spender-sandbox / cuckoo-modified

Modified edition of cuckoo
395 stars 178 forks source link

Automatic package detection #423

Closed Nwinternights closed 7 years ago

Nwinternights commented 7 years ago

Hi All, I was trying to upload a bin file through web interface and i know that's a JS. If i leave "auto" in "analysis package" I get only static analysis of VT with benign score but, if I force cuckoo to "js" i get all the behevour signature matched with 10 malscore. Does anyone have any tips to workaround that issue? the file is: 3e18dcfb2947a5252ddd238526e175f16b866c2b75da503c129e81fa8e587e07 thanks M.

spender-sandbox commented 7 years ago

No way to work around it without adding some more code to packages.py to do deeper inspection of files with "ascii text" file type or whatever it was detected as.

-Brad

Nwinternights commented 7 years ago

thank you Brad for quick answer.