Cisco Talos Update for FireSIGHT Management Center

Date: 2019-08-29

This SRU number: 2019-08-29-001
Previous SRU number: 2019-08-26-001

Applies to:

This SEU number: 2061
Previous SEU: 2059

Applies to:

This is the complete list of rules added in SRU 2019-08-29-001 and SEU 2061.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
151309MALWARE-CNCWin.Trojan.Pistacchietto variant outbound connectionoffdropdropdrop
151310FILE-OFFICEMicrosoft Excel ExternSheet record remote code execution attemptoffoffoffdrop
151311FILE-OFFICEMicrosoft Excel ExternSheet record remote code execution attemptoffoffoffdrop
151312SERVER-WEBAPPWSO2 Carbon persistent cross site scripting attemptoffoffoffdrop
151313FILE-OFFICEMicrosoft Office Excel invalid FRTWrapper record integer underflow attemptoffoffoffdrop
151314FILE-OFFICEMicrosoft Office Excel invalid FRTWrapper record integer underflow attemptoffoffoffdrop
151315SERVER-WEBAPPAtlassian Jira ContactAdministrators and SendBulkMail template injection remote code execution attemptoffoffdropdrop
151316SERVER-WEBAPPAtlassian Jira ContactAdministrators and SendBulkMail template injection remote code execution attemptoffoffdropdrop
151317SERVER-WEBAPPAtlassian Jira ContactAdministrators and SendBulkMail template injection remote code execution attemptoffoffdropdrop
151318SERVER-WEBAPPAtlassian Jira ContactAdministrators and SendBulkMail template injection remote code execution attemptoffoffdropdrop
151320MALWARE-CNCWin.Trojan.BlackMoon variant outbound connectionoffdropdropdrop
151326FILE-OFFICEMicrosoft Office Excel DBQueryExt record memory corruption attemptoffoffoffdrop
351331SERVER-WEBAPPTRUFFLEHUNTER TALOS-2019-0888 attack attemptoffoffoffoff
351332SERVER-WEBAPPTRUFFLEHUNTER TALOS-2019-0888 attack attemptoffoffoffoff
151335BROWSER-IEMicrosoft Edge scripting engine uninitialized pointers memory corruption attemptoffoffoffdrop
151336BROWSER-IEMicrosoft Edge scripting engine uninitialized pointers memory corruption attemptoffoffoffdrop
151337MALWARE-CNCUser-Agent known malicious user-agent string - Extenbrooffdropdropdrop
151339INDICATOR-SCANTrend Micro Threat Discovery Appliance logon.cgi authentication attemptoffoffoffdrop
151340SERVER-WEBAPPTrend Micro Threat Discovery Appliance dlp_policy_upload.cgi arbitrary file download attemptoffoffoffdrop
151341MALWARE-CNCUser-Agent known malicious user-agent string - Nemtyoffdropdropdrop
151342MALWARE-CNCUser-Agent known malicious user-agent string - Nemtyoffdropdropdrop
151360MALWARE-CNCWin.Ransomware.LooCipher variant outbound connectionoffdropdropdrop
151361MALWARE-OTHERWin.Ransomware.LooCipher variant download attemptoffdropdropdrop
151362MALWARE-OTHERWin.Ransomware.LooCipher variant download attemptoffdropdropdrop
151363FILE-OFFICEMicrosoft Office Excel TXO and OBJ records parsing stack memory corruption attemptoffoffoffdrop
151364FILE-OFFICEMicrosoft Office Excel TXO and OBJ records parsing stack memory corruption attemptoffoffoffdrop
151368MALWARE-OTHERWin.Backdoor.Agent inbound request attemptoffdropdropdrop
351369OS-WINDOWSMicrosoft Windows RDP DecompressUnchopper integer overflow attemptdropdropdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
151227SERVER-OTHERFreeRADIUS DHCP string options integer underflow attemptoffoffoffdrop
151228SERVER-OTHERFreeRADIUS DHCP string options integer underflow attemptoffoffoffdrop
151229SERVER-OTHERFreeRADIUS DHCP string options integer underflow attemptoffoffoffdrop
151230SERVER-OTHERFreeRADIUS DHCP string options integer underflow attemptoffoffoffdrop
151231SERVER-OTHERFreeRADIUS DHCP string options integer underflow attemptoffoffoffdrop
151232SERVER-OTHERFreeRADIUS DHCP string options integer underflow attemptoffoffoffdrop
151233SERVER-OTHERFreeRADIUS DHCP string options integer underflow attemptoffoffoffdrop
151319SERVER-OTHERMosca MQTT broker regular expression denial of service attemptoffoffoffdrop
151321SERVER-WEBAPPSAP Internet Transaction Server information disclosure attemptoffoffoffdrop
151322SERVER-WEBAPPSAP Internet Transaction Server information disclosure attemptoffoffoffdrop
151323SERVER-WEBAPPSAP Internet Transaction Server information disclosure attemptoffoffoffdrop
151324SERVER-WEBAPPSAP Internet Transaction Server information disclosure attemptoffoffoffdrop
151325SERVER-WEBAPPSAP Internet Transaction Server information disclosure attemptoffoffoffdrop
151327OS-OTHERIntel x64 side-channel analysis information leak attemptoffoffdropdrop
151328OS-OTHERIntel x64 side-channel analysis information leak attemptoffoffdropdrop
151329OS-OTHERIntel x64 side-channel analysis information leak attemptoffoffdropdrop
151330OS-OTHERIntel x64 side-channel analysis information leak attemptoffoffdropdrop
151333SERVER-OTHEROpenSSL TLS record tampering denial of service attemptoffoffoffdrop
151334SERVER-OTHEROpenSSL TLS record tampering denial of service attemptoffoffoffdrop
151338PROTOCOL-TELNETTippingPoint IPS hostname disclosure attemptoffoffoffdrop
151343SERVER-OTHEROpenSSL TLS anomalous non-zero length session ticket in client hellooffoffoffdrop
151344SERVER-OTHEROpenSSL TLS anomalous non-zero length session ticket in client hellooffoffoffdrop
151345SERVER-OTHEROpenSSL TLS anomalous non-zero length session ticket in client hellooffoffoffdrop
151346SERVER-OTHEROpenSSL TLS anomalous non-zero length session ticket in client hellooffoffoffdrop
151347SERVER-OTHEROpenSSL TLS anomalous ascii session ticketoffoffoffdrop
151348SERVER-OTHEROpenSSL TLS anomalous ascii session ticketoffoffoffdrop
151349SERVER-OTHEROpenSSL TLS anomalous ascii session ticketoffoffoffdrop
151350SERVER-OTHEROpenSSL TLS anomalous ascii session ticketoffoffoffdrop
151351SERVER-OTHEROpenSSL TLS anomalous ascii client session ticketoffoffoffdrop
151352SERVER-OTHEROpenSSL TLS anomalous ascii client session ticketoffoffoffdrop
151353SERVER-OTHEROpenSSL TLS anomalous ascii client session ticketoffoffoffdrop
151354SERVER-OTHEROpenSSL TLS anomalous ascii client session ticketoffoffoffdrop
351355SERVER-WEBAPPCisco IOS XE REST API information disclosure attemptoffdropdropdrop
151356SERVER-OTHEROpenSSL DTLS duplicate record denial of service attemptoffoffoffdrop
151357SERVER-OTHEROpenSSL DTLS duplicate record denial of service attemptoffoffoffdrop
151358SERVER-OTHEROpenSSL DTLS duplicate record denial of service attemptoffoffoffdrop
151359SERVER-OTHEROpenSSL DTLS duplicate record denial of service attemptoffoffoffdrop
351365SERVER-WEBAPPCisco NX-OS Software NX-API denial of service attemptoffoffoffdrop
351366SERVER-WEBAPPCisco NX-OS Software NX-API denial of service attemptoffoffoffdrop
351367SERVER-WEBAPPCisco NX-OS Software NX-API denial of service attemptoffoffoffdrop