From this community.sophos.com/kb/en-u… I derive it's about lookups of domains against some blacklist. Given that these domains are themselves queried over DNS, there's little point to encrypt the blacklist lookups. Basic obfuscation against keyword matching could make sense.
1
2
This was the result I saw, which says it can contain URLs and file submissions, which does not make perfect sense unless there was some context I'm missing... community.sophos.com/kb/en-u…
1
Should have used ROT26 as higher number means better encryption
Nov 26, 2019 · 8:16 PM UTC


