brad-sp / community-modified

Modified edition of cuckoo community modules
31 stars 17 forks source link

Fix observed false negatives, add a file indicator #111

Closed KillerInstinct closed 9 years ago

KillerInstinct commented 9 years ago

From spyware sample: http://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/tspy_kibex.a

It checks for the existence of the software key itself and not any of its child keys, thus we need to remove the pattern for the ending slash.