snort at outlook.com
Thu Jun 7 08:17:11 EDT 2018
I certainly didn’t know this! Excellent research and good call not including the rule.
From: Alex McDonnell <amcdonnell at sourcefire.com>
Sent: Thursday, June 7, 2018 3:03:01 PM
To: Y M
Subject: Re: [Snort-sigs] Win.Backdoor.Joanap
Yaser, we looked at the User-Agent: DavClnt rule and found there was no distinction between the malicious traffic and traffic from word. Looking at blog.didierstevens.com/2017/11/13/webdav-traffic-to-malicious-sites/<http://blog.didierstevens.com/2017/11/13/webdav-traffic-to-malicious-sites/> it seems to be expected fallback behavior. We have decided not to publish this rule.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-sigs