spender-sandbox / community-modified

Modified edition of cuckoo community modules

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

New APIs needed for modifies_wallpaper.py sig to work

kevross33 opened this issue · comments

Hi,

The APIs SystemParametersInfoA and SystemParametersInfoW needs to be hooked for this signature to work and to detect most ransomware which modifies the wallpaper like Cerber or WannaCry. Currently this signature does not detect that the wallpaper has been modified.