Rule Category

FILE-OTHER -- Snort detected traffic targeting vulnerabilities in a file type that does not require enough rule coverage to have its own category.

Alert Message

FILE-OTHER Multiple vendor Antivirus magic byte detection evasion attempt

Rule Explanation

An attacker can specify an incorrect Content-Type when sending a malicious file and cause several antivirus products to misidentify the file type during scans.

What To Look For

This rule triggers on attempt to evade detection in several Antivirus products by incorrectly specifying the file type being scanned.

Known Usage

Public information/Proof of Concept available

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

Rule Vulnerability

N/A

Not Applicable

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2005-3370
Loading description
CVE-2005-3371
Loading description
CVE-2005-3372
Loading description
CVE-2005-3373
Loading description
CVE-2005-3374
Loading description
CVE-2005-3375
Loading description
CVE-2005-3376
Loading description
CVE-2005-3377
Loading description
CVE-2005-3378
Loading description
CVE-2005-3379
Loading description
CVE-2005-3380
Loading description
CVE-2005-3381
Loading description
CVE-2005-3382
Loading description

MITRE ATT&CK Framework

Tactic: Defense Evasion

Technique: Obfuscated Files or Information

For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org