Skip to main content
Answer

Support ticket regarding Mandiant APT1 MD5s/FQDNs

  • February 20, 2013
  • 1 reply
  • 16 views

explanoit
Silver VIP
Forum|alt.badge.img+6
FYI to other bussines customers, I've already opened two support tickets requesting that Webroot verify they are blocking all MD5s and FQDNs that Mandiant released in their APT1 report.
 
http://intelreport.mandiant.com/
 
I will update this post once I have confirmation.
 
EDIT: Webroot has confirmed they have been blocked. Before I opened the ticket, I tried adding a bunch to overrides and Webroot was already blocking quiet a few of the MD5s already. Nice job.

Best answer by explanoit

Webroot has confirmed they have been blocked. Before I opened the ticket, I tried adding a bunch to overrides and Webroot already knew about quite a few of the files and already had them as malicious.

1 reply

explanoit
Silver VIP
Forum|alt.badge.img+6
  • Author
  • Silver VIP
  • Answer
  • February 20, 2013
Webroot has confirmed they have been blocked. Before I opened the ticket, I tried adding a bunch to overrides and Webroot already knew about quite a few of the files and already had them as malicious.