Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-04-27

This SRU number: 2017-04-26-001
Previous SRU number: 2017-04-25-003

Applies to:

This SEU number: 1663
Previous SEU: 1662

Applies to:

This is the complete list of rules added in SRU 2017-04-26-001 and SEU 1663.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
142377FILE-PDFAdobe Acrobat Reader dll injection sandbox escapeoffoffoff
142378SERVER-OTHERYealink VoIP phone remote code execution attemptoffoffoff
142379SERVER-WEBAPPOpenCart directory traversal attemptoffoffoff
142380SERVER-WEBAPPOpenCart directory traversal attemptoffoffoff
142381SERVER-WEBAPPOpenCart directory traversal attemptoffoffoff
142382SERVER-WEBAPPTrend Micro Threat Discovery Appliance detected_potential_files.cgi command injection attemptoffoffdrop
142383SERVER-WEBAPPTrend Micro Threat Discovery Appliance detected_potential_files.cgi command injection attemptoffoffdrop
142384SERVER-WEBAPPTrend Micro Threat Discovery Appliance detected_potential_files.cgi command injection attemptoffoffdrop
142385MALWARE-CNCWin.Trojan.Moonwind outbound communicationoffdropdrop
142386MALWARE-CNCWin.Trojan.Mikcer variant outbound connection attemptoffdropdrop
142387SERVER-WEBAPPDataRate SCADA directory traversal attemptoffoffoff
142388SERVER-WEBAPPDataRate SCADA directory traversal attemptoffoffoff
142390MALWARE-CNCWin.Trojan.Moarider variant outbound connection attemptoffdropdrop
142391MALWARE-CNCWin.Trojan.Moarider variant outbound connection attemptoffdropdrop
142392SERVER-WEBAPPYealink VoIP phone directory traversal attemptoffoffdrop
142393SERVER-WEBAPPYealink VoIP phone directory traversal attemptoffoffdrop
142394SERVER-WEBAPPYealink VoIP phone directory traversal attemptoffoffdrop
142395MALWARE-CNCWin.Trojan.Oddjob outbound connectionoffdropdrop
142396EXPLOIT-KITBlacole inbound malformed pdf download attemptoffoffdrop
142397EXPLOIT-KITBlacole inbound malformed pdf download attemptoffoffdrop
142398MALWARE-CNCWin.Trojan.RedLeaves outbound connection attemptoffdropdrop
342399FILE-PDFTRUFFLEHUNTER TALOS-2017-0323 attack attemptoffoffoff
342400FILE-PDFTRUFFLEHUNTER TALOS-2017-0323 attack attemptoffoffoff
142402SERVER-WEBAPPmultiple product command injection attemptoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
142401SERVER-WEBAPPmultiple product version scan attemptoffoffoff
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
142389BROWSER-IEMicrosoft Internet Explorer uninitialized or deleted object access attemptoffoffoff

Updated Rules:

Updated rules can be found at this link.