cuckoosandbox / community

Repository of modules and signatures contributed by the community
324 stars 175 forks source link

Signature infostealer_browser.py is inaccurate #59

Closed botherder closed 8 years ago

botherder commented 9 years ago

The signature infostealer_browser.py raises way too many false positives and it's causing considerable issues, needs to be fixed.

jbremer commented 9 years ago

I think a lot of false positives can be resolved by not caring about the index.dat file - does that file contain anything useful at all anyway?

botherder commented 8 years ago

Has the signature changed?

jbremer commented 8 years ago

Not really, aside from changing to the latest Signature API.

jbremer commented 8 years ago

I removed the index.dat thing as it was causing pretty much only false positives. Guess this can be closed.