    Posted Tue June 22, 2021 08:06 AM
    Hi Community,

    I came across some interesting event and would like to share with you. I was checking on some Firewall Event and found this.

    Seems ok since BILD.de is a known domain . However, we I checked on the payload information I came across this:

    BlLD.de -> small L.
    I use Chrome and Firefox. What kind of settings do you use to avoid something like this?

    Posted Fri July 16, 2021 07:12 AM

    Hi Bruno, interesting question.
    What is your QRadar question? Of course we are able to detect something like that using rules. This would require a refset including bad urls like this one. Is that your question? Or are you referring to browser settings? Chrome and firefox handle this in different ways.
    Chrome default setting will offer you to visit the website which has a marketing redirect attached. URL = "BlLD.de"
    Firefox will not even offer the marketing page but will present google result rightaway when you include google results in your search settings. Only when you deactivate your history you will see the redirected site.

    Posted Mon July 19, 2021 02:52 AM
    Hi Bruno, 

    strange and confusing for an analyst looking at the events. How are the other letters i in other payload fields in your installation? Maybe it is dependent on the browser or the User Preference settings. In my intstallation the small i is displayed like this:

    I use User Preference locale: English (United Kingdom) in QRadar and "Standar font"="Times New Roman", "Sans-serif font"=Arial in Chrome.



