Skip to content

Fix martian sig#439

Open
jdval wants to merge 6 commits intocuckoosandbox:masterfrom
jdval:fix_martian_sig
Open

Fix martian sig#439
jdval wants to merge 6 commits intocuckoosandbox:masterfrom
jdval:fix_martian_sig

Conversation

@jdval
Copy link

@jdval jdval commented Nov 20, 2018

I'm pretty sure this is just a couple of bugg in the signature logic, unless I'm misunderstanding the intent of the signature.

  1. the loop was continuing ONLY IF the process name was in the list of whitelist_proc
  2. there were two whitelist regexes for AcroRd64.exe and none for AcroRd32.exe

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant