mandiant / iocs

FireEye Publicly Shared Indicators of Compromise (IOCs)
Apache License 2.0
462 stars 117 forks source link

False positive in IronGate IOCs #7

Closed bartblaze closed 8 years ago

bartblaze commented 8 years ago

File with hash 7a0c1017e6b5bb5dc776b3b883a1d0e0 in the IronGate IOCs seems to be the legitimate NetResView.

Please verify.

Edit: while it's technically not wrong, I don't think it needs to be included as an IOC. Cheers.

williamgibb commented 8 years ago

That is correct. The hash is logically AND'd with a filename term.

bartblaze commented 8 years ago

Hi William,

Thanks for your reply. That makes sense.

Cheers!