Neo23x0 / signature-base

YARA signature and IOC database for my scanners and tools
Other
2.45k stars 602 forks source link

FP from otx-hash-ioc #23

Closed Dovakeen closed 6 years ago

Dovakeen commented 6 years ago

Hi,

otx-hash-ioc, line 8841: A11A2F0CFE6D0B4C50945989DB6360CD;ARP Spoofing Used to Insert Malicious Adverts https://www.alienvault.com/blogs/labs-research/arp-spoofing-used-to-insert-malic

It seems to be WinPcap 4.1.3 installer : https://www.winpcap.org/install/default.htm Tried to contact the blog article author on www.alienvault.com to discuss this, no luck yet.

Thanks for Loki and keeping the rules up to date by the way.

Neo23x0 commented 6 years ago

Thanks, I fixed that https://github.com/Neo23x0/signature-base/commit/3ed59d8f588a85d3f1982e8c6836e03269a821f9