cuckoosandbox / community

Repository of modules and signatures contributed by the community
324 stars 175 forks source link

Fix martian sig #439

Open jdval opened 5 years ago

jdval commented 5 years ago

I'm pretty sure this is just a couple of bugg in the signature logic, unless I'm misunderstanding the intent of the signature.

1) the loop was continuing ONLY IF the process name was in the list of whitelist_proc 2) there were two whitelist regexes for AcroRd64.exe and none for AcroRd32.exe