brad-sp / community-modified

Modified edition of cuckoo community modules
31 stars 17 forks source link

Add a signature for CryptoWall #166

Closed KillerInstinct closed 8 years ago

KillerInstinct commented 8 years ago

Also extract out campaign ID and C2 domains.

KillerInstinct commented 8 years ago

@brad-accuvant If you want, update the cuckoomon dll's to make RtlDecompressBuffer use the 'c' log type to utilize large buffers. As-is we may truncate, thus not logging all C2 domains.