MS.Windows.Update.Spoofing

description-logoDescription

This signature detects a DNS spoof attempt that redirects a request for windowsupdate.microsoft.com to a malicious server. This could be used as a compound attack, attempting to convince a user to download a malicious executable.

affected-products-logoAffected Products

Any Microsoft Windows version.

Impact logoImpact

Download a malicious executable.

recomended-action-logoRecommended Actions

N/A

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-12-02 16.972