From 131d9844a842710de282caff15641fbc5193bdf6 Mon Sep 17 00:00:00 2001 From: doomedraven Date: Sat, 28 Sep 2024 18:46:31 +0200 Subject: [PATCH] Update infostealer_browser.py --- .../signatures/windows/infostealer_browser.py | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/modules/signatures/windows/infostealer_browser.py b/modules/signatures/windows/infostealer_browser.py index 2698782c..ee99023d 100644 --- a/modules/signatures/windows/infostealer_browser.py +++ b/modules/signatures/windows/infostealer_browser.py @@ -62,26 +62,26 @@ def __init__(self, *args, **kwargs): re.compile(r".*\\Microsoft\\Edge\\User\\ Data\\Default\\.*", re.I), # Google Chrome - re.compile(r".*\\Application\\ Data Data\\Google\\Chrome\\.*", re.I), + re.compile(r".*\\Application\\ Data\\Google\\Chrome\\.*", re.I), re.compile(r".*\\Local\\Google\\Chrome\\User\\ Data\\Default\\.*", re.I), re.compile(r".*\\AppData\\Local\\Google\\Chrome\\User\\ Data\\Default\\.*", re.I), # Chromium-based Browsers - re.compile(r".*\\Application\\ Data Data\\Chromium\\.*", re.I), + re.compile(r".*\\Application\\ Data\\Chromium\\.*", re.I), re.compile(r".*\\AppData\\Local\\Chromium\\.*", re.I), - re.compile(r".*\\Application\\ Data Data\\ChromePlus\\.*", re.I), + re.compile(r".*\\Application\\ Data\\ChromePlus\\.*", re.I), re.compile(r".*\\AppData\\Local\\MapleStudio\\ChromePlus\\.*", re.I), - re.compile(r".*\\Application\\ Data Data\\Nichrome\\.*", re.I), - re.compile(r".*\\Application\\ Data Data\\Bromium\\.*", re.I), - re.compile(r".*\\Application\\ Data Data\\RockMelt\\.*", re.I), - re.compile(r".*\\Application\\ Data Data\\Flock\\.*", re.I), + re.compile(r".*\\Application\\ Data\\Nichrome\\.*", re.I), + re.compile(r".*\\Application\\ Data\\Bromium\\.*", re.I), + re.compile(r".*\\Application\\ Data\\RockMelt\\.*", re.I), + re.compile(r".*\\Application\\ Data\\Flock\\.*", re.I), re.compile(r".*\\AppData\\Local\\Flock\\.*", re.I), - re.compile(r".*\\Application\\ Data Data\\Comodo\\Dragon\\.*", re.I), + re.compile(r".*\\Application\\ Data\\Comodo\\Dragon\\.*", re.I), re.compile(r".*\\AppData\\Local\\Comodo\\Dragon\\.*", re.I), re.compile(r".*\\BraveSoftware\\Brave-Browser\\User\\ Data\\Default\\.*", re.I), # Opera - re.compile(r".*\\Application\\ Data Data\\Opera\\.*", re.I), + re.compile(r".*\\Application\\ Data\\Opera\\.*", re.I), re.compile(r".*\\AppData\\Roaming\\Opera\\Opera\\.*", re.I), re.compile(r".*\\AppData\\Roaming\\Opera Software\\Opera Stable\\.*", re.I),