Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2018-02-27

This SRU number: 2018-02-26-001
Previous SRU number: 2018-02-22-001

Applies to:

This SEU number: 1804
Previous SEU: 1803

Applies to:

This is the complete list of rules modified in SRU 2018-02-26-001 and SEU 1804.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
110113MALWARE-CNCWin.Trojan.Peacomm command and control propagation detectedoffalertalert
110114MALWARE-CNCWin.Trojan.Peacomm command and control propagation detectedoffalertalert
110184MALWARE-BACKDOORwow 23 runtime detectionoffoffoff
116271MALWARE-CNCWin.Trojan.TDSS.1.Gen keepalive detectionoffoffoff
119029MALWARE-CNCWin.Trojan.PcClient.AI variant outbound connectionoffoffoff
119123MALWARE-CNCDropper Win.Trojan.Cefyns.A variant outbound connectionoffoffoff
119471POLICY-OTHERdnstunnel v0.5 outbound traffic detectedoffoffoff
120120OS-WINDOWSMicrosoft Windows WINS internal communications on network exploit attemptoffoffoff
120233MALWARE-CNCWin.Trojan.Virut variant outbound connectionoffoffoff
121544MALWARE-CNCPossible host infection - excessive DNS queries for .euoffoffoff
121545MALWARE-CNCPossible host infection - excessive DNS queries for .ruoffoffoff
121546MALWARE-CNCPossible host infection - excessive DNS queries for .cnoffoffoff
123115SERVER-MYSQLMySQL/MariaDB client authentication bypass attemptoffoffoff
123381MALWARE-BACKDOORWin.Trojan.Thoper.C runtime detectionoffoffoff
124265MALWARE-OTHERMalicious UA detected on non-standard portoffdropdrop
125907SERVER-WEBAPPPHPmyadmin brute force login attempt - User-Agent User-Agentoffoffoff
127240SERVER-OTHERmultiple vendors IPMI RAKP username brute force attemptoffoffoff
127536APP-DETECTTCP over DNS response attemptoffoffoff
127540APP-DETECTOzymanDNS dns tunneling up attemptoffoffoff
127541APP-DETECTOzymanDNS dns tunneling down attemptoffoffoff
127669APP-DETECTHeyoka outbound communication attemptoffoffoff
127700APP-DETECTNSTX DNS tunnel outbound connection attemptoffoffoff
127929APP-DETECTSplashtop communication attemptoffoffoff
128005MALWARE-CNCWin.Trojan.Kuluoz outbound commandoffdropdrop
128849SERVER-WEBAPPWordPress XMLRPC potential port-scan attemptoffoffoff
12923NETBIOSSMB repeated logon failureoffoffoff
12924NETBIOSSMB-DS repeated logon failureoffoffoff
130802PROTOCOL-SCADAYokogawa CENTUM CS 3000 bkclogserv buffer overflow attemptoffdropdrop
13152SQLsa brute force failed login attemptoffoffoff
131814MALWARE-CNCWin.Trojan.Darkcomet outbound keepalive signal sentoffoffoff
13273SQLsa brute force failed login unicode attemptoffoffoff
133429POLICY-OTHERMicrosoft Windows SMB potential group policy fallback exploit attemptoffoffoff
135029MALWARE-CNCWin.Keylogger.Lotronc variant outbound connectionoffdropdrop
136379POLICY-OTHERdnstunnel v0.5 outbound traffic detectedoffoffoff
136454SERVER-OTHERmultiple products WinExec function remote code execution attemptoffoffoff
137891INDICATOR-OBFUSCATIONDNS tunneling attemptoffoffoff
137892INDICATOR-OBFUSCATIONDNS tunneling attemptoffoffoff
138514MALWARE-CNCWin.Trojan.Sweeper outbound connectionoffdropdrop
138515MALWARE-CNCWin.Trojan.Sweeper outbound connectionoffdropdrop
138516MALWARE-CNCWin.Trojan.Sweeper outbound connectionoffdropdrop
140063OS-LINUXLinux Kernel Challenge ACK provocation attemptoffoffoff
140340MALWARE-CNCWin.Trojan.Cry variant outbound connectionoffdropdrop
140883SERVER-WEBAPPWordPress XMLRPC pingback ddos attemptoffdropdrop
141920SERVER-WEBAPPMcAfee Virus Scan Linux authentication token brute force attemptoffoffoff
142133SERVER-APACHEApache mod_session_crypto padding oracle brute force attemptoffoffoff
142451SERVER-WEBAPPMCA Sistemas ScadaBR index.php brute force login attemptoffoffoff
144434SERVER-APACHEApache HTTP Server possible OPTIONS method memory leak attemptoffoffoff
144651NETBIOSSMB NTLMSSP authentication brute force attemptoffoffoff
14984SQLsa brute force failed login unicode attemptoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
112002PROTOCOL-VOIPBYE floodoffoffoff
112003PROTOCOL-VOIPCANCEL floodoffoffoff
112004PROTOCOL-VOIPINVITE message Content-Length header size of zerooffoffoff
115522SERVER-OTHERActive Directory invalid OID denial of service attempt offoffoff
115578MALWARE-TOOLSSlowloris http DoS tooloffoffoff
119318MALWARE-OTHERDos.Tool.LOIC UDP default U dun goofed attackoffoffoff
119319MALWARE-OTHERDos.Tool.LOIC TCP default U dun goofed attackoffoffoff
119389PROTOCOL-VOIPREGISTER floodoffoffoff
119869MALWARE-TOOLSAnonymous PHP RefRef DoS tooloffoffoff
120138SERVER-OTHERNortel Networks Multiple UNIStim VoIP Products Remote Eavesdrop Attemptoffoffoff
120212SERVER-OTHERSSL CBC encryption mode weakness brute force attemptoffoffoff
120393PROTOCOL-VOIPBYE floodoffoffoff
120394PROTOCOL-VOIPCANCEL floodoffoffoff
120395PROTOCOL-VOIPREGISTER floodoffoffoff
120396PROTOCOL-VOIPINVITE flood attemptoffoffoff
120397PROTOCOL-VOIPINVITE floodoffoffoff
120421PROTOCOL-VOIPINVITE message Content-Length header size of zerooffoffoff
120436MALWARE-TOOLSTHC SSL renegotiation DOS attemptoffoffoff
120437MALWARE-TOOLSTHC SSL renegotiation DOS attemptoffoffoff
120438MALWARE-TOOLSTHC SSL renegotiation DOS attemptoffoffoff
120439MALWARE-TOOLSTHC SSL renegotiation DOS attemptoffoffoff
121092MALWARE-TOOLSJavaScript LOIC attackoffdropdrop
121445SERVER-OTHERvsFTPd denial of service attemptoffoffoff
121513MALWARE-TOOLSHOIC http denial of service attackoffdropdrop
121608PROTOCOL-VOIPDigium Asterisk IAX2 call number denial of serviceoffoffoff
121817PROTOCOL-DNSexcessive queries of type ANY - potential DoSoffoffoff
12273PROTOCOL-IMAPlogin brute force attemptoffoffoff
12274PROTOCOL-POPlogin brute force attemptoffoffoff
12275SERVER-MAILAUTH LOGON brute force attemptoffoffoff
122953MALWARE-TOOLSHulk denial of service attemptoffoffoff
123360SERVER-IIStilde character file name discovery attemptoffoffoff
123998SERVER-OTHERDHCP discover broadcast flood attemptoffoffoff
124395MALWARE-OTHERitsoknoproblembro TCP floodoffoffoff
124396MALWARE-OTHERitsoknoproblembro UDP floodoffoffoff
124908SERVER-MYSQLOracle MySQL user enumeration attemptoffoffoff
125101SERVER-OTHERCisco IOS syslog message flood denial of service attemptoffoffoff
12523SERVER-OTHERBGP spoofed connection reset attemptoffoffoff
125825SERVER-OTHERTLSv1.0 plaintext recovery attemptoffoffoff
125826SERVER-OTHERTLSv1.1 plaintext recovery attemptoffoffoff
125827SERVER-OTHERTLSv1.2 plaintext recovery attemptoffoffoff
125828SERVER-OTHERSSLv3 plaintext recovery attemptoffoffoff
126321NETBIOSSMB named pipe bruteforce attemptoffoffoff
126557SERVER-WEBAPPWordpress brute-force login attemptoffoffoff
126645SERVER-OTHERSSL TLS deflate compression weakness brute force attemptoffoffoff
126759SERVER-OTHERMIT Kerberos libkdb_ldap principal name handling denial of service attemptoffoffoff
126981SERVER-WEBAPPWordPress login denial of service attemptoffoffoff
127225SERVER-OTHERAdobe ColdFusion JRun error page getWriter denial of service attemptoffoffoff
127899PROTOCOL-VOIPPossible SIP OPTIONS service information gathering attemptoffoffoff
127900PROTOCOL-VOIPExcessive number of SIP 4xx responses potential user or password guessing attemptoffoffoff
127901PROTOCOL-VOIPGhost call attack attemptoffoffoff
127902PROTOCOL-VOIPPossible SIP OPTIONS service information gathering attemptoffoffoff
127903PROTOCOL-VOIPGhost call attack attemptoffoffoff
127904PROTOCOL-VOIPExcessive number of SIP 4xx responses potential user or password guessing attemptoffoffoff
127938PROTOCOL-DNSIPv6 host name enumerationoffoffoff
128532MALWARE-TOOLSPyLoris http DoS tooloffoffoff
129362SERVER-OTHERNovell NetWare AFP denial of service attemptoffoffoff
129393SERVER-OTHERntp monlist denial of service attemptoffoffoff
129715SERVER-IISMicrosoft Windows ASP .NET denial of service attemptoffoffoff
130339SERVER-OTHERCisco Catalyst telnet memory leak denial of service attemptoffoffoff
130510SERVER-OTHEROpenSSL SSLv3 heartbeat read overrun attemptoffdropdrop
130511SERVER-OTHEROpenSSL TLSv1 heartbeat read overrun attemptoffdropdrop
130512SERVER-OTHEROpenSSL TLSv1.1 heartbeat read overrun attemptoffdropdrop
130513SERVER-OTHEROpenSSL TLSv1.2 heartbeat read overrun attemptoffdropdrop
130711SERVER-OTHEROpenVPN OpenSSL SSLv3 heartbeat read overrun attemptoffdropdrop
130712SERVER-OTHEROpenVPN OpenSSL SSLv3 heartbeat read overrun attemptoffdropdrop
130713SERVER-OTHEROpenVPN OpenSSL TLSv1 heartbeat read overrun attemptoffdropdrop
130714SERVER-OTHEROpenVPN OpenSSL TLSv1 heartbeat read overrun attemptoffdropdrop
130715SERVER-OTHEROpenVPN OpenSSL TLSv1.1 heartbeat read overrun attemptoffdropdrop
130716SERVER-OTHEROpenVPN OpenSSL TLSv1.1 heartbeat read overrun attemptoffdropdrop
130717SERVER-OTHEROpenVPN OpenSSL TLSv1.2 heartbeat read overrun attemptoffdropdrop
130718SERVER-OTHEROpenVPN OpenSSL TLSv1.2 heartbeat read overrun attemptoffdropdrop
130727SERVER-OTHEROpenVPN OpenSSL SSLv3 heartbeat read overrun attemptoffdropdrop
130728SERVER-OTHEROpenVPN OpenSSL SSLv3 heartbeat read overrun attemptoffdropdrop
130729SERVER-OTHEROpenVPN OpenSSL TLSv1 heartbeat read overrun attemptoffdropdrop
130730SERVER-OTHEROpenVPN OpenSSL TLSv1 heartbeat read overrun attemptoffdropdrop
130731SERVER-OTHEROpenVPN OpenSSL TLSv1.1 heartbeat read overrun attemptoffdropdrop
130732SERVER-OTHEROpenVPN OpenSSL TLSv1.1 heartbeat read overrun attemptoffdropdrop
130733SERVER-OTHEROpenVPN OpenSSL TLSv1.2 heartbeat read overrun attemptoffdropdrop
130734SERVER-OTHEROpenVPN OpenSSL TLSv1.2 heartbeat read overrun attemptoffdropdrop
131082SERVER-OTHERVino VNC multiple client authentication denial of service attemptoffoffoff
131180SERVER-OTHEROpenSSL DTLS handshake recursion denial of service attemptoffoffoff
131181SERVER-OTHEROpenSSL DTLS handshake recursion denial of service attemptoffoffoff
131304SERVER-WEBAPPPocketPAD brute-force login attemptoffoffoff
132204SERVER-OTHERSSLv3 POODLE CBC padding brute force attemptoffoffoff
132205SERVER-OTHERSSLv3 POODLE CBC padding brute force attemptoffoffoff
132381SERVER-OTHEROpenSSL DTLS SRTP extension parsing denial-of-service attemptoffoffoff
132382SERVER-OTHEROpenSSL DTLS SRTP extension parsing denial-of-service attemptoffoffoff
132465SERVER-OTHEROpenSSL TLS large number of session tickets sent - possible dos attemptoffoffoff
132466SERVER-OTHEROpenSSL TLS large number of session tickets sent - possible dos attemptoffoffoff
132467SERVER-OTHEROpenSSL TLS large number of session tickets sent - possible dos attemptoffoffoff
132468SERVER-OTHEROpenSSL TLS large number of session tickets sent - possible dos attemptoffoffoff
132647SERVER-MYSQLOracle MySQL Server InnoDB Memcached plugin resource exhaustion attemptoffoffoff
132648SERVER-MYSQLOracle MySQL Server InnoDB Memcached plugin resource exhaustion attemptoffoffoff
132649SERVER-MYSQLOracle MySQL Server InnoDB Memcached plugin resource exhaustion attemptoffoffoff
132650SERVER-MYSQLOracle MySQL Server InnoDB Memcached plugin resource exhaustion attemptoffoffoff
132651SERVER-MYSQLOracle MySQL Server InnoDB Memcached plugin resource exhaustion attemptoffoffoff
132755SERVER-OTHERTLSv1.0 POODLE CBC padding brute force attemptoffoffoff
132756SERVER-OTHERTLSv1.1 POODLE CBC padding brute force attemptoffoffoff
132757SERVER-OTHERTLSv1.2 POODLE CBC padding brute force attemptoffoffoff
132758SERVER-OTHERTLSv1.0 POODLE CBC padding brute force attemptoffoffoff
132759SERVER-OTHERTLSv1.1 POODLE CBC padding brute force attemptoffoffoff
132760SERVER-OTHERTLSv1.2 POODLE CBC padding brute force attemptoffoffoff
132952SERVER-WEBAPPiCloud Apple ID brute-force login attemptoffoffoff
133583PROTOCOL-DNSISC BIND recursive resolver resource consumption denial of service attemptoffoffoff
133654SERVER-OTHEROpenSSH maxstartup threshold connection exhaustion denial of service attemptoffoffoff
134112SERVER-OTHERNTP mode 6 REQ_NONCE denial of service attemptoffoffoff
134114SERVER-OTHERNTP mode 6 UNSETTRAP denial of service attemptoffoffoff
134213SERVER-WEBAPPWordPress overly large password class-phpass.php denial of service attemptoffoffoff
134288SERVER-OTHERWindows iSCSI target login request Denial of Service attemptoffoffoff
134306SERVER-WEBAPPSubversion HTTP excessive REPORT requests denial of service attemptoffoffoff
134475SERVER-WEBAPPWordpress username enumeration attemptoffoffoff
135406SERVER-APACHEApache HTTP Server mod_status heap buffer overflow attemptoffoffoff
13542SQLSA brute force login attemptoffoffoff
13543SQLSA brute force login attempt TDS v7/8offoffoff
136194POLICY-OTHERBitTorrent distributed reflected denial-of-service attemptoffoffoff
136493SERVER-OTHERSquid snmphandleUDP off-by-one buffer overflow attemptoffoffoff
138622SERVER-OTHERISC BIND malformed control channel authentication message denial of service attemptoffoffoff
142893SERVER-WEBAPPEaton VURemote denial of service attemptoffoffoff
143227PROTOCOL-SCADAIEC 104 force off denial of service attemptoffoffoff
143228PROTOCOL-SCADAIEC 104 force on denial of service attemptoffoffoff
143252PROTOCOL-SCADAIEC 61850 device connection enumeration attemptoffoffoff
143253PROTOCOL-SCADAIEC 61850 virtual manufacturing device domain variable enumeration attemptoffoffoff
143846SERVER-OTHERISC BIND malformed control channel authentication message denial of service attemptoffoffoff
143928PROTOCOL-OTHERNETBIOS Session Service header length field denial of service attemptoffoffoff
145157SERVER-OTHERSSDP M-SEARCH ssdp-all potential amplified distributed denial-of-service attemptoffoffoff
145164POLICY-OTHERRPC Portmapper version 3 dump request attemptoffoffoff
145165POLICY-OTHERRPC Portmapper version 2 dump request attemptoffoffoff
145166POLICY-OTHERRPC Portmapper getstat request attemptoffoffoff
145499SERVER-OTHERISC DHCPD remote denial of service attemptoffoffoff
145568SERVER-SAMBASamba LDAP Server libldb denial of service attemptoffoffoff
145577PROTOCOL-VOIPMr.SIP invite request denial of service attemptoffoffoff
145578PROTOCOL-VOIPMr.SIP options request denial of service attemptoffoffoff
145579PROTOCOL-VOIPMr.SIP subscribe request denial of service attemptoffoffoff
145580PROTOCOL-VOIPMr.SIP invite request denial of service attemptoffoffoff
145581PROTOCOL-VOIPMr.SIP options request denial of service attemptoffoffoff
145582PROTOCOL-VOIPMr.SIP subscribe request denial of service attemptoffoffoff
19622SERVER-OTHERSpiffit UDP denial of service attemptoffoffoff
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
115259PROTOCOL-DNSDNS root query traffic amplification attemptoffoffoff
115260PROTOCOL-DNSDNS root query response traffic amplification attemptoffoffoff
115414PROTOCOL-SCADAOMRON-FINS program area protect clear brute force attemptoffoffoff
120398PROTOCOL-VOIPResponse code 420 Bad Extension response floodoffoffoff
120399PROTOCOL-VOIPResponse code 420 Bad Extension response floodoffoffoff
120400PROTOCOL-VOIPResponse code 415 Unsupported Media Type response floodoffoffoff
120401PROTOCOL-VOIPResponse code 415 Unsupported Media Type response floodoffoffoff
120402PROTOCOL-VOIPResponse code 405 Method Not Allowed response floodoffoffoff
120403PROTOCOL-VOIPResponse code 405 Method Not Allowed response floodoffoffoff
121232SERVER-OTHERRemote Desktop Protocol brute force attemptoffoffoff
121262OS-WINDOWSDCERPC ISystemActivate flood attemptoffoffoff
129314PROTOCOL-SCADAModbus function scanoffoffoff
129315PROTOCOL-SCADAModbus list scanoffoffoff
129316PROTOCOL-SCADAModbus value scanoffoffoff
141060PROTOCOL-SCADAIEC 104 List directoryoffoffoff