cuckoosandbox / community

Repository of modules and signatures contributed by the community
323 stars 175 forks source link

Minor signature fixes and additions #434

Open Brae opened 6 years ago

Brae commented 6 years ago

Previously js_eval.py simply reported 'Executed javascript' for any COleScript::Compile hook result, but since the VBScript hooking refers to the same function name this incorrectly identifies the language. Added check for VB content.

Brae commented 5 years ago

Added basic extractor for Kraken Cryptor ransomware configs. Only shows most relevant info, limitations in push_config make it hard to show all the data.