From 4f44c257f57b70aea84211e3131e5ee62915079c Mon Sep 17 00:00:00 2001 From: V <45754825+vxsh4d0w@users.noreply.github.com> Date: Sat, 2 Feb 2019 01:44:07 +0100 Subject: [PATCH] New Pattern Update This update fix last review made a month ago. --- iocp/data/patterns.ini | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/iocp/data/patterns.ini b/iocp/data/patterns.ini index 5cedc0d..d966ffa 100644 --- a/iocp/data/patterns.ini +++ b/iocp/data/patterns.ini @@ -7,22 +7,22 @@ pattern: \b(([a-z0-9\-]{2,}\[?\.\]?)+(abogado|ac|academy|accountants|active|acto defang: True [IP] -pattern: \b(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\b +pattern: \b(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?(\.|$)){4}\b [Email] -pattern: \b([a-z][_a-z0-9-.]+@[a-z0-9-]+\.[a-z]+)\b +pattern: \b[a-zA-Z0-9.!#$%&’*+/=?^_`{|}~-]+@[a-zA-Z0-9-]+(?:\.[a-zA-Z0-9-]+)*\b [MD5] -pattern: \b([a-f0-9]{32}|[A-F0-9]{32})\b +pattern: \b[a-fA-F0-9]{32}\b [SHA1] -pattern: \b([a-f0-9]{40}|[A-F0-9]{40})\b +pattern: \b[a-fA-F0-9]{40}\b [SHA256] -pattern: \b([a-f0-9]{64}|[A-F0-9]{64})\b +pattern: \b[a-fA-F0-9]{64}\b [CVE] -pattern: \b(CVE\-[0-9]{4}\-[0-9]{4,6})\b +pattern: \b(CVE-(1999|2\d{3})-(0\d{2}[1-9]|[1-9]\d{3,}))\b [Registry] pattern: \b((HKLM|HKCU)\\[\\A-Za-z0-9-_]+)\b @@ -31,4 +31,4 @@ pattern: \b((HKLM|HKCU)\\[\\A-Za-z0-9-_]+)\b pattern: \b([A-Za-z0-9-_\.]+\.(exe|dll|bat|sys|htm|html|js|jar|jpg|png|vb|scr|pif|chm|zip|rar|cab|pdf|doc|docx|ppt|pptx|xls|xlsx|swf|gif))\b [Filepath] -pattern: \b[A-Z]:\\[A-Za-z0-9-_\.\\]+\b +pattern: \b[a-z]:\\(?:[^\\/:*?"<>|\r\n]+\\)*[^\\/:*?"<>|\r\n]*\b