Rule Category
FILE-EXECUTABLE -- Snort detected traffic targeting vulnerabilites that are found in or delivered through executable files, regardless of platform. In those instances, Snort is able to correct traffic that has been altered.
AhnLab-V3 2010.04.04.30 Backdoor/Win32.Bredolab. Automated systems are supervised and improved constantly to avoid false positives. As malware look. These vendors don't provide any way to submit a false positive without making an account, or at all. Alibaba (virustotal@list.alibaba-inc.com rejected my mail as spam) AhnLab-V3 (login only) ALYac (requires program). The current test AhnLab V3 Mobile Security 3.1 for Android (191801) from May 2019 of AV-TEST, the leading international and independent service provider for antivirus software and malware. V3 Home helps your kids use internet wisely and also helps your family spend time with each other, not with smartphone. For One-Person Households. Be safe with V3 Home. Even if you are not at home, V3 Home will give you a notification whenever it detects unauthorized access to your Wifi network or devices. False Positives; Adware.Tracking Cookie: XPD8C61E.txt /xiti.com F/P?? Scan report by SAS. Antivirus Ergebnis Aktualisierung Agnitum 20131113 AhnLab-V3.
Alert Message
FILE-EXECUTABLE Portable Executable multiple antivirus evasion attempt
Ahnlab V3 Lite
Ahnlab V3 Report False Positive Test
Rule Explanation
The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a 4a464946 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.Impact:CVSS base score 4.3CVSS impact score 2.9CVSS exploitability score 8.6confidentialityImpact NONEintegrityImpact PARTIALavailabilityImpact PARTIALDetails:Ease of Attack: