I certainly didnít know this! Excellent research and good call not including the rule.

Thanks Alex.
YM

From: Alex McDonnell <amcdonnell@sourcefire.com>
Sent: Thursday, June 7, 2018 3:03:01 PM
To: Y M
Cc: snort-sigs
Subject: Re: [Snort-sigs] Win.Backdoor.Joanap
 
Yaser, we looked at the User-Agent: DavClnt rule and found there was no distinction between the malicious traffic and traffic from word. Looking at blog.didierstevens.com/2017/11/13/webdav-traffic-to-malicious-sites/ it seems to be expected fallback behavior. We have decided not to publish this rule. 

thanks
Alex McDonnell
TALOS