[Snort-sigs] SID 39379 Norton Antivirus ASPack

Alex McDonnell amcdonnell at ...435...
Mon Feb 13 15:11:47 EST 2017


This is a Shared Object rule that is detecting CVE-2016-2208 that was
published in https://bugs.chromium.org/p/project-zero/issues/detail?id=820

Thanks
Alex McDonnell
TALOS

On Mon, Feb 13, 2017 at 3:01 PM, Charlie Dyer <charlierwdyer at ...2420...>
wrote:

> Hello list
>
> Could anyone shed light on the rule 39379?
>
> I can't see any content matching, it simply alerts on any file that is an
> executable being downloaded, is that right?
> If so, what has this got to do with Norton Antivirus?
>
> Many thanks in advance.
>
> Charlie
>
> ------------------------------------------------------------
> ------------------
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, SlashDot.org! http://sdm.link/slashdot
> _______________________________________________
> Snort-sigs mailing list
> Snort-sigs at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/snort-sigs
>
> http://www.snort.org
>
> Please visit http://blog.snort.org for the latest news about Snort!
>
> Visit the Snort.org to subscribe to the official Snort ruleset, make sure
> to stay up to date to catch the most <a href="
> https://snort.org/downloads/#rule-downloads">emerging threats</a>!
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20170213/3f43a984/attachment.html>


More information about the Snort-sigs mailing list