetoday.ru - Packed.Win32.Katusha.joffoffoff
116873BLACKLISTDNS request for known malware domain youword.cn - Trojan.Win32.Scar.bvguoffoffoff
116874BLACKLISTDNS request for known malware domain ophaeghaev.ru - Trojan-Spy.Win32.Zbot.akmioffoffoff
116875BLACKLISTDNS request for known malware domain up1.free-sms.co.kr - Trojan.Win32.Vilsel.akpoffoffoff
116876BLACKLISTDNS request for known malware domain c.softdowns.info - Trojan.BAT.Agent.ynoffoffoff
116877BLACKLISTDNS request for known malware domain ddkom.biz - Trojan.Win32.Scar.ckhroffoffoff
116878BLACKLISTDNS request for known malware domain vopret.ru - Trojan.Win32.FraudPack.axwnoffoffoff
116879BLACKLISTDNS request for known malware domain dnfpomo.dnfranran.com - Trojan-GameThief.Win32.OnLineGames.bnkxoffoffoff
116881BLACKLISTDNS request for known malware domain sex-gifts.ru - Trojan-Spy.Win32.Zbot.genoffoffoff
116882BLACKLISTDNS request for known malware domain 111.168lala.com - Backdoor.Win32.Popwin.cynoffoffoff
116883BLACKLISTDNS request for known malware domain mcafee-registry.ru - Trojan-Spy.Win32.Zbot.akgboffoffoff
116884BLACKLISTDNS request for known malware domain bits4ever.ru - Trojan-Spy.Win32.Zbot.akntoffoffoff
116885BLACKLISTDNS request for known malware domain monicaecarlos.com - Trojan-Downloader.Win32.Genome.awxvoffoffoff
116887BLACKLISTDNS request for known malware domain hesneclimi.ru - Packed.Win32.Krap.aeoffoffoff
116888BLACKLISTDNS request for known malware domain dbtte.com - Trojan-Banker.Win32.Banz.crkoffoffoff
116890BLACKLISTDNS request for known malware domain in6cs.com - Trojan.Win32.Tdss.beeaoffoffoff
116891BLACKLISTDNS request for known malware domain solo1928.ru - Trojan-Spy.Win32.Zbot.genoffoffoff
116892BLACKLISTDNS request for known malware domain fg545633.host.zgridc.com - Trojan.Win32.Pincav.abuboffoffoff
116893BLACKLISTDNS request for known malware domain primusdns.ru - Backdoor.Win32.Havar.ehoffoffoff
116895BLACKLISTDNS request for known malware domain alodh.in - Backdoor.Win32.Delf.vdeoffoffoff
116896BLACKLISTDNS request for known malware domain reward.pnshop.co.kr - Backdoor.Win32.Agent.ahraoffoffoff
116898BLACKLISTDNS request for known malware domain sx21.e4578.com - Trojan.Win32.Scar.ccqboffoffoff
116900BLACKLISTDNS request for known malware domain reportes201.com - Trojan-Downloader.Win32.Genome.asheoffoffoff
116901BLACKLISTDNS request for known malware domain local.1140.co.kr - Trojan-Downloader.Win32.Genome.aobmoffoffoff
116902BLACKLISTDNS request for known malware domain promojoy.net - Packed.Win32.Krap.gxoffoffoff
116903BLACKLISTDNS request for known malware domain gpwg.ws - Worm.Win32.AutoRun.bjcaoffoffoff
116906BLACKLISTDNS request for known malware domain down.p2pplay.com - Trojan-GameThief.Win32.OnLineGames.wgkvoffoffoff
116907BLACKLISTDNS request for known malware domain livetrust.info - Trojan-Spy.Win32.Zbot.akkuoffoffoff
116908BLACKLISTDNS request for known malware domain ootaivilei.ru - Trojan-Spy.Win32.Zbot.akmeoffoffoff
116909BLACKLISTDNS request for known malware domain babah20122012.com - Trojan-Spy.Win32.Zbot.akbboffoffoff
116910BLACKLISTDNS request for known malware domain pattern - 0-0-0-0-0-0-0.infooffoffoff
116911BLACKLISTURI request for known malicious URI - ucsp0416.exe?t=offoffoff
116912BLACKLISTURI request for known malicious URI - net/cfg2.binoffoffoff
116913BLACKLISTURI request for known malicious URI - count_log/log/boot.php?p=offoffoff
116914BLACKLISTURI request for known malicious URI - .bin?ucspoffoffoff
116915BLACKLISTURI request for known malicious URI - /MNG/Download/?File=AZFoffoffoff
116916BLACKLISTURI request for known malicious URI - /jarun/jezerceoffoffoff
116917BLACKLISTURI request for known malicious URI - /ekaterina/velikaoffoffoff
116918BLACKLISTURI request for known malicious URI - /ultimate/fightoffoffoff
116919BLACKLISTURI request for known malicious URI - /tmp/pm.exe?t=offoffoff
116920BLACKLISTURI request for known malicious URI - /DownLoadFile/BaePo/veroffoffoff
116921BLACKLISTURI request for known malicious URI - /s1/launcher/update/Update/data/offoffoff
116922BLACKLISTURI request for known malicious URI - /cgi-bin/rd.cgi?f=/vercfg.dat?AgentID=offoffoff
116923BLACKLISTURI request for known malicious URI - /search.php?username=coolweb07&keywords=offoffoff
116924BLACKLISTURI request for known malicious URI - /inst.php?fff=offdropdrop
116925BLACKLISTURI request for known malicious URI - /message.php?subid=offoffoff
116926BLACKLISTURI request for known malicious URI - strMode=setup&strID=pcvaccine&strPC=offoffoff
116927BLACKLISTURI request for known malicious URI - MGWEB.php?c=TestUrloffoffoff
116928BLACKLISTURI request for known malicious URI - /stat.html?0dPg0uXTraCSqrOdlrKpmpyorePbzoffoffoff
116929BLACKLISTURI request for known malicious URI - gate.php?guid=offoffoff
116930BLACKLISTURI request for known malicious URI - count.asp?mac=offoffoff
116931BLACKLISTURI request for known malicious URI - feedbigfoot.php?m=offoffoff
116932BLACKLISTURI request for known malicious URI - /qqnongchang/qqkj.offoffoff
116933BLACKLISTURI request for known malicious URI - /root/9 frt.raroffoffoff
117350SERVER-ORACLEOracle Application Server forms arbitrary system command execution attemptoffoffoff
117819BLACKLISTDNS request for known malware domain motuh.comoffoffoff
117821BLACKLISTDNS request for known malware domain ketsymbol.comoffoffoff
117824BLACKLISTDNS request for known malware domain teenxmovs.netoffoffoff
117826BLACKLISTDNS request for known malware domain cheaps1.infooffoffoff
117827BLACKLISTDNS request for known malware domain sexmoviesland.netoffoffoff
117828BLACKLISTDNS request for known malware domain 67.201.36.16offoffoff
117830BLACKLISTDNS request for known malware domain dickvsclit.netoffoffoff
117831BLACKLISTDNS request for known malware domain edrichfinearts.comoffoffoff
117834BLACKLISTDNS request for known malware domain 343.boolans.comoffoffoff
117835BLACKLISTDNS request for known malware domain xpresdnet.comoffoffoff
117836BLACKLISTDNS request for known malware domain gbsup.comoffoffoff
117837BLACKLISTDNS request for known malware domain xxsmovies.comoffoffoff
117838BLACKLISTDNS request for known malware domain vc.iwriteweb.comoffoffoff
117839BLACKLISTDNS request for known malware domain js.222233.comoffoffoff
117840BLACKLISTDNS request for known malware domain www.grannyplanet.comoffoffoff
117842BLACKLISTDNS request for known malware domain extrahotx.netoffoffoff
117843BLACKLISTDNS request for known malware domain extralargevideos.comoffoffoff
117844BLACKLISTDNS request for known malware domain www.derquda.comoffoffoff
117845BLACKLISTDNS request for known malware domain aahydrogen.comoffoffoff
117846BLACKLISTDNS request for known malware domain trumpetlicks.comoffoffoff
117847BLACKLISTDNS request for known malware domain mskla.comoffoffoff
117849BLACKLISTDNS request for known malware domain fuckersucker.comoffoffoff
117850BLACKLISTDNS request for known malware domain pornfucklist.comoffoffoff
117851BLACKLISTDNS request for known malware domain game.685faiudeme.comoffoffoff
117853BLACKLISTDNS request for known malware domain dommonview.comoffoffoff
117854BLACKLISTDNS request for known malware domain www.lamiaexragazza.comoffoffoff
117855BLACKLISTDNS request for known malware domain acofinder.comoffoffoff
117856BLACKLISTDNS request for known malware domain fuckfuckvids.comoffoffoff
117857BLACKLISTDNS request for known malware domain www.cnhack.cnoffoffoff
117858BLACKLISTDNS request for known malware domain kingsizematures.comoffoffoff
117859BLACKLISTDNS request for known malware domain promotds.comoffoffoff
117860BLACKLISTDNS request for known malware domain mejac.comoffoffoff
117863BLACKLISTDNS request for known malware domain rpt2.21civ.comoffoffoff
117864BLACKLISTDNS request for known malware domain tubexxxmatures.comoffoffoff
117866BLACKLISTDNS request for known malware domain aebankonline.comoffoffoff
117870BLACKLISTDNS request for known malware domain trojan8.comoffoffoff
117871BLACKLISTDNS request for known malware domain brutalxvideos.comoffoffoff
117872BLACKLISTDNS request for known malware domain www3.sexown.comoffoffoff
117873BLACKLISTDNS request for known malware domain mummimpegs.comoffoffoff
117874BLACKLISTDNS request for known malware domain f19dd4abb8b8bdf2.cnoffoffoff
117875BLACKLISTDNS request for known malware domain www.very-young-boys.comoffoffoff
117876BLACKLISTDNS request for known malware domain 91629.comoffoffoff
117878BLACKLISTDNS request for known malware domain ayb.host127-0-0-1.comoffoffoff
117879BLACKLISTDNS request for known malware domain cfg.353wanwan.comoffoffoff
117881BLACKLISTDNS request for known malware domain fucktosky.comoffoffoff
117882BLACKLISTDNS request for known malware domain procca.comoffoffoff
117883BLACKLISTDNS request for known malware domain autouploaders.netoffoffoff
117884BLACKLISTDNS request for known malware domain gimmemyporn.comoffoffoff
117885BLACKLISTDNS request for known malware domain waytoall.comoffoffoff
117886BLACKLISTDNS request for known malware domain www.spamature.comoffoffoff
117887BLACKLISTDNS request for known malware domain info.collectionerrorreport.comoffoffoff
117889BLACKLISTDNS request for known malware domain www.ajie520.comoffoffoff
117891BLACKLISTDNS request for known malware domain bestkind.ruoffoffoff
117893BLACKLISTDNS request for known malware domain www.zxc0001.comoffoffoff
117894BLACKLISTDNS request for known malware domain streq.cnoffoffoff
117895BLACKLISTDNS request for known malware domain pyow.prixi-soft.iroffoffoff
117897BLACKLISTDNS request for known malware domain www.moneytw8.comoffoffoff
117898BLACKLISTURI request for known malicious URI - /get2.php?c=VTOXUGUI&d=offoffoff
117899BLACKLISTURI request for known malicious URI - /reques0.asp?kind=006&mac=offoffoff
117900BLACKLISTURI request for known malicious URI - /basic/cn3c2/c.*dlloffoffoff
117901BLACKLISTURI request for known malicious URI - /mybackup21.raroffoffoff
117902BLACKLISTURI request for known malicious URI - /?getexe=loader.exeoffoffoff
117903BLACKLISTURI request for known malicious URI - stid=offoffoff
117904BLACKLISTURI request for known malicious URI - /tongji.jsoffdropdrop
117905BLACKLISTURI request for known malicious URI - 1de49069b6044785e9dfcd4c035cfd0c.phpoffoffoff
117906BLACKLISTURI request for known malicious URI - 2x/.*phpoffoffoff
117907BLACKLISTURI request for known malicious URI - /MNG/Download/?File=AZF DATADIR Downloadoffoffoff
117908BLACKLISTURI request for known malicious URI - /images/crypt_22.exeoffoffoff
117909BLACKLISTURI request for known malicious URI - /images/css/1.exeoffoffoff
117910BLACKLISTURI request for known malicious URI - /7xdown.exeoffoffoff
117911BLACKLISTURI request for known malicious URI - /winhelper.exeoffoffoff
117912BLACKLISTURI request for known malicious URI - /upopwin/count.asp?mac=offoffoff
117913BLACKLISTURI request for known malicious URI - /ok.exeoffoffoff
117914BLACKLISTURI request for known malicious URI - /LjBin/Bin.Dlloffoffoff
117915BLACKLISTURI request for known malicious URI - /1001ns/cfg3n.binoffoffoff
117916BLACKLISTURI request for known malicious URI - /dh/stats.binoffoffoff
117917BLACKLISTURI request for known malicious URI - /zeus/config.binoffoffoff
118132INDICATOR-OBFUSCATIONmalware-associated JavaScript obfuscation functionoffoffoff
118251BLACKLISTDNS request for known malware domain vcxde.comoffoffoff
118252BLACKLISTDNS request for known malware domain protectyourpc-11.comoffoffoff
118253BLACKLISTDNS request for known malware domain blogsmonitoringservice.comoffoffoff
118254BLACKLISTDNS request for known malware domain checkserverstux.comoffoffoff
118255BLACKLISTDNS request for known malware domain gopheisstoo.ccoffoffoff
118256BLACKLISTDNS request for known malware domain tutubest.comoffoffoff
118257BLACKLISTDNS request for known malware domain dns-check.bizoffoffoff
118258BLACKLISTDNS request for known malware domain ftuny.comoffoffoff
118259BLACKLISTDNS request for known malware domain whysohardx.comoffoffoff
118260BLACKLISTDNS request for known malware domain freenetgameonline.comoffoffoff
118336BLACKLISTUser-Agent known malicious user-agent string gbot/2.3offoffoff
118337BLACKLISTUser-Agent known malicious user-agent string iamx/3.11offoffoff
118338BLACKLISTUser-Agent known malicious user-agent string NSISDL/1.2offoffoff
118340BLACKLISTUser-Agent known malicious user-agent string ClickAdsByIE 0.7.5offoffoff
118341BLACKLISTUser-Agent known malicious user-agent string UtilMind HTTPGetoffoffoff
118342BLACKLISTUser-Agent known malicious user-agent string NSIS_DOWNLOADoffoffoff
118343BLACKLISTUser-Agent known malicious user-agent string WSEnrichmentoffoffoff
118345BLACKLISTUser-Agent known malicious user-agent string Macrovision_DM_2.4.15offoffoff
118346BLACKLISTUser-Agent known malicious user-agent string GPRecoveroffoffoff
118347BLACKLISTUser-Agent known malicious user-agent string AutoItoffoffoff
118348BLACKLISTUser-Agent known malicious user-agent string Opera/9.80 Pesto/2.2.15offoffoff
118349BLACKLISTUser-Agent known malicious user-agent string Flipopiaoffoffoff
118350BLACKLISTUser-Agent known malicious user-agent string GabPathoffoffoff
118351BLACKLISTUser-Agent known malicious user-agent string GPUpdateroffoffoff
118352BLACKLISTUser-Agent known malicious user-agent string PinballCorp-BSAI/VER_STR_COMMAoffoffoff
118353BLACKLISTUser-Agent request for known PUA user agent - SelectRebatesoffdropdrop
118354BLACKLISTUser-Agent known malicious user-agent string opera/8.11offoffoff
118355BLACKLISTUser-Agent known malicious user-agent string Se2011offoffoff
118356BLACKLISTUser-Agent known malicious user-agent string randomoffoffoff
118357BLACKLISTUser-Agent known malicious user-agent string Setup Factoryoffoffoff
118358BLACKLISTUser-Agent known malicious user-agent string NSIS_INETLOADoffoffoff
118359BLACKLISTUser-Agent known malicious user-agent string Shareazaoffoffoff
118360BLACKLISTUser-Agent known malicious user-agent string Oncuesoffoffoff
118361BLACKLISTUser-Agent known malicious user-agent string Downloader1.1offoffoff
118362BLACKLISTUser-Agent known malicious user-agent string Search Toolbar 1.1offoffoff
118363BLACKLISTUser-Agent known malicious user-agent string GPRecoveroffoffoff
118364BLACKLISTUser-Agent known malicious user-agent string msndownoffoffoff
118365BLACKLISTUser-Agent known malicious user-agent string Agentccoffoffoff
118366BLACKLISTUser-Agent known malicious user-agent string OCInstalleroffoffoff
118367BLACKLISTUser-Agent known malicious user-agent string FPRecoveroffoffoff
118368BLACKLISTUser-Agent known malicious user-agent string Our_Agentoffoffoff
118369BLACKLISTUser-Agent known malicious user-agent string iexp-getoffoffoff
118370BLACKLISTUser-Agent known malicious user-agent string Mozilla Windows MSIEoffoffoff
118371BLACKLISTUser-Agent known malicious user-agent string QvodDownoffoffoff
118373BLACKLISTUser-Agent known malicious user-agent string Installeroffoffoff
118374BLACKLISTUser-Agent known malicious user-agent string SurfBearoffoffoff
118375BLACKLISTUser-Agent known malicious user-agent string HTTP Wininetoffoffoff
118376BLACKLISTUser-Agent known malicious user-agent string Trololooffoffoff
118377BLACKLISTUser-Agent known malicious user-agent string malwareoffoffoff
118378BLACKLISTUser-Agent known malicious user-agent string AutoHotkeyoffoffoff
118379BLACKLISTUser-Agent known malicious user-agent string AskInstallCheckeroffoffoff
118380BLACKLISTUser-Agent known malicious user-agent string FPUpdateroffoffoff
118381BLACKLISTUser-Agent known malicious user-agent string Travel Updateoffoffoff
118382BLACKLISTUser-Agent known malicious user-agent string WMUpdateoffoffoff
118383BLACKLISTUser-Agent known malicious user-agent string GPInstalleroffoffoff
118385BLACKLISTUser-Agent known malicious user-agent string HTTPCSDCENTERoffoffoff
118386BLACKLISTUser-Agent known malicious user-agent string AHTTPConnectionoffoffoff
118387BLACKLISTUser-Agent known malicious user-agent string dwplayeroffoffoff
118388BLACKLISTUser-Agent known malicious user-agent string RookIE/1.0offdropdrop
118389BLACKLISTUser-Agent known malicious user-agent string 3653Clientoffoffoff
118390BLACKLISTUser-Agent known malicious user-agent string Delphi 5.xoffoffoff
118391BLACKLISTUser-Agent known malicious user-agent string MyLoveoffoffoff
118392BLACKLISTUser-Agent known malicious user-agent string qixioffoffoff
118393BLACKLISTUser-Agent known malicious user-agent string vyre32offoffoff
118394BLACKLISTUser-Agent known malicious user-agent string OCRecoveroffoffoff
118395BLACKLISTUser-Agent known malicious user-agent string Duckling/1.0offoffoff
118492BLACKLISTDNS request for known malware domain ilo.brenz.pl - Win.Trojan.Ramnitoffoffoff
118774MALWARE-CNCURI request for known malicious URIoffoffoff
118775MALWARE-CNCURI request for known malicious URI - /gpdcountoffoffoff
123157EXPLOIT-KITNuclear Pack exploit kit binary downloadoffdropdrop
123218EXPLOIT-KITRedkit Repeated Exploit Request Patternoffalertalert
123636INDICATOR-OBFUSCATIONJavaScript built-in function parseInt appears obfuscated - likely packer or encoderoffoffoff
135316BLACKLISTUser-Agent known malicious user-agent string EI Plugin updateroffdropdrop
137273FILE-OFFICEMicrosoft Office RTF parser heap overflow attemptoffdropdrop
137274FILE-OFFICEMicrosoft Office RTF parser heap overflow attemptoffdropdrop
139710BLACKLISTUser-Agent known malicious user-agent string mozilla/2.0offdropdrop
140366BROWSER-IEMicrosoft Internet Explorer ArraySpeciesCreate type confusion attemptoffoffdrop
140367BROWSER-IEMicrosoft Internet Explorer ArraySpeciesCreate type confusion attemptoffoffdrop
141515POLICY-OTHERMcAfee Virus Scan Linux outdated version detectedoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
123156EXPLOIT-KITNuclear Pack exploit kit landing pageoffoffdrop
124103MALWARE-OTHERHTTP POST request to a JPG fileoffoffoff
124104MALWARE-OTHERHTTP POST request to a JPEG fileoffoffoff
124105MALWARE-OTHERHTTP POST request to a GIF fileoffoffoff
124106MALWARE-OTHERHTTP POST request to a PNG fileoffoffoff
124107MALWARE-OTHERHTTP POST request to a BMP fileoffoffalert
124108MALWARE-OTHERHTTP POST request to a RAR fileoffoffoff
124109MALWARE-OTHERHTTP POST request to a ZIP fileoffoffoff
124110MALWARE-OTHERHTTP POST request to an MP3 fileoffoffoff
135780FILE-PDFAdobe Reader out of bounds memory read attemptoffdropdrop
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
123113INDICATOR-OBFUSCATIONeval gzinflate base64_decode call - likely maliciousoffoffoff
123114INDICATOR-OBFUSCATIONGIF header with PHP tags - likely maliciousoffoffoff