* Talos combines our security experts from TRAC, SecApps, and VRT teams.
This SRU number: 2017-11-20-002
Previous SRU number: 2017-11-15-001
Applies to:
This SEU number: 1760
Previous SEU: 1758
Applies to:
This is the complete list of rules added in SRU 2017-11-20-002 and SEU 1760.
The format of the file is:
GID - SID - Rule Group - Rule Message - Policy State
The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.
The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.
Note: Unless stated explicitly, the rules are for the series of products listed above.
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 44886 | BLACKLIST | User-Agent known malicious user-agent string - Win.Trojan.Volgmer | off | drop | drop |
1 | 44887 | FILE-FLASH | Adobe Flash Player bitmap hitTest integer overflow attempt | off | drop | drop |
1 | 44888 | FILE-FLASH | Adobe Flash Player bitmap hitTest integer overflow attempt | off | drop | drop |
1 | 44889 | BLACKLIST | User-Agent known malicious user-agent string - WidgiToolbar | off | drop | drop |
1 | 44890 | SERVER-OTHER | CouchDB remote privilege escalation attempt | off | off | drop |
1 | 44891 | FILE-FLASH | Adobe Flash Player determinePreferredLocales memory corruption attempt | off | drop | drop |
1 | 44892 | FILE-FLASH | Adobe Flash Player determinePreferredLocales memory corruption attempt | off | drop | drop |
1 | 44893 | FILE-OTHER | Adobe Professional EMF out of bounds read attempt | off | off | drop |
1 | 44894 | FILE-OTHER | Adobe Professional EMF out of bounds read attempt | off | off | drop |
1 | 44895 | MALWARE-CNC | Win.Trojan.CoinMiner inbound request attempt | off | drop | drop |
1 | 44896 | MALWARE-CNC | Win.Trojan.CoinMiner outbound request attempt | off | drop | drop |
1 | 44897 | MALWARE-CNC | Win.Trojan.CoinMiner outbound request attempt | off | drop | drop |
1 | 44898 | MALWARE-CNC | Win.Trojan.CoinMiner outbound request attempt | off | drop | drop |
1 | 44899 | MALWARE-CNC | Win.Trojan.CoinMiner inbound request attempt | off | drop | drop |
1 | 44900 | FILE-PDF | Adobe Reader PDF embedded javascript events use after free attempt | off | drop | drop |
1 | 44901 | FILE-PDF | Adobe Reader PDF embedded javascript events use after free attempt | off | drop | drop |
1 | 44902 | FILE-FLASH | Adobe Flash Player PSDK Metadata memory corruption attempt | off | drop | drop |
1 | 44903 | FILE-FLASH | Adobe Flash Player PSDK Metadata memory corruption attempt | off | drop | drop |
1 | 44904 | FILE-PDF | Adobe Acrobat untrusted pointer dereference attempt | off | off | off |
1 | 44905 | FILE-PDF | Adobe Acrobat untrusted pointer dereference attempt | off | off | off |
1 | 44906 | FILE-PDF | Adobe Acrobat Reader javscript use after free attempt | off | off | off |
1 | 44907 | FILE-PDF | Adobe Acrobat Reader javscript use after free attempt | off | off | off |
3 | 44908 | FILE-OTHER | KeyView SDK WordPerfect parsing stack buffer overflow attempt | off | off | drop |
3 | 44909 | FILE-OTHER | KeyView SDK WordPerfect parsing stack buffer overflow attempt | off | off | drop |
3 | 44910 | SERVER-OTHER | Altiris Express Server Engine stack buffer overflow attempt | off | off | drop |
1 | 44911 | MALWARE-CNC | Osx.Trojan.Fruitfly variant outbound connection detected | off | drop | drop |
1 | 44912 | FILE-IMAGE | Adobe Acrobat Pro invalid APP13 marker size attempt | off | drop | drop |
1 | 44913 | FILE-IMAGE | Adobe Acrobat Pro invalid APP13 marker size attempt | off | drop | drop |
1 | 44914 | FILE-PDF | Adobe Acrobat Reader PrintParams out of bounds array index attempt | off | off | off |
1 | 44915 | FILE-PDF | Adobe Acrobat Reader PrintParams out of bounds array index attempt | off | off | off |
1 | 44916 | SERVER-WEBAPP | ManageEngine Applications Manager GraphicalView.do SQL injection attempt | off | off | drop |
1 | 44917 | SERVER-WEBAPP | ManageEngine Applications Manager GraphicalView.do SQL injection attempt | off | off | drop |
1 | 44918 | SERVER-WEBAPP | ManageEngine Applications Manager GraphicalView.do SQL injection attempt | off | off | drop |
1 | 44919 | FILE-OTHER | Adobe Acrobat Pro EmfPlusRectF out of bounds read attempt | off | off | off |
1 | 44920 | FILE-OTHER | Adobe Acrobat Pro EmfPlusRectF out of bounds read attempt | off | off | off |
1 | 44921 | SERVER-WEBAPP | ManageEngine Applications Manager manageApplications.do SQL injection attempt | off | off | drop |
1 | 44922 | SERVER-WEBAPP | ManageEngine Applications Manager manageApplications.do SQL injection attempt | off | off | drop |
1 | 44923 | FILE-OTHER | Adobe Acrobat EMF Bezier curve out of bounds read attempt | off | off | drop |
1 | 44924 | FILE-OTHER | Adobe Acrobat EMF Bezier curve out of bounds read attempt | off | off | drop |
1 | 44929 | FILE-IMAGE | Adobe Acrobat Pro EMF out of bounds write attempt | off | drop | drop |
1 | 44930 | FILE-IMAGE | Adobe Acrobat Pro EMF out of bounds write attempt | off | drop | drop |
1 | 44931 | FILE-OTHER | Adobe Acrobat Pro XPS file embedded JPEG invalid SOS data memory corruption attempt | off | off | off |
1 | 44932 | FILE-OTHER | Adobe Acrobat Pro XPS file embedded JPEG invalid SOS data memory corruption attempt | off | off | off |
1 | 44933 | FILE-PDF | Adobe Acrobat Reader untrusted pointer dereference attempt | off | off | drop |
1 | 44934 | FILE-PDF | Adobe Acrobat Reader untrusted pointer dereference attempt | off | off | drop |
1 | 44935 | FILE-OTHER | Adobe Acrobat Pro XPS out of bounds read attempt | off | off | off |
1 | 44936 | FILE-OTHER | Adobe Acrobat Pro XPS out of bounds read attempt | off | off | off |
1 | 44937 | FILE-OTHER | Adobe Acrobat EMFPlus out of bounds buffer overflow attempt | off | off | drop |
1 | 44938 | FILE-OTHER | Adobe Acrobat EMFPlus out of bounds buffer overflow attempt | off | off | drop |
1 | 44939 | FILE-PDF | Adobe Acrobat field dictionary value Unicode buffer overflow attempt | off | drop | drop |
1 | 44940 | FILE-PDF | Adobe Acrobat field dictionary value Unicode buffer overflow attempt | off | drop | drop |
1 | 44943 | MALWARE-CNC | Win.Trojan.FallChill variant outbound connection | off | drop | drop |
1 | 44944 | MALWARE-CNC | Win.Trojan.FallChill variant outbound connection | off | drop | drop |
1 | 44945 | MALWARE-CNC | Win.Trojan.FallChill variant outbound connection | off | drop | drop |
1 | 44946 | MALWARE-CNC | Win.Trojan.FallChill variant outbound connection | off | drop | drop |
1 | 44947 | FILE-PDF | Adobe Acrobat Reader double free attempt | off | off | off |
1 | 44948 | FILE-PDF | Adobe Acrobat Reader double free attempt | off | off | off |
1 | 44949 | FILE-PDF | Acrobat TrueTypeFont file out of bounds read attempt | off | drop | drop |
1 | 44950 | FILE-PDF | Acrobat TrueTypeFont file out of bounds read attempt | off | drop | drop |
1 | 44951 | FILE-FLASH | Adobe Flash Player Primetime SDK use after free attempt | off | off | drop |
1 | 44952 | FILE-FLASH | Adobe Flash Player Primetime SDK use after free attempt | off | off | drop |
1 | 44953 | FILE-OTHER | Adobe Acrobat EMF out of bounds buffer overflow attempt | off | off | drop |
1 | 44954 | FILE-OTHER | Adobe Acrobat EMF out of bounds buffer overflow attempt | off | off | drop |
1 | 44955 | FILE-PDF | Adobe Acrobat Reader JavaScript infinite recursion heap overflow attempt | off | drop | drop |
1 | 44956 | FILE-PDF | Adobe Acrobat Reader JavaScript infinite recursion heap overflow attempt | off | drop | drop |
1 | 44957 | FILE-PDF | Adobe Acrobat malformed XObject use after free attempt | off | off | off |
1 | 44958 | FILE-PDF | Adobe Acrobat malformed XObject use after free attempt | off | off | off |
1 | 44959 | FILE-IMAGE | Adobe Acrobat TIFF malformed YCbCrCoefficients values memory corruption attempt | off | drop | drop |
1 | 44960 | FILE-IMAGE | Adobe Acrobat TIFF malformed YCbCrCoefficients values memory corruption attempt | off | drop | drop |
1 | 44961 | FILE-PDF | Adobe Acrobat Reader untrusted pointer dereference attempt | off | off | drop |
1 | 44962 | FILE-PDF | Adobe Acrobat Reader untrusted pointer dereference attempt | off | off | drop |
1 | 44963 | FILE-FLASH | Adobe Flash Player tvsdk object use after free attempt | off | drop | drop |
1 | 44964 | FILE-FLASH | Adobe Flash Player tvsdk object use after free attempt | off | drop | drop |
1 | 44965 | FILE-OTHER | Adobe Acrobat Pro security bypass attempt | off | off | drop |
1 | 44966 | FILE-OTHER | Adobe Acrobat Pro security bypass attempt | off | off | drop |
1 | 44967 | FILE-PDF | Acrobat malformed html tag out of bounds read attempt | off | drop | drop |
1 | 44968 | FILE-PDF | Acrobat malformed html tag out of bounds read attempt | off | drop | drop |
1 | 44969 | FILE-IMAGE | Adobe Acrobat Pro EMF EmfPlusFont memory corruption attempt | off | drop | drop |
1 | 44970 | FILE-IMAGE | Adobe Acrobat Pro EMF EmfPlusFont memory corruption attempt | off | drop | drop |
1 | 44971 | SERVER-OTHER | QNAP transcode server command injection attempt | off | off | off |
1 | 44972 | MALWARE-CNC | Win.Trojan.Ramnit variant outbound connection attempt | off | drop | drop |
1 | 44973 | MALWARE-CNC | Win.Trojan.Ramnit variant outbound connection attempt | off | drop | drop |
1 | 44975 | MALWARE-CNC | Php.Dropper.Mayhem cnc communication attempt | off | drop | drop |
1 | 44976 | FILE-PDF | Adobe Reader ActualText attribute type confusion attempt | off | off | drop |
1 | 44977 | FILE-PDF | Adobe Reader ActualText attribute type confusion attempt | off | off | drop |
1 | 44978 | BROWSER-FIREFOX | Mozilla Firefox browser engine memory corruption attempt | off | off | off |
1 | 44981 | MALWARE-OTHER | Win.Ransomware.Kristina encryption over SMB attempt | off | drop | drop |
1 | 44982 | MALWARE-OTHER | Win.Ransomware.Kristina encryption over SMB attempt | off | drop | drop |
1 | 44983 | FILE-OTHER | Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt | off | drop | drop |
1 | 44984 | FILE-OTHER | Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt | off | drop | drop |
1 | 44987 | FILE-PDF | Adobe Acrobat PDF font character encoding out of bounds write attempt | off | drop | drop |
1 | 44988 | FILE-PDF | Adobe Acrobat PDF font character encoding out of bounds write attempt | off | drop | drop |
1 | 44989 | FILE-OFFICE | Microsoft Office Equation Editor object with automatic execution embedded in RTF attempt | off | drop | drop |
1 | 44990 | FILE-OFFICE | Microsoft Office Equation Editor object with automatic execution embedded in RTF attempt | off | drop | drop |
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 44925 | FILE-PDF | Adobe Acrobat thermometer object untrusted pointer dereference attempt | off | drop | drop |
1 | 44926 | FILE-PDF | Adobe Acrobat thermometer object untrusted pointer dereference attempt | off | drop | drop |
1 | 44974 | SERVER-OTHER | Cisco IOS Smart Install identification attempt | off | off | off |
1 | 44979 | FILE-PDF | Foxit Reader util printf information disclosure attempt | off | off | off |
1 | 44980 | FILE-PDF | Foxit Reader util printf information disclosure attempt | off | off | off |
1 | 44985 | SERVER-OTHER | Galil RIO-47100 denial of service attempt | off | off | off |
3 | 44986 | SERVER-OTHER | TRUFFLEHUNTER TALOS-2017-0486 attack attempt | off | off | off |
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 44927 | FILE-OTHER | Adobe Acrobat Pro WebCapture out of bounds read attempt | off | drop | drop |
1 | 44928 | FILE-OTHER | Adobe Acrobat Pro WebCapture out of bounds read attempt | off | drop | drop |
1 | 44941 | FILE-OTHER | Adobe Acrobat Reader FDF file security bypass attempt | off | off | off |
1 | 44942 | FILE-OTHER | Adobe Acrobat Reader FDF file security bypass attempt | off | off | off |
Updated rules can be found at this link.