Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update martians sig #226

Merged
merged 11 commits into from Jul 14, 2017
Merged

Update martians sig #226

merged 11 commits into from Jul 14, 2017

Conversation

kevross33
Copy link
Contributor

This is a big change; the idea is to create a martian signature where individual interesting processes can be added more easily. Whitelisting has been added from the following cuckoo-modified signatures:

https://github.com/spender-sandbox/community-modified/blob/master/modules/signatures/martians_ie.py
https://github.com/spender-sandbox/community-modified/blob/master/modules/signatures/martians_office.py

This is a big change; the idea is to create a martian signature where individual interesting processes can be added more easily. Whitelisting has been added from the following cuckoo-modified signatures:

https://github.com/spender-sandbox/community-modified/blob/master/modules/signatures/martians_ie.py
https://github.com/spender-sandbox/community-modified/blob/master/modules/signatures/martians_office.py
@kevross33
Copy link
Contributor Author

Office Example:
martianoffice

Wscript Example:
martianwscript

@kevross33
Copy link
Contributor Author

Pony Dropper Doc (DEP seems to "FP" on EXEs loaded but I think this is just the FP mentioned during submit on exploit stuff; still bad for it to be executing :-D):
martianpony

@kevross33
Copy link
Contributor Author

Malware document downloader sample (spawns powershell) ebf4cc27140a7e261a359af115f57463

added in powershell detection, simplified it to better report on parent process with commandlines and also neatened the signature.
@kevross33
Copy link
Contributor Author

here is analysis of ebf4cc27140a7e261a359af115f57463. It highlights powershell but also using inetsim (it doesn't care if it is an exe it gets back it just executes it but you could give it one) it highlights this too.

image

@jbremer jbremer merged commit cff99ba into cuckoosandbox:master Jul 14, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants