Skip to content

High severity signatures firing during benign URL analysis in IE 7 #252

@seanthegeek

Description

@seanthegeek

When analyzing various benign URLS in IE on Windows 7:

  • example.com
  • google.com

The following high severity signatures fired, which raised the MalScore to malicious levels:

  • creates_largekey
    regkeyval: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\ProgramsCache
  • stack_pivot
    process: explorer.exe:1288

Ideally, the MalScore should be in the benign range.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions