[Snort-sigs] Win.Backdoor.Joanap

Y M snort at outlook.com
Thu Jun 7 08:17:11 EDT 2018


I certainly didn’t know this! Excellent research and good call not including the rule.

Thanks Alex.
YM
________________________________
From: Alex McDonnell <amcdonnell at sourcefire.com>
Sent: Thursday, June 7, 2018 3:03:01 PM
To: Y M
Cc: snort-sigs
Subject: Re: [Snort-sigs] Win.Backdoor.Joanap

Yaser, we looked at the User-Agent: DavClnt rule and found there was no distinction between the malicious traffic and traffic from word. Looking at blog.didierstevens.com/2017/11/13/webdav-traffic-to-malicious-sites/<http://blog.didierstevens.com/2017/11/13/webdav-traffic-to-malicious-sites/> it seems to be expected fallback behavior. We have decided not to publish this rule.

thanks
Alex McDonnell
TALOS
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20180607/3f0748ba/attachment.html>


More information about the Snort-sigs mailing list