Talos has added and modified multiple rules in the deleted, file-other, file-pdf and server-webapp rule sets to provide coverage for emerging threats from these technologies.
For information about Snort Subscriber Rulesets available for purchase, please visit the Snort product page.
This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2983.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:48767 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant payload download attempt (malware-cnc.rules) * 1:48753 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (file-pdf.rules) * 1:48756 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (file-pdf.rules) * 1:48758 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (file-other.rules) * 1:48748 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (file-other.rules) * 1:48755 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (file-other.rules) * 1:48752 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (file-pdf.rules) * 1:48760 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (file-other.rules) * 1:48759 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (file-other.rules) * 1:48763 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (deleted.rules) * 1:48761 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (file-other.rules) * 1:48749 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (file-other.rules) * 1:48765 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48766 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48764 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48762 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (deleted.rules) * 1:48754 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (file-other.rules) * 1:48750 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (file-pdf.rules) * 1:48751 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (file-pdf.rules) * 1:48757 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (file-pdf.rules) * 3:48747 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0751 attack attempt (server-webapp.rules)
* 1:46697 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (file-pdf.rules) * 1:42869 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (file-pdf.rules) * 1:46696 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (file-pdf.rules) * 1:48598 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (file-pdf.rules) * 1:42868 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (file-pdf.rules) * 1:47964 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (file-other.rules) * 1:47963 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (file-other.rules) * 1:48599 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (file-pdf.rules)
This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2990.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:48751 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (file-pdf.rules) * 1:48752 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (file-pdf.rules) * 1:48748 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (file-other.rules) * 1:48767 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant payload download attempt (malware-cnc.rules) * 1:48758 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (file-other.rules) * 1:48754 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (file-other.rules) * 1:48759 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (file-other.rules) * 1:48755 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (file-other.rules) * 1:48760 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (file-other.rules) * 1:48757 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (file-pdf.rules) * 1:48761 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (file-other.rules) * 1:48753 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (file-pdf.rules) * 1:48762 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (deleted.rules) * 1:48750 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (file-pdf.rules) * 1:48749 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (file-other.rules) * 1:48763 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (deleted.rules) * 1:48764 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48765 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48756 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (file-pdf.rules) * 1:48766 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 3:48747 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0751 attack attempt (server-webapp.rules)
* 1:46696 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (file-pdf.rules) * 1:42868 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (file-pdf.rules) * 1:46697 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (file-pdf.rules) * 1:47963 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (file-other.rules) * 1:42869 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (file-pdf.rules) * 1:48599 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (file-pdf.rules) * 1:48598 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (file-pdf.rules) * 1:47964 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (file-other.rules)
This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3000.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:48765 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (snort3-malware-cnc.rules) * 1:48759 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (snort3-file-other.rules) * 1:48767 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant payload download attempt (snort3-malware-cnc.rules) * 1:48764 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (snort3-malware-cnc.rules) * 1:48748 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (snort3-file-other.rules) * 1:48749 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (snort3-file-other.rules) * 1:48766 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (snort3-malware-cnc.rules) * 1:48761 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (snort3-file-other.rules) * 1:48754 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (snort3-file-other.rules) * 1:48758 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (snort3-file-other.rules) * 1:48753 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (snort3-file-pdf.rules) * 1:48751 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (snort3-file-pdf.rules) * 1:48756 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (snort3-file-pdf.rules) * 1:48750 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (snort3-file-pdf.rules) * 1:48755 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (snort3-file-other.rules) * 1:48752 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (snort3-file-pdf.rules) * 1:48760 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (snort3-file-other.rules) * 1:48757 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (snort3-file-pdf.rules) * 1:48763 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (snort3-deleted.rules) * 1:48762 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (snort3-deleted.rules)
* 1:42869 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (snort3-file-pdf.rules) * 1:47963 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (snort3-file-other.rules) * 1:46697 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (snort3-file-pdf.rules) * 1:48598 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (snort3-file-pdf.rules) * 1:42868 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (snort3-file-pdf.rules) * 1:47964 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (snort3-file-other.rules) * 1:46696 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (snort3-file-pdf.rules) * 1:48599 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (snort3-file-pdf.rules)
This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091100.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:48752 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (file-pdf.rules) * 1:48753 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (file-pdf.rules) * 1:48755 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (file-other.rules) * 1:48759 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (file-other.rules) * 1:48749 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (file-other.rules) * 1:48750 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (file-pdf.rules) * 1:48748 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (file-other.rules) * 1:48751 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (file-pdf.rules) * 1:48762 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (deleted.rules) * 1:48754 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (file-other.rules) * 1:48763 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (deleted.rules) * 1:48764 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48765 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48766 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48757 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (file-pdf.rules) * 1:48767 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant payload download attempt (malware-cnc.rules) * 1:48758 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (file-other.rules) * 1:48756 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (file-pdf.rules) * 1:48761 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (file-other.rules) * 1:48760 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (file-other.rules) * 3:48747 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0751 attack attempt (server-webapp.rules)
* 1:46696 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (file-pdf.rules) * 1:42869 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (file-pdf.rules) * 1:42868 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (file-pdf.rules) * 1:47963 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (file-other.rules) * 1:48598 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (file-pdf.rules) * 1:48599 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (file-pdf.rules) * 1:47964 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (file-other.rules) * 1:46697 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (file-pdf.rules)
This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091101.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:48767 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant payload download attempt (malware-cnc.rules) * 1:48752 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (file-pdf.rules) * 1:48753 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (file-pdf.rules) * 1:48757 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (file-pdf.rules) * 1:48756 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (file-pdf.rules) * 1:48748 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (file-other.rules) * 1:48749 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (file-other.rules) * 1:48750 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (file-pdf.rules) * 1:48751 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (file-pdf.rules) * 1:48754 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (file-other.rules) * 1:48761 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (file-other.rules) * 1:48762 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (deleted.rules) * 1:48758 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (file-other.rules) * 1:48763 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (deleted.rules) * 1:48764 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48765 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48766 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48759 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (file-other.rules) * 1:48755 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (file-other.rules) * 1:48760 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (file-other.rules) * 3:48747 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0751 attack attempt (server-webapp.rules)
* 1:46696 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (file-pdf.rules) * 1:46697 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (file-pdf.rules) * 1:47963 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (file-other.rules) * 1:47964 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (file-other.rules) * 1:48598 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (file-pdf.rules) * 1:48599 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (file-pdf.rules) * 1:42868 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (file-pdf.rules) * 1:42869 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (file-pdf.rules)
This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091200.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:48761 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (file-other.rules) * 1:48760 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (file-other.rules) * 1:48759 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (file-other.rules) * 1:48758 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (file-other.rules) * 1:48757 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (file-pdf.rules) * 1:48756 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (file-pdf.rules) * 1:48755 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (file-other.rules) * 1:48754 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (file-other.rules) * 1:48753 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (file-pdf.rules) * 1:48752 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (file-pdf.rules) * 1:48751 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (file-pdf.rules) * 1:48750 <-> ENABLED <-> FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (file-pdf.rules) * 1:48749 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (file-other.rules) * 1:48748 <-> ENABLED <-> FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (file-other.rules) * 1:48767 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant payload download attempt (malware-cnc.rules) * 1:48766 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48765 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48764 <-> ENABLED <-> MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (malware-cnc.rules) * 1:48763 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (deleted.rules) * 1:48762 <-> DISABLED <-> DELETED FILE-PDF Adobe Acrobat Reader AnnotsString memory corruption attempt (deleted.rules) * 3:48747 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0751 attack attempt (server-webapp.rules)
* 1:46696 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (file-pdf.rules) * 1:42869 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (file-pdf.rules) * 1:46697 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA use after free attempt (file-pdf.rules) * 1:47963 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (file-other.rules) * 1:47964 <-> DISABLED <-> FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (file-other.rules) * 1:48598 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (file-pdf.rules) * 1:48599 <-> DISABLED <-> FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (file-pdf.rules) * 1:42868 <-> ENABLED <-> FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (file-pdf.rules)