diff --git a/modules/signatures/andromeda_apis.py b/modules/signatures/andromeda_apis.py index 7eb1180..a7de9d9 100644 --- a/modules/signatures/andromeda_apis.py +++ b/modules/signatures/andromeda_apis.py @@ -39,6 +39,7 @@ def on_call(self, call, process): try: eventname_int = int(eventname) if self.sysvolserial and eventname_int == self.sysvolserial ^ 0x696e6a63: # 'injc' + self.add_match(process, 'api', call) return True except: pass diff --git a/modules/signatures/antiav_avast_libs.py b/modules/signatures/antiav_avast_libs.py index 3e64908..3308fa4 100644 --- a/modules/signatures/antiav_avast_libs.py +++ b/modules/signatures/antiav_avast_libs.py @@ -29,4 +29,5 @@ class AvastDetectLibs(Signature): def on_call(self, call, process): dllname = self.get_argument(call, "FileName") if "snxhk" in dllname.lower(): + self.add_match(process, 'api', call) return True diff --git a/modules/signatures/antiav_bitdefender_libs.py b/modules/signatures/antiav_bitdefender_libs.py index 3d17ab9..af2cc41 100644 --- a/modules/signatures/antiav_bitdefender_libs.py +++ b/modules/signatures/antiav_bitdefender_libs.py @@ -29,4 +29,5 @@ class BitdefenderDetectLibs(Signature): def on_call(self, call, process): dllname = self.get_argument(call, "FileName") if "avcuf32" in dllname.lower(): + self.add_match(process, 'api', call) return True