Cisco Talos Update for FireSIGHT Management Center

Date: 2018-07-19

This SRU number: 2018-07-19-001
Previous SRU number: 2018-07-16-001

Applies to:

This SEU number: 1885
Previous SEU: 1883

Applies to:

This is the complete list of rules added in SRU 2018-07-19-001 and SEU 1885.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
147236MALWARE-CNCUnix.Trojan.Prowli variant outbound connectionoffdropdropdrop
147237FILE-OTHERAdobe Acrobat Pro XPS out-of-bounds read attemptoffdropdropdrop
147238FILE-OTHERAdobe Acrobat Pro XPS out-of-bounds read attemptoffdropdropdrop
147239FILE-PDFAdobe Acrobat Reader U3D data stream heap overflow attemptoffoffdropdrop
147240FILE-PDFAdobe Acrobat Reader U3D data stream heap overflow attemptoffoffdropdrop
147241MALWARE-CNCWin.Trojan.Mylobot additional payload downloadoffdropdropdrop
147242MALWARE-CNCWin.Trojan.Mylobot additional payload downloadoffdropdropdrop
147243MALWARE-CNCWin.Trojan.Mylobot inbound connectionoffdropdropdrop
147244MALWARE-CNCWin.Malware.Ramnit outbound REGISTER_BOT beaconoffdropdropdrop
147247FILE-IMAGEAdobe Acrobat Pro crafted GIF file out-of-bounds read attemptoffoffdropdrop
147248FILE-IMAGEAdobe Acrobat Pro crafted GIF file out-of-bounds read attemptoffoffdropdrop
147251FILE-OTHERAdobe Acrobat Pro use after free attemptoffoffoffoff
147252FILE-OTHERAdobe Acrobat Pro use after free attemptoffoffoffoff
147253POLICY-OTHERcryptomining javascript client detectedoffdropdropdrop
147254FILE-OTHERMicrosoft Excel malicious CSV code execution attemptoffoffdropdrop
147255FILE-OTHERMicrosoft Excel malicious CSV code execution attemptoffoffdropdrop
147256FILE-OTHERMicrosoft Excel malicious CSV code execution attemptoffoffdropdrop
147257FILE-OTHERMicrosoft Excel malicious CSV code execution attemptoffoffdropdrop
147258FILE-OTHERMicrosoft Excel malicious CSV code execution attemptoffoffdropdrop
147259FILE-OTHERMicrosoft Excel malicious CSV code execution attemptoffoffdropdrop
147260FILE-OTHERMicrosoft Excel malicious CSV code execution attemptoffoffdropdrop
147261FILE-OTHERMicrosoft Excel malicious CSV code execution attemptoffoffdropdrop
147262FILE-OTHERMicrosoft Excel malicious CSV code execution attemptoffoffdropdrop
147263FILE-OTHERMicrosoft Excel malicious CSV code execution attemptoffoffdropdrop
147264MALWARE-CNCWin.Trojan.ICLoader outbound connectionoffdropdropdrop
147265MALWARE-CNCWin.Trojan.ICLoader outbound connectionoffdropdropdrop
147266FILE-OTHERAdobe Acrobat Pro out-of-bounds read attemptoffoffoffoff
147267FILE-OTHERAdobe Acrobat Pro out-of-bounds read attemptoffoffoffoff
147268FILE-OTHERAdobe Acrobat Pro out-of-bounds read attemptoffoffoffoff
147269FILE-OTHERAdobe Acrobat Pro out-of-bounds read attemptoffoffoffoff
147270FILE-PDFAdobe Reader JavaScript XSL value-of select transformation out-of-bounds write attemptoffoffdropdrop
147271FILE-PDFAdobe Reader JavaScript XSL value-of select transformation out-of-bounds write attemptoffoffdropdrop
147274FILE-OTHERAdobe Acrobat Pro out-of-bounds read attemptoffoffoffoff
147275FILE-OTHERAdobe Acrobat Pro out-of-bounds read attemptoffoffoffoff
147276FILE-OTHERAdobe Acrobat Pro XPS file PPDoc out-of-bounds read attemptoffoffdropdrop
147277FILE-OTHERAdobe Acrobat Pro XPS file PPDoc out-of-bounds read attemptoffoffdropdrop
147278MALWARE-OTHERWin.Ransomware.Gandcrab variant network share encryption attemptoffdropdropdrop
147279FILE-OTHERAdobe Acrobat Pro out-of-bounds read attemptoffoffoffoff
147280FILE-OTHERAdobe Acrobat Pro out-of-bounds read attemptoffoffoffoff
347281SERVER-OTHERCisco SD-WAN Solution default login attemptoffoffdropdrop
347282SERVER-OTHERCisco SD-WAN Solution default login attemptoffoffdropdrop
147283FILE-OTHERAdobe Reader HTML to PDF conversion getMatchedCSSRules use-after-free attemptoffoffdropdrop
147284FILE-OTHERAdobe Reader HTML to PDF conversion getMatchedCSSRules use-after-free attemptoffoffdropdrop
347285SERVER-OTHERCisco Policy Suite interface unauthenticated access attemptoffoffdropdrop
347286SERVER-OTHERCisco Policy Suite interface unauthenticated access attemptoffoffdropdrop
147287FILE-PDFAdobe Reader JavaScript XSLT parsing out-of-bounds read attemptoffoffdropdrop
147288FILE-PDFAdobe Reader JavaScript XSLT parsing out-of-bounds read attemptoffoffdropdrop
147289FILE-PDFAdobe Reader JavaScript exportAsFDFStr out-of-bounds write attemptoffoffdropdrop
147290FILE-PDFAdobe Reader JavaScript exportAsFDFStr out-of-bounds write attemptoffoffdropdrop
147291BROWSER-IEMicrosoft Internet Explorer CTreePos type confusion attemptoffdropdropdrop
147292BROWSER-IEMicrosoft Internet Explorer CTreePos type confusion attemptoffdropdropdrop
147293BROWSER-IEMicrosoft Internet Explorer CTreePos type confusion attemptoffdropdropdrop
147294BROWSER-IEMicrosoft Internet Explorer CTreePos type confusion attemptoffdropdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
147245FILE-OTHERAdobe Acrobat Pro XPS TTF out-of-bounds read attemptoffoffoffdrop
147246FILE-OTHERAdobe Acrobat Pro XPS TTF out-of-bounds read attemptoffoffoffdrop
147249FILE-OTHERAdobe Acrobat Pro XPS out-of-bounds read attemptoffoffoffdrop
147250FILE-OTHERAdobe Acrobat Pro XPS out-of-bounds read attemptoffoffoffdrop
347272OS-OTHERDHCPv6 flood denial of service attemptoffoffdropoff
347273OS-OTHERDHCPv6 flood denial of service attemptoffoffdropoff