Antivirus Content Updates Flashcards

1
Q

What is included in the Antivirus packages?

A
  1. antivirus signatures
  2. Spyware DNS C2 Signatures
  3. Spyware Autogen C2 Signatures
  4. IP Malicious IP feed
  5. IP Suspicious IP feed
  6. IP Bulletproof IP feed
  7. IP Tor exit IP feed

includes new and old

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the difference between Spyware DNS C2 Signatures and Spyware Autogen C2 Signatures?

A

DNS C2 Signatures rely on the analysis of DNS queries, Autogen C2 Signatures analyze the payload of the communication, allowing them to detect C2 traffic even when the domain or IP address of the C2 server is not previously known

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are Spyware DNS C2 Signatures designed to do?

A

detect outbound C2 communication by monitoring DNS requests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When do Spyware DNS C2 Signatures kick in?

A

when compromised hosts attempt to resolve domain names associated with known malicious command-and-control servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Based on what do Spyware Autogen C2 Signatures detect malware?

A

based on payload

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the main capability of Spyware Autogen C2 Signatures?

A

detect C2 communications with C2 hosts that are unknown or change rapidly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are Spyware Autogen C2 Signatures particularly effective in?

A

identifying malware that employs dynamic domain generation algorithms (DGAs) or uses previously unknown C2 domains for communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How are Spyware Autogen C2 Signatures generated?

A

automatically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 3 main categories that Antivirus package contain?

A
  1. virus signatures
  2. DNS anti-spyware signatures
  3. integrated EDL IP addresses

EDL - bulletproof, high risk, known malicious, tor exit nodes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the naming convention for antivirus packages?

A

panup-all-antivirus-xxxx-yyyy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly