# # LOKI CUSTOM FALSE POSITIVE HASHES # This file contains MD5, SHA1 and SHA256 hashes and a short info like file name # or hash origin # # FORMAT ----------------------------------------------------------------------- # # MD5;COMMENT # SHA1;COMMENT # SHA256;COMMENT # 5cfbe1fb8df52bfba6d021319b0da899;Yara Rules of v0.2 6e5ebbc8b70c1d593634daf0c190deadfda18c3cbc8f552a76f156f3869ef05b;REGIN False Positive - Microsoft USB Scanner Driver 7565e7de9532c75b3a16e3ed0103bc092dbca63c6bdc19053dfef01250029e59;REGIN False Positive - NSRL listed a26db2eb9f3e2509b4eba949db97595cc32332d9321df68283bfc102e66d766f;REGIN False Positive - Windows Serial Driver 18cd54d163c9c5f16e824d13c411e21fd7616d34e9f1cf2adcbf869ed6aeeed4;REGIN False Positive - CD Tower Web Client 0099940a366b401f30faaf820f4815083778383a2b1e9fab58e16d10b8965e3f;REGIN False Positive - USB Scanner Driver b04a85ef2edbc5ac7b312e9d57b533d9d355d0c7cbbd24a8085c6873baf9411f;REGIN False Positive - SCSI Driver Windows 581730d7cce49af90efad5f904ce205ee7123e6c0d206867fb8ad22559fa0556;REGIN False Positive - Windows Media Component Setup Application 519a0d7ebc75dcf65c80d61f952768e49c33c5c7c320a4cc4b4a12a0e9f3337d;REGIN False Positive - SP1.CAB MSDN Disc 3498 (Microsoft) 5d7509ee8bf1c3c14c10b9c2be3d58d56acedfb08444f9c774e5d8caa8659043;REGIN False Positive - Client.exe fe0253432d1dd217b9d342f442a50b3647125a1c;Regin FP ba833714e98efd8c07518bd1303e33e40884ea70;Regin FP 54263888c64a7f010d3b5e399369b0f3ff3af0a0de8adb502b98277533e4d45f;REGIN False Positive - Windows Serial Driver d566bd2f46aebcad47261775d64fd970e297542fd846fde2685e45efc4669901;REGIN False Positive - Windows Serial Driver c541cf35129e7effb57ac60d72bc45f821956a7e6f6a85d9a42364e1ddce3485;REGIN False Positive - Windows Serial Driver d566bd2f46aebcad47261775d64fd970e297542fd846fde2685e45efc4669901;REGIN False Positive - Windows Serial Driver 40beeeca4c797a3355f4b01c57c2763c33028f27826315062320789a496d0810;REGIN False Positive - Windows Serial Driver d64d63805beef5f6ea2e791c6fe61d9f9c740e42;REGIN FP 14f3e6b05e5693b1cbd9091bafe2649f830799a3;Malwarebytes Winlogon accc2e5afb242d348da00bd3edf9b8033e81320bf33f790f1ac9ed8e9db78975;Novell nwfilter c78655bc80301d76ed4fef1c1ea40a7d;Public IOC but is valid Windows 2003 svchost.exe e617348b8947f28e2a280dd93c75a6ad;Empty MS Word Document 0d4c486a24a711a45fd83acdf4d18506;Legitimate Flash ca0c67ba7aeba6aed5ddb852e6eea811;Legitimate Flash b8a9e91134e7c89440a0f95470d5e47b;Zlib fab221b5fb21d68e7866804d3066938786d93540fb816c10561df233f740d63f;MalwareBytes - Anti-Malware with system file names a2f830a3fe6aaeb6cd4e17a22eeafeb2;MS15-078 / MS15-077 exploit - generic signature False Positive - Drweb32.dll (Ahead Nero) 6f2bfad61cf27546e9a08228ba5c87ad;regini.exe Windows 2008 R2 signed abd883dd4c3ae03c4c9034e6539adc08c72f0f131e4b8912871489d0b81f423f;smss.exe MS software catalogue 5af2e6ca017b1d44a63d1b46dbb8c2604b74ebde;Malwarebytes winlogon 5730866b34ef589bd398c9a9b6d7e307;MS Office setlang.exe