Changeset 1345

Show
Ignore:
Timestamp:
03/07/08 16:32:00 (6 months ago)
Author:
kindlund
Message:

Added rule to exclude benign Flash activity, re: ticket #136

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • honeyclient/trunk/thirdparty/capture-mod/FileMonitor.exl

    r1332 r1345  
    220220+   Delete  C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\CatRoot2\\tmp\.edb 
    221221+   Write   C:\\WINDOWS\\system32\\winlogon\.exe    C:\\WINDOWS\\system32\\dllcache\\wuweb\.dll\.new 
     222 
     223#### Honeyclient manual add - iexplore.exe - ticket #136 (flash) 
     224+   Write   C:\\Program Files\\Internet Explorer\\iexplore\.exe C:\\WINDOWS\\fla.?\.tmp 
     225+   Delete  C:\\Program Files\\Internet Explorer\\iexplore\.exe C:\\WINDOWS\\fla.?\.tmp