Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-05-04

This SRU number: 2017-05-03-001
Previous SRU number: 2017-05-01-002

Applies to:

This SEU number: 1666
Previous SEU: 1665

Applies to:

This is the complete list of rules added in SRU 2017-05-03-001 and SEU 1666.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
342432SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0328 attack attemptoffoffdrop
342433SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0328 attack attemptoffoffdrop
342434SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0328 attack attemptoffoffdrop
342435SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0330 attack attemptoffoffdrop
342436SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0330 attack attemptoffoffdrop
342437SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0331 attack attemptoffoffdrop
342438SERVER-MAILIBM Domino BMP parsing integer overflow attemptoffdropdrop
142439MALWARE-CNCWin.Trojan.Axespec outbound requestoffdropdrop
142440OS-WINDOWSMicrosoft Jet DB Engine Buffer Overflow attemptoffoffoff
142441OS-WINDOWSMicrosoft Jet DB Engine Buffer Overflow attemptoffoffoff
142442OS-WINDOWSMicrosoft Jet DB Engine Buffer Overflow attemptoffoffoff
142443OS-WINDOWSMicrosoft Jet DB Engine Buffer Overflow attemptoffdropdrop
142444OS-WINDOWSMicrosoft Jet DB Engine Buffer Overflow attemptoffoffoff
142445OS-WINDOWSMicrosoft Jet DB Engine Buffer Overflow attemptoffoffoff
142446OS-WINDOWSMicrosoft Jet DB Engine Buffer Overflow attemptoffoffoff
142447MALWARE-CNCWin.Trojan.Batlopma variant outbound connection attemptoffdropdrop
142448BROWSER-IEMicrosoft Internet Explorer deleted object access memory corruption attemptoffoffoff
142449BROWSER-IEMicrosoft Internet Explorer deleted object access memory corruption attemptoffoffoff
142450BROWSER-IEMicrosoft Internet Explorer deleted object access memory corruption attemptoffoffoff
142451SERVER-WEBAPPMCA Sistemas ScadaBR index.php brute force login attemptoffoffoff
142452MALWARE-CNCWin.Trojan.Frethog variant outbound connection attemptoffdropdrop
142453MALWARE-CNCWin.Trojan.Frethog variant inbound connection attemptoffdropdrop
142454BLACKLISTUser-Agent known malicious user-agent string - Frethogoffdropdrop
142455SERVER-WEBAPPUnitrends Enterprise Backup Appliance password.php command injection attemptoffoffdrop
142456SERVER-WEBAPPUnitrends Enterprise Backup Appliance password.php command injection attemptoffoffdrop
142457SERVER-WEBAPPUnitrends Enterprise Backup Appliance password.php command injection attemptoffoffdrop
142461SERVER-WEBAPPUnitrends Enterprise Backup Appliance reports.php PHP file injection attemptoffoffdrop
142462SERVER-WEBAPPUnitrends Enterprise Backup Appliance reports.php directory traversal attemptoffoffdrop
142465SERVER-WEBAPPtriple dot directory traversal attemptoffoffoff
142467SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142468SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142469SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142470SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142471SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142472SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142473SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142474SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142477SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142478SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142479SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142480SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142481SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142482SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142483SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142484SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142485SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142486SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142487SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
142488SERVER-WEBAPPEdimax 802.11AC repeater command injection attemptoffoffdrop
342489SERVER-OTHERCisco Aironet Mobility Express PnP agent directory traversal attemptoffoffdrop
142490POLICY-OTHERIntel AMT remote administration tool access attemptoffoffoff
142491POLICY-OTHERIntel AMT remote administration tool access attemptoffoffoff
142492APP-DETECTIntel AMT DHCP boot request detectedoffoffoff
342493SERVER-OTHERCisco CVR100W VPN Router SSDP uuid stack buffer overflow attemptoffoffdrop
142494FILE-EXECUTABLEXOR 0x01 encrypted portable executable file download attemptoffoffoff
142495FILE-EXECUTABLEXOR 0x02 encrypted portable executable file download attemptoffoffoff
142496FILE-EXECUTABLEXOR 0x03 encrypted portable executable file download attemptoffoffoff
142497FILE-EXECUTABLEXOR 0x04 encrypted portable executable file download attemptoffoffoff
142498FILE-EXECUTABLEXOR 0x05 encrypted portable executable file download attemptoffoffoff
142499FILE-EXECUTABLEXOR 0x06 encrypted portable executable file download attemptoffoffoff
142500FILE-EXECUTABLEXOR 0x07 encrypted portable executable file download attemptoffoffoff
142501FILE-EXECUTABLEXOR 0x08 encrypted portable executable file download attemptoffoffoff
142502FILE-EXECUTABLEXOR 0x09 encrypted portable executable file download attemptoffoffoff
142503FILE-EXECUTABLEXOR 0x0a encrypted portable executable file download attemptoffoffoff
142504FILE-EXECUTABLEXOR 0x0b encrypted portable executable file download attemptoffoffoff
142505FILE-EXECUTABLEXOR 0x0c encrypted portable executable file download attemptoffoffoff
142506FILE-EXECUTABLEXOR 0x0d encrypted portable executable file download attemptoffoffoff
142507FILE-EXECUTABLEXOR 0x0e encrypted portable executable file download attemptoffoffoff
142508FILE-EXECUTABLEXOR 0x0f encrypted portable executable file download attemptoffoffoff
142509FILE-EXECUTABLEXOR 0x10 encrypted portable executable file download attemptoffoffoff
142510FILE-EXECUTABLEXOR 0x11 encrypted portable executable file download attemptoffoffoff
142511FILE-EXECUTABLEXOR 0x12 encrypted portable executable file download attemptoffoffoff
142512FILE-EXECUTABLEXOR 0x13 encrypted portable executable file download attemptoffoffoff
142513FILE-EXECUTABLEXOR 0x14 encrypted portable executable file download attemptoffoffoff
142514FILE-EXECUTABLEXOR 0x15 encrypted portable executable file download attemptoffoffoff
142515FILE-EXECUTABLEXOR 0x16 encrypted portable executable file download attemptoffoffoff
142516FILE-EXECUTABLEXOR 0x17 encrypted portable executable file download attemptoffoffoff
142517FILE-EXECUTABLEXOR 0x18 encrypted portable executable file download attemptoffoffoff
142518FILE-EXECUTABLEXOR 0x19 encrypted portable executable file download attemptoffoffoff
142519FILE-EXECUTABLEXOR 0x1a encrypted portable executable file download attemptoffoffoff
142520FILE-EXECUTABLEXOR 0x1b encrypted portable executable file download attemptoffoffoff
142521FILE-EXECUTABLEXOR 0x1c encrypted portable executable file download attemptoffoffoff
142522FILE-EXECUTABLEXOR 0x1d encrypted portable executable file download attemptoffoffoff
142523FILE-EXECUTABLEXOR 0x1e encrypted portable executable file download attemptoffoffoff
142524FILE-EXECUTABLEXOR 0x1f encrypted portable executable file download attemptoffoffoff
142525FILE-EXECUTABLEXOR 0x20 encrypted portable executable file download attemptoffoffoff
142526FILE-EXECUTABLEXOR 0x21 encrypted portable executable file download attemptoffoffoff
142527FILE-EXECUTABLEXOR 0x22 encrypted portable executable file download attemptoffoffoff
142528FILE-EXECUTABLEXOR 0x23 encrypted portable executable file download attemptoffoffoff
142529FILE-EXECUTABLEXOR 0x24 encrypted portable executable file download attemptoffoffoff
142530FILE-EXECUTABLEXOR 0x25 encrypted portable executable file download attemptoffoffoff
142531FILE-EXECUTABLEXOR 0x26 encrypted portable executable file download attemptoffoffoff
142532FILE-EXECUTABLEXOR 0x27 encrypted portable executable file download attemptoffoffoff
142533FILE-EXECUTABLEXOR 0x28 encrypted portable executable file download attemptoffoffoff
142534FILE-EXECUTABLEXOR 0x29 encrypted portable executable file download attemptoffoffoff
142535FILE-EXECUTABLEXOR 0x2a encrypted portable executable file download attemptoffoffoff
142536FILE-EXECUTABLEXOR 0x2b encrypted portable executable file download attemptoffoffoff
142537FILE-EXECUTABLEXOR 0x2c encrypted portable executable file download attemptoffoffoff
142538FILE-EXECUTABLEXOR 0x2d encrypted portable executable file download attemptoffoffoff
142539FILE-EXECUTABLEXOR 0x2e encrypted portable executable file download attemptoffoffoff
142540FILE-EXECUTABLEXOR 0x2f encrypted portable executable file download attemptoffoffoff
142541FILE-EXECUTABLEXOR 0x30 encrypted portable executable file download attemptoffoffoff
142542FILE-EXECUTABLEXOR 0x31 encrypted portable executable file download attemptoffoffoff
142543FILE-EXECUTABLEXOR 0x32 encrypted portable executable file download attemptoffoffoff
142544FILE-EXECUTABLEXOR 0x33 encrypted portable executable file download attemptoffoffoff
142545FILE-EXECUTABLEXOR 0x34 encrypted portable executable file download attemptoffoffoff
142546FILE-EXECUTABLEXOR 0x35 encrypted portable executable file download attemptoffoffoff
142547FILE-EXECUTABLEXOR 0x36 encrypted portable executable file download attemptoffoffoff
142548FILE-EXECUTABLEXOR 0x37 encrypted portable executable file download attemptoffoffoff
142549FILE-EXECUTABLEXOR 0x38 encrypted portable executable file download attemptoffoffoff
142550FILE-EXECUTABLEXOR 0x39 encrypted portable executable file download attemptoffoffoff
142551FILE-EXECUTABLEXOR 0x3a encrypted portable executable file download attemptoffoffoff
142552FILE-EXECUTABLEXOR 0x3b encrypted portable executable file download attemptoffoffoff
142553FILE-EXECUTABLEXOR 0x3c encrypted portable executable file download attemptoffoffoff
142554FILE-EXECUTABLEXOR 0x3d encrypted portable executable file download attemptoffoffoff
142555FILE-EXECUTABLEXOR 0x3e encrypted portable executable file download attemptoffoffoff
142556FILE-EXECUTABLEXOR 0x3f encrypted portable executable file download attemptoffoffoff
142557FILE-EXECUTABLEXOR 0x40 encrypted portable executable file download attemptoffoffoff
142558FILE-EXECUTABLEXOR 0x41 encrypted portable executable file download attemptoffoffoff
142559FILE-EXECUTABLEXOR 0x42 encrypted portable executable file download attemptoffoffoff
142560FILE-EXECUTABLEXOR 0x43 encrypted portable executable file download attemptoffoffoff
142561FILE-EXECUTABLEXOR 0x44 encrypted portable executable file download attemptoffoffoff
142562FILE-EXECUTABLEXOR 0x45 encrypted portable executable file download attemptoffoffoff
142563FILE-EXECUTABLEXOR 0x46 encrypted portable executable file download attemptoffoffoff
142564FILE-EXECUTABLEXOR 0x47 encrypted portable executable file download attemptoffoffoff
142565FILE-EXECUTABLEXOR 0x48 encrypted portable executable file download attemptoffoffoff
142566FILE-EXECUTABLEXOR 0x49 encrypted portable executable file download attemptoffoffoff
142567FILE-EXECUTABLEXOR 0x4a encrypted portable executable file download attemptoffoffoff
142568FILE-EXECUTABLEXOR 0x4b encrypted portable executable file download attemptoffoffoff
142569FILE-EXECUTABLEXOR 0x4c encrypted portable executable file download attemptoffoffoff
142570FILE-EXECUTABLEXOR 0x4d encrypted portable executable file download attemptoffoffoff
142571FILE-EXECUTABLEXOR 0x4e encrypted portable executable file download attemptoffoffoff
142572FILE-EXECUTABLEXOR 0x4f encrypted portable executable file download attemptoffoffoff
142573FILE-EXECUTABLEXOR 0x50 encrypted portable executable file download attemptoffoffoff
142574FILE-EXECUTABLEXOR 0x51 encrypted portable executable file download attemptoffoffoff
142575FILE-EXECUTABLEXOR 0x52 encrypted portable executable file download attemptoffoffoff
142576FILE-EXECUTABLEXOR 0x53 encrypted portable executable file download attemptoffoffoff
142577FILE-EXECUTABLEXOR 0x54 encrypted portable executable file download attemptoffoffoff
142578FILE-EXECUTABLEXOR 0x55 encrypted portable executable file download attemptoffoffoff
142579FILE-EXECUTABLEXOR 0x56 encrypted portable executable file download attemptoffoffoff
142580FILE-EXECUTABLEXOR 0x57 encrypted portable executable file download attemptoffoffoff
142581FILE-EXECUTABLEXOR 0x58 encrypted portable executable file download attemptoffoffoff
142582FILE-EXECUTABLEXOR 0x59 encrypted portable executable file download attemptoffoffoff
142583FILE-EXECUTABLEXOR 0x5a encrypted portable executable file download attemptoffoffoff
142584FILE-EXECUTABLEXOR 0x5b encrypted portable executable file download attemptoffoffoff
142585FILE-EXECUTABLEXOR 0x5c encrypted portable executable file download attemptoffoffoff
142586FILE-EXECUTABLEXOR 0x5d encrypted portable executable file download attemptoffoffoff
142587FILE-EXECUTABLEXOR 0x5e encrypted portable executable file download attemptoffoffoff
142588FILE-EXECUTABLEXOR 0x5f encrypted portable executable file download attemptoffoffoff
142589FILE-EXECUTABLEXOR 0x60 encrypted portable executable file download attemptoffoffoff
142590FILE-EXECUTABLEXOR 0x61 encrypted portable executable file download attemptoffoffoff
142591FILE-EXECUTABLEXOR 0x62 encrypted portable executable file download attemptoffoffoff
142592FILE-EXECUTABLEXOR 0x63 encrypted portable executable file download attemptoffoffoff
142593FILE-EXECUTABLEXOR 0x64 encrypted portable executable file download attemptoffoffoff
142594FILE-EXECUTABLEXOR 0x65 encrypted portable executable file download attemptoffoffoff
142595FILE-EXECUTABLEXOR 0x66 encrypted portable executable file download attemptoffoffoff
142596FILE-EXECUTABLEXOR 0x67 encrypted portable executable file download attemptoffoffoff
142597FILE-EXECUTABLEXOR 0x68 encrypted portable executable file download attemptoffoffoff
142598FILE-EXECUTABLEXOR 0x69 encrypted portable executable file download attemptoffoffoff
142599FILE-EXECUTABLEXOR 0x6a encrypted portable executable file download attemptoffoffoff
142600FILE-EXECUTABLEXOR 0x6b encrypted portable executable file download attemptoffoffoff
142601FILE-EXECUTABLEXOR 0x6c encrypted portable executable file download attemptoffoffoff
142602FILE-EXECUTABLEXOR 0x6d encrypted portable executable file download attemptoffoffoff
142603FILE-EXECUTABLEXOR 0x6e encrypted portable executable file download attemptoffoffoff
142604FILE-EXECUTABLEXOR 0x6f encrypted portable executable file download attemptoffoffoff
142605FILE-EXECUTABLEXOR 0x70 encrypted portable executable file download attemptoffoffoff
142606FILE-EXECUTABLEXOR 0x71 encrypted portable executable file download attemptoffoffoff
142607FILE-EXECUTABLEXOR 0x72 encrypted portable executable file download attemptoffoffoff
142608FILE-EXECUTABLEXOR 0x73 encrypted portable executable file download attemptoffoffoff
142609FILE-EXECUTABLEXOR 0x74 encrypted portable executable file download attemptoffoffoff
142610FILE-EXECUTABLEXOR 0x75 encrypted portable executable file download attemptoffoffoff
142611FILE-EXECUTABLEXOR 0x76 encrypted portable executable file download attemptoffoffoff
142612FILE-EXECUTABLEXOR 0x77 encrypted portable executable file download attemptoffoffoff
142613FILE-EXECUTABLEXOR 0x78 encrypted portable executable file download attemptoffoffoff
142614FILE-EXECUTABLEXOR 0x79 encrypted portable executable file download attemptoffoffoff
142615FILE-EXECUTABLEXOR 0x7a encrypted portable executable file download attemptoffoffoff
142616FILE-EXECUTABLEXOR 0x7b encrypted portable executable file download attemptoffoffoff
142617FILE-EXECUTABLEXOR 0x7c encrypted portable executable file download attemptoffoffoff
142618FILE-EXECUTABLEXOR 0x7d encrypted portable executable file download attemptoffoffoff
142619FILE-EXECUTABLEXOR 0x7e encrypted portable executable file download attemptoffoffoff
142620FILE-EXECUTABLEXOR 0x7f encrypted portable executable file download attemptoffoffoff
142621FILE-EXECUTABLEXOR 0x80 encrypted portable executable file download attemptoffoffoff
142622FILE-EXECUTABLEXOR 0x81 encrypted portable executable file download attemptoffoffoff
142623FILE-EXECUTABLEXOR 0x82 encrypted portable executable file download attemptoffoffoff
142624FILE-EXECUTABLEXOR 0x83 encrypted portable executable file download attemptoffoffoff
142625FILE-EXECUTABLEXOR 0x84 encrypted portable executable file download attemptoffoffoff
142626FILE-EXECUTABLEXOR 0x85 encrypted portable executable file download attemptoffoffoff
142627FILE-EXECUTABLEXOR 0x86 encrypted portable executable file download attemptoffoffoff
142628FILE-EXECUTABLEXOR 0x87 encrypted portable executable file download attemptoffoffoff
142629FILE-EXECUTABLEXOR 0x88 encrypted portable executable file download attemptoffoffoff
142630FILE-EXECUTABLEXOR 0x89 encrypted portable executable file download attemptoffoffoff
142631FILE-EXECUTABLEXOR 0x8a encrypted portable executable file download attemptoffoffoff
142632FILE-EXECUTABLEXOR 0x8b encrypted portable executable file download attemptoffoffoff
142633FILE-EXECUTABLEXOR 0x8c encrypted portable executable file download attemptoffoffoff
142634FILE-EXECUTABLEXOR 0x8d encrypted portable executable file download attemptoffoffoff
142635FILE-EXECUTABLEXOR 0x8e encrypted portable executable file download attemptoffoffoff
142636FILE-EXECUTABLEXOR 0x8f encrypted portable executable file download attemptoffoffoff
142637FILE-EXECUTABLEXOR 0x90 encrypted portable executable file download attemptoffoffoff
142638FILE-EXECUTABLEXOR 0x91 encrypted portable executable file download attemptoffoffoff
142639FILE-EXECUTABLEXOR 0x92 encrypted portable executable file download attemptoffoffoff
142640FILE-EXECUTABLEXOR 0x93 encrypted portable executable file download attemptoffoffoff
142641FILE-EXECUTABLEXOR 0x94 encrypted portable executable file download attemptoffoffoff
142642FILE-EXECUTABLEXOR 0x95 encrypted portable executable file download attemptoffoffoff
142643FILE-EXECUTABLEXOR 0x96 encrypted portable executable file download attemptoffoffoff
142644FILE-EXECUTABLEXOR 0x97 encrypted portable executable file download attemptoffoffoff
142645FILE-EXECUTABLEXOR 0x98 encrypted portable executable file download attemptoffoffoff
142646FILE-EXECUTABLEXOR 0x99 encrypted portable executable file download attemptoffoffoff
142647FILE-EXECUTABLEXOR 0x9a encrypted portable executable file download attemptoffoffoff
142648FILE-EXECUTABLEXOR 0x9b encrypted portable executable file download attemptoffoffoff
142649FILE-EXECUTABLEXOR 0x9c encrypted portable executable file download attemptoffoffoff
142650FILE-EXECUTABLEXOR 0x9d encrypted portable executable file download attemptoffoffoff
142651FILE-EXECUTABLEXOR 0x9e encrypted portable executable file download attemptoffoffoff
142652FILE-EXECUTABLEXOR 0x9f encrypted portable executable file download attemptoffoffoff
142653FILE-EXECUTABLEXOR 0xa0 encrypted portable executable file download attemptoffoffoff
142654FILE-EXECUTABLEXOR 0xa1 encrypted portable executable file download attemptoffoffoff
142655FILE-EXECUTABLEXOR 0xa2 encrypted portable executable file download attemptoffoffoff
142656FILE-EXECUTABLEXOR 0xa3 encrypted portable executable file download attemptoffoffoff
142657FILE-EXECUTABLEXOR 0xa4 encrypted portable executable file download attemptoffoffoff
142658FILE-EXECUTABLEXOR 0xa5 encrypted portable executable file download attemptoffoffoff
142659FILE-EXECUTABLEXOR 0xa6 encrypted portable executable file download attemptoffoffoff
142660FILE-EXECUTABLEXOR 0xa7 encrypted portable executable file download attemptoffoffoff
142661FILE-EXECUTABLEXOR 0xa8 encrypted portable executable file download attemptoffoffoff
142662FILE-EXECUTABLEXOR 0xa9 encrypted portable executable file download attemptoffoffoff
142663FILE-EXECUTABLEXOR 0xaa encrypted portable executable file download attemptoffoffoff
142664FILE-EXECUTABLEXOR 0xab encrypted portable executable file download attemptoffoffoff
142665FILE-EXECUTABLEXOR 0xac encrypted portable executable file download attemptoffoffoff
142666FILE-EXECUTABLEXOR 0xad encrypted portable executable file download attemptoffoffoff
142667FILE-EXECUTABLEXOR 0xae encrypted portable executable file download attemptoffoffoff
142668FILE-EXECUTABLEXOR 0xaf encrypted portable executable file download attemptoffoffoff
142669FILE-EXECUTABLEXOR 0xb0 encrypted portable executable file download attemptoffoffoff
142670FILE-EXECUTABLEXOR 0xb1 encrypted portable executable file download attemptoffoffoff
142671FILE-EXECUTABLEXOR 0xb2 encrypted portable executable file download attemptoffoffoff
142672FILE-EXECUTABLEXOR 0xb3 encrypted portable executable file download attemptoffoffoff
142673FILE-EXECUTABLEXOR 0xb4 encrypted portable executable file download attemptoffoffoff
142674FILE-EXECUTABLEXOR 0xb5 encrypted portable executable file download attemptoffoffoff
142675FILE-EXECUTABLEXOR 0xb6 encrypted portable executable file download attemptoffoffoff
142676FILE-EXECUTABLEXOR 0xb7 encrypted portable executable file download attemptoffoffoff
142677FILE-EXECUTABLEXOR 0xb8 encrypted portable executable file download attemptoffoffoff
142678FILE-EXECUTABLEXOR 0xb9 encrypted portable executable file download attemptoffoffoff
142679FILE-EXECUTABLEXOR 0xba encrypted portable executable file download attemptoffoffoff
142680FILE-EXECUTABLEXOR 0xbb encrypted portable executable file download attemptoffoffoff
142681FILE-EXECUTABLEXOR 0xbc encrypted portable executable file download attemptoffoffoff
142682FILE-EXECUTABLEXOR 0xbd encrypted portable executable file download attemptoffoffoff
142683FILE-EXECUTABLEXOR 0xbe encrypted portable executable file download attemptoffoffoff
142684FILE-EXECUTABLEXOR 0xbf encrypted portable executable file download attemptoffoffoff
142685FILE-EXECUTABLEXOR 0xc0 encrypted portable executable file download attemptoffoffoff
142686FILE-EXECUTABLEXOR 0xc1 encrypted portable executable file download attemptoffoffoff
142687FILE-EXECUTABLEXOR 0xc2 encrypted portable executable file download attemptoffoffoff
142688FILE-EXECUTABLEXOR 0xc3 encrypted portable executable file download attemptoffoffoff
142689FILE-EXECUTABLEXOR 0xc4 encrypted portable executable file download attemptoffoffoff
142690FILE-EXECUTABLEXOR 0xc5 encrypted portable executable file download attemptoffoffoff
142691FILE-EXECUTABLEXOR 0xc6 encrypted portable executable file download attemptoffoffoff
142692FILE-EXECUTABLEXOR 0xc7 encrypted portable executable file download attemptoffoffoff
142693FILE-EXECUTABLEXOR 0xc8 encrypted portable executable file download attemptoffoffoff
142694FILE-EXECUTABLEXOR 0xc9 encrypted portable executable file download attemptoffoffoff
142695FILE-EXECUTABLEXOR 0xca encrypted portable executable file download attemptoffoffoff
142696FILE-EXECUTABLEXOR 0xcb encrypted portable executable file download attemptoffoffoff
142697FILE-EXECUTABLEXOR 0xcc encrypted portable executable file download attemptoffoffoff
142698FILE-EXECUTABLEXOR 0xcd encrypted portable executable file download attemptoffoffoff
142699FILE-EXECUTABLEXOR 0xce encrypted portable executable file download attemptoffoffoff
142700FILE-EXECUTABLEXOR 0xcf encrypted portable executable file download attemptoffoffoff
142701FILE-EXECUTABLEXOR 0xd0 encrypted portable executable file download attemptoffoffoff
142702FILE-EXECUTABLEXOR 0xd1 encrypted portable executable file download attemptoffoffoff
142703FILE-EXECUTABLEXOR 0xd2 encrypted portable executable file download attemptoffoffoff
142704FILE-EXECUTABLEXOR 0xd3 encrypted portable executable file download attemptoffoffoff
142705FILE-EXECUTABLEXOR 0xd4 encrypted portable executable file download attemptoffoffoff
142706FILE-EXECUTABLEXOR 0xd5 encrypted portable executable file download attemptoffoffoff
142707FILE-EXECUTABLEXOR 0xd6 encrypted portable executable file download attemptoffoffoff
142708FILE-EXECUTABLEXOR 0xd7 encrypted portable executable file download attemptoffoffoff
142709FILE-EXECUTABLEXOR 0xd8 encrypted portable executable file download attemptoffoffoff
142710FILE-EXECUTABLEXOR 0xd9 encrypted portable executable file download attemptoffoffoff
142711FILE-EXECUTABLEXOR 0xda encrypted portable executable file download attemptoffoffoff
142712FILE-EXECUTABLEXOR 0xdb encrypted portable executable file download attemptoffoffoff
142713FILE-EXECUTABLEXOR 0xdc encrypted portable executable file download attemptoffoffoff
142714FILE-EXECUTABLEXOR 0xdd encrypted portable executable file download attemptoffoffoff
142715FILE-EXECUTABLEXOR 0xde encrypted portable executable file download attemptoffoffoff
142716FILE-EXECUTABLEXOR 0xdf encrypted portable executable file download attemptoffoffoff
142717FILE-EXECUTABLEXOR 0xe0 encrypted portable executable file download attemptoffoffoff
142718FILE-EXECUTABLEXOR 0xe1 encrypted portable executable file download attemptoffoffoff
142719FILE-EXECUTABLEXOR 0xe2 encrypted portable executable file download attemptoffoffoff
142720FILE-EXECUTABLEXOR 0xe3 encrypted portable executable file download attemptoffoffoff
142721FILE-EXECUTABLEXOR 0xe4 encrypted portable executable file download attemptoffoffoff
142722FILE-EXECUTABLEXOR 0xe5 encrypted portable executable file download attemptoffoffoff
142723FILE-EXECUTABLEXOR 0xe6 encrypted portable executable file download attemptoffoffoff
142724FILE-EXECUTABLEXOR 0xe7 encrypted portable executable file download attemptoffoffoff
142725FILE-EXECUTABLEXOR 0xe8 encrypted portable executable file download attemptoffoffoff
142726FILE-EXECUTABLEXOR 0xe9 encrypted portable executable file download attemptoffoffoff
142727FILE-EXECUTABLEXOR 0xea encrypted portable executable file download attemptoffoffoff
142728FILE-EXECUTABLEXOR 0xeb encrypted portable executable file download attemptoffoffoff
142729FILE-EXECUTABLEXOR 0xec encrypted portable executable file download attemptoffoffoff
142730FILE-EXECUTABLEXOR 0xed encrypted portable executable file download attemptoffoffoff
142731FILE-EXECUTABLEXOR 0xee encrypted portable executable file download attemptoffoffoff
142732FILE-EXECUTABLEXOR 0xef encrypted portable executable file download attemptoffoffoff
142733FILE-EXECUTABLEXOR 0xf0 encrypted portable executable file download attemptoffoffoff
142734FILE-EXECUTABLEXOR 0xf1 encrypted portable executable file download attemptoffoffoff
142735FILE-EXECUTABLEXOR 0xf2 encrypted portable executable file download attemptoffoffoff
142736FILE-EXECUTABLEXOR 0xf3 encrypted portable executable file download attemptoffoffoff
142737FILE-EXECUTABLEXOR 0xf4 encrypted portable executable file download attemptoffoffoff
142738FILE-EXECUTABLEXOR 0xf5 encrypted portable executable file download attemptoffoffoff
142739FILE-EXECUTABLEXOR 0xf6 encrypted portable executable file download attemptoffoffoff
142740FILE-EXECUTABLEXOR 0xf7 encrypted portable executable file download attemptoffoffoff
142741FILE-EXECUTABLEXOR 0xf8 encrypted portable executable file download attemptoffoffoff
142742FILE-EXECUTABLEXOR 0xf9 encrypted portable executable file download attemptoffoffoff
142743FILE-EXECUTABLEXOR 0xfa encrypted portable executable file download attemptoffoffoff
142744FILE-EXECUTABLEXOR 0xfb encrypted portable executable file download attemptoffoffoff
142745FILE-EXECUTABLEXOR 0xfc encrypted portable executable file download attemptoffoffoff
142746FILE-EXECUTABLEXOR 0xfd encrypted portable executable file download attemptoffoffoff
142747FILE-EXECUTABLEXOR 0xfe encrypted portable executable file download attemptoffoffoff
142748FILE-EXECUTABLEXOR 0xff encrypted portable executable file download attemptoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
142458PROTOCOL-DNSISC BIND unexpected DNAME CNAME ordering denial of service attemptoffoffoff
142463FILE-IMAGEFoxit Reader malformed DataSubBlock size attemptoffoffoff
142464FILE-IMAGEFoxit Reader malformed DataSubBlock size attemptoffoffoff
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
142459INDICATOR-COMPROMISEAdobe Reader PDF embedded null JPEG imageoffoffoff
142460INDICATOR-COMPROMISEAdobe Reader PDF embedded null JPEG imageoffoffoff
142466SERVER-OTHERWinRadius long password denial of service attemptoffoffoff
142475FILE-PDFmalformed embedded JPEG2000 image information disclosure attemptoffoffdrop
142476FILE-PDFmalformed embedded JPEG2000 image information disclosure attemptoffoffdrop

Updated Rules:

Updated rules can be found at this link.