signature-base/iocs/falsepositive-hashes.txt
2016-02-15 10:22:28 +01:00

48 lines
2.9 KiB
Plaintext

#
# LOKI CUSTOM FALSE POSITIVE HASHES
# This file contains MD5, SHA1 and SHA256 hashes and a short info like file name
# or hash origin
#
# FORMAT -----------------------------------------------------------------------
#
# MD5;COMMENT
# SHA1;COMMENT
# SHA256;COMMENT
#
5cfbe1fb8df52bfba6d021319b0da899;Yara Rules of v0.2
6e5ebbc8b70c1d593634daf0c190deadfda18c3cbc8f552a76f156f3869ef05b;REGIN False Positive - Microsoft USB Scanner Driver
7565e7de9532c75b3a16e3ed0103bc092dbca63c6bdc19053dfef01250029e59;REGIN False Positive - NSRL listed
a26db2eb9f3e2509b4eba949db97595cc32332d9321df68283bfc102e66d766f;REGIN False Positive - Windows Serial Driver
18cd54d163c9c5f16e824d13c411e21fd7616d34e9f1cf2adcbf869ed6aeeed4;REGIN False Positive - CD Tower Web Client
0099940a366b401f30faaf820f4815083778383a2b1e9fab58e16d10b8965e3f;REGIN False Positive - USB Scanner Driver
b04a85ef2edbc5ac7b312e9d57b533d9d355d0c7cbbd24a8085c6873baf9411f;REGIN False Positive - SCSI Driver Windows
581730d7cce49af90efad5f904ce205ee7123e6c0d206867fb8ad22559fa0556;REGIN False Positive - Windows Media Component Setup Application
519a0d7ebc75dcf65c80d61f952768e49c33c5c7c320a4cc4b4a12a0e9f3337d;REGIN False Positive - SP1.CAB MSDN Disc 3498 (Microsoft)
5d7509ee8bf1c3c14c10b9c2be3d58d56acedfb08444f9c774e5d8caa8659043;REGIN False Positive - Client.exe
fe0253432d1dd217b9d342f442a50b3647125a1c;Regin FP
ba833714e98efd8c07518bd1303e33e40884ea70;Regin FP
54263888c64a7f010d3b5e399369b0f3ff3af0a0de8adb502b98277533e4d45f;REGIN False Positive - Windows Serial Driver
d566bd2f46aebcad47261775d64fd970e297542fd846fde2685e45efc4669901;REGIN False Positive - Windows Serial Driver
c541cf35129e7effb57ac60d72bc45f821956a7e6f6a85d9a42364e1ddce3485;REGIN False Positive - Windows Serial Driver
d566bd2f46aebcad47261775d64fd970e297542fd846fde2685e45efc4669901;REGIN False Positive - Windows Serial Driver
40beeeca4c797a3355f4b01c57c2763c33028f27826315062320789a496d0810;REGIN False Positive - Windows Serial Driver
d64d63805beef5f6ea2e791c6fe61d9f9c740e42;REGIN FP
14f3e6b05e5693b1cbd9091bafe2649f830799a3;Malwarebytes Winlogon
accc2e5afb242d348da00bd3edf9b8033e81320bf33f790f1ac9ed8e9db78975;Novell nwfilter
c78655bc80301d76ed4fef1c1ea40a7d;Public IOC but is valid Windows 2003 svchost.exe
e617348b8947f28e2a280dd93c75a6ad;Empty MS Word Document
0d4c486a24a711a45fd83acdf4d18506;Legitimate Flash
ca0c67ba7aeba6aed5ddb852e6eea811;Legitimate Flash
b8a9e91134e7c89440a0f95470d5e47b;Zlib
fab221b5fb21d68e7866804d3066938786d93540fb816c10561df233f740d63f;MalwareBytes - Anti-Malware with system file names
a2f830a3fe6aaeb6cd4e17a22eeafeb2;MS15-078 / MS15-077 exploit - generic signature False Positive - Drweb32.dll (Ahead Nero)
6f2bfad61cf27546e9a08228ba5c87ad;regini.exe Windows 2008 R2 signed
abd883dd4c3ae03c4c9034e6539adc08c72f0f131e4b8912871489d0b81f423f;smss.exe MS software catalogue
5af2e6ca017b1d44a63d1b46dbb8c2604b74ebde;Malwarebytes winlogon
5730866b34ef589bd398c9a9b6d7e307;MS Office setlang.exe