Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-02-09

This SRU number: 2017-02-09-001
Previous SRU number: 2017-02-06-001

Applies to:

This SEU number: 1613
Previous SEU: 1610

Applies to:

This is the complete list of rules added in SRU 2017-02-09-001 and SEU 1613.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
141521SERVER-WEBAPPMcAfee Virus Scan Linux cross site scripting attemptoffdropdrop
141522BROWSER-IEMicrosoft Internet Explorer CGeneratedTreeNode object use after free attemptoffoffoff
141523BROWSER-IEMicrosoft Internet Explorer CGeneratedTreeNode object use after free attemptoffoffoff
141524INDICATOR-COMPROMISESOCKS5 proxy server method negotiation on non-standard portoffoffoff
141525INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141526INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141527INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141528INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141529INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141530INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141531INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141532INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141533INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141534INDICATOR-COMPROMISESOCKS5 proxy server method negotiation on non-standard portoffoffoff
141536SERVER-WEBAPPZoneMinder file.php directory traversal attemptoffoffdrop
341538SERVER-WEBAPPCisco ASA WebVPN memory corruption attemptoffdropdrop
141539BLACKLISTUser-Agent known malicious user-agent string - Elite Keyloggeroffdropdrop
141540MALWARE-CNCWin.Malware.Disttrack variant outbound connectionoffdropdrop
141541SERVER-ORACLEOracle reports servlet command execution attemptoffoffoff
141542SERVER-ORACLEOracle reports servlet command execution attemptoffoffoff
341543FILE-OFFICETRUFFLEHUNTER TALOS-2017-0285 attack attemptoffoffdrop
341544FILE-OFFICETRUFFLEHUNTER TALOS-2017-0285 attack attemptoffoffdrop
341545FILE-OFFICETRUFFLEHUNTER TALOS-2017-0284 attack attemptoffoffdrop
341546FILE-OFFICETRUFFLEHUNTER TALOS-2017-0284 attack attemptoffoffdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
141520SERVER-OTHERGe Fanuc Proficy WebView DOS attemptoffoffdrop
141535SERVER-WEBAPPBroadwin WebAccess DOS attemptoffoffdrop
141537SERVER-OTHERSiemens WinCC TIA Portal DOS attemptoffoffoff
341548SERVER-OTHERF5 BIG-IP TLS session ticket implementation uninitialized memory disclosure attemptoffdropdrop
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
341547SERVER-OTHERTLS client hello session resumption detectedoffalertalert

Updated Rules:

Updated rules can be found at this link.