brad-sp / community-modified

Modified edition of cuckoo community modules
31 stars 17 forks source link

Add a regex mutex detection #104

Closed KillerInstinct closed 9 years ago

KillerInstinct commented 9 years ago

Seems Zeus variants with HTTP based C2 adapted mutex generation similar to that of Zeus variants with P2P C2. With the HTTP versions we observed many mutex creations, so we'll just trigger based on the count of the total unique mutexes that match the pattern. Also removed a bunch of white space. Bumped version as this requires all=True