Antivirus Content Updates Flashcards
What is included in the Antivirus packages?
- antivirus signatures
- Spyware DNS C2 Signatures
- Spyware Autogen C2 Signatures
- IP Malicious IP feed
- IP Suspicious IP feed
- IP Bulletproof IP feed
- IP Tor exit IP feed
includes new and old
What is the difference between Spyware DNS C2 Signatures and Spyware Autogen C2 Signatures?
DNS C2 Signatures rely on the analysis of DNS queries, Autogen C2 Signatures analyze the payload of the communication, allowing them to detect C2 traffic even when the domain or IP address of the C2 server is not previously known
What are Spyware DNS C2 Signatures designed to do?
detect outbound C2 communication by monitoring DNS requests
When do Spyware DNS C2 Signatures kick in?
when compromised hosts attempt to resolve domain names associated with known malicious command-and-control servers
Based on what do Spyware Autogen C2 Signatures detect malware?
based on payload
What is the main capability of Spyware Autogen C2 Signatures?
detect C2 communications with C2 hosts that are unknown or change rapidly
What are Spyware Autogen C2 Signatures particularly effective in?
identifying malware that employs dynamic domain generation algorithms (DGAs) or uses previously unknown C2 domains for communication
How are Spyware Autogen C2 Signatures generated?
automatically
What are the 3 main categories that Antivirus package contain?
- virus signatures
- DNS anti-spyware signatures
- integrated EDL IP addresses
EDL - bulletproof, high risk, known malicious, tor exit nodes
What is the naming convention for antivirus packages?
panup-all-antivirus-xxxx-yyyy