Cisco Talos Update for FireSIGHT Management Center

Date: 2018-04-19

This SRU number: 2018-04-18-001
Previous SRU number: 2018-04-16-001

Applies to:

This SEU number: 1836
Previous SEU: 1835

Applies to:

This is the complete list of rules added in SRU 2018-04-18-001 and SEU 1836.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
146347SERVER-WEBAPPMediaWiki index.php rs cross site scripting attemptoffoffoffoff
146348SERVER-WEBAPPNetIQ Access Manager Identity Server directory traversal attemptoffdropdropdrop
146349SERVER-WEBAPPNetIQ Access Manager Identity Server directory traversal attemptoffdropdropdrop
146350SERVER-WEBAPPNetIQ Access Manager Identity Server directory traversal attemptoffdropdropdrop
146351BROWSER-PLUGINSMitsubishi EZPcAut220 ActiveX clsid access attemptoffoffoffoff
146352BROWSER-PLUGINSMitsubishi EZPcAut220 ActiveX clsid access attemptoffoffoffoff
146353SERVER-WEBAPPManageEngine ServiceDesk download-file directory traversal attemptoffoffoffoff
146354SERVER-WEBAPPManageEngine ServiceDesk download-file directory traversal attemptoffoffoffoff
146355SERVER-WEBAPPManageEngine ServiceDesk download-file directory traversal attemptoffoffoffoff
146356MALWARE-CNCAndr.Trojan.Wroba outbound connectionoffdropdropoff
146357MALWARE-CNCAndr.Trojan.Wroba outbound connectionoffdropdropoff
146358MALWARE-CNCAndr.Trojan.Wroba outbound connectionoffdropdropoff
146359MALWARE-CNCAndr.Trojan.Wroba outbound connectionoffdropdropoff
146360MALWARE-CNCAndr.Trojan.Wroba outbound connectionoffdropdropoff
146361MALWARE-CNCAndr.Trojan.Wroba outbound connectionoffdropdropoff
146362MALWARE-CNCAndr.Trojan.Wroba outbound connectionoffdropdropoff
146363MALWARE-CNCAndr.Trojan.Wroba outbound connectionoffdropdropoff
146364MALWARE-CNCAndr.Trojan.Wroba outbound connectionoffdropdropoff
146368MALWARE-BACKDOORJSP Web shell upload attemptoffoffdropdrop
146369MALWARE-BACKDOORJSP Web shell access attemptoffoffdropdrop
146376SERVER-OTHERlibgd heap-overflow attemptoffoffdropdrop
146377SERVER-OTHERlibgd heap-overflow attemptoffoffdropdrop
146378MALWARE-CNCWin.Trojan.Dropper variant outbound connectionoffdropdropdrop
146379SERVER-WEBAPPAfian FileRun SQL injection attemptoffoffdropdrop
146380SERVER-WEBAPPAfian FileRun SQL injection attemptoffoffdropdrop
146383SERVER-OTHERMicro Focus Operations Orchestration information disclosure attemptoffoffoffoff
146384BROWSER-IEInternet Explorer URL file remote code execution attempt detectedoffdropdropdrop
146385BROWSER-IEInternet Explorer URL file remote code execution attempt detectedoffdropdropdrop
346386SERVER-WEBAPPCisco IOS XE Web UI arbitrary file write attemptoffoffdropdrop
346390SERVER-WEBAPPTRUFFLEHUNTER TALOS-2018-0577 attack attemptoffoffoffoff
346391SERVER-WEBAPPTRUFFLEHUNTER TALOS-2018-0577 attack attemptoffoffoffoff
346392SERVER-WEBAPPTRUFFLEHUNTER TALOS-2018-0577 attack attemptoffoffoffoff
346395SERVER-WEBAPPTRUFFLEHUNTER TALOS-2018-0578 attack attemptoffoffoffoff
146396FILE-EXECUTABLEWin.Ransomware.Rapid download attemptoffdropdropdrop
146397FILE-EXECUTABLEWin.Ransomware.Rapid download attemptoffdropdropdrop
146398BROWSER-OTHERMozilla Firefox table object integer underflowoffoffoffoff
146399BROWSER-OTHERMozilla Firefox table object integer underflowoffoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
146365PUA-OTHERCoinHive Miner client detectedoffdropdropdrop
146366PUA-OTHERCryptoNight webassembly download attemptoffdropdropoff
146367FILE-IDENTIFYWebAssembly file download detectedoffoffoffoff
146370PUA-OTHERMoonify Miner client detectedoffdropdropdrop
146371PUA-OTHERMoonify TLS server hello attemptoffdropdropdrop
146372PUA-OTHERMoonify TLS client hello attemptoffdropdropdrop
146373PROTOCOL-OTHERCLDAP potential reflected distributed denial of service attemptoffoffoffoff
146374PROTOCOL-OTHERCLDAP potential reflected distributed denial of service attemptoffoffoffoff
146375SERVER-OTHERDualDesk v20 Proxy.exe long string denial of service attemptoffoffoffoff
146382SERVER-OTHERMicro Focus Operations Orchestration denial of service attemptoffoffoffoff
146387SERVER-OTHERMultiple Vendors NTP zero-origin timestamp denial of service attemptoffoffoffoff
346388FILE-OTHERTRUFFLEHUNTER TALOS-2018-0579 attack attemptoffoffdropdrop
346389FILE-OTHERTRUFFLEHUNTER TALOS-2018-0579 attack attemptoffoffdropdrop
146393FILE-IDENTIFYWebAssembly file detectedoffoffoffoff
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
146381INDICATOR-COMPROMISEPotential data exfiltration through Google form submissionoffoffoffoff
146394FILE-IDENTIFYWebAssembly file attachment detectedoffoffoffoff