Think you have a false positive on this rule?

Sid 1-50769

Message

MALWARE-CNC Win.Trojan.QUADAGENT outbound DNS tunnel

Summary

This event is generated when Win.Trojan.QUADAGENT DNS tunneling beacons are detected.

Impact

A Network Trojan was detected

Detailed information

Affected systems

Ease of attack

False positives

False negatives

Corrective action

Contributors

  • Cisco Talos Intelligence Group

Additional References

  • virustotal.com/gui/file/1f6369b42a76d02f32558912b57ede4f5ff0a90b18d3b96a4fe24120fa2c300c