Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/undo-ransomware/ransomware_detection.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMatthias Held <ilovemilk@wusa.io>2018-09-13 17:59:21 +0300
committerMatthias Held <ilovemilk@wusa.io>2018-09-13 17:59:21 +0300
commit638143177e906a90ce87fe3f15570f72bd61d7f7 (patch)
tree12418b04b703906e52116cfdfbc642e2133305c6 /lib/FileSignatures.php
parent32f3f89390a32090669feec501b6c072ceed6890 (diff)
Add more signatures
Signed-off-by: Matthias Held <matthias.held@uni-konstanz.de>
Diffstat (limited to 'lib/FileSignatures.php')
-rw-r--r--lib/FileSignatures.php15
1 files changed, 13 insertions, 2 deletions
diff --git a/lib/FileSignatures.php b/lib/FileSignatures.php
index abe02d1..5ac2c37 100644
--- a/lib/FileSignatures.php
+++ b/lib/FileSignatures.php
@@ -46,7 +46,7 @@ class FileSignatures
['mimeType' => '', 'extensions' => ['xls'], 'signature' => ['starting' => ['offset' => 512, 'bytes' => ['/0908100000060500/']]]],
['mimeType' => '', 'extensions' => ['doc'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/0d444f43/']]]],
['mimeType' => '', 'extensions' => ['webm'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/1a45dfa3/']]]],
- ['mimeType' => '', 'extensions' => ['mkv'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/45dfa3934282886d6174726f736b61/']]]],
+ ['mimeType' => '', 'extensions' => ['mkv','mka', 'mks', 'mk3d', 'webm'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/45dfa3934282886d6174726f736b61/', '/1a45dfa3/']]]],
['mimeType' => '', 'extensions' => ['gz', 'tgz', 'vlt'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/1f8b08/']]]],
['mimeType' => '', 'extensions' => ['tar'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/1f9d/', '/1fA0/']]]],
['mimeType' => '', 'extensions' => ['eps'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/252150532d41646f62652d332e3020455053462d332030/']]]],
@@ -59,12 +59,23 @@ class FileSignatures
['mimeType' => '', 'extensions' => ['swf'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/435753/', '/465753/']]]],
['mimeType' => '', 'extensions' => ['gif'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/474946383761/', '/474946383961/']], 'trailing' => ['offset' => 0, 'bytes' => ['/003b/']]]],
['mimeType' => '', 'extensions' => ['tif', 'tiff'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/492049/', '/49492a00/', '/4d4d002a/', '/4d4d002b/']]]],
- ['mimeType' => '', 'extensions' => ['mp3'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/494433/']]]],
+ ['mimeType' => '', 'extensions' => ['mp3'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/494433/', '/FFFB/']]]],
['mimeType' => '', 'extensions' => ['com', 'dll', 'drv', 'exe', 'pif', 'qts', 'qtx', 'sys', 'acm', 'ax', 'cpl', 'fon', 'ocx', 'olb', 'scr', 'vbx'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/4d5a/']]]],
['mimeType' => '', 'extensions' => ['zip', 'jar', 'kmz', 'kwd', 'odt', 'odp', 'ott', 'sxc', 'sxd', 'sxi', 'sxw', 'sxc', 'wmz', 'xpi', 'xps', 'xpt'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/504b030414000100630000000000/']]]],
['mimeType' => '', 'extensions' => ['epub'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/504b03040a000200/']]]],
['mimeType' => '', 'extensions' => ['docx', 'pptx', 'xlsx'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/504b030414000600/']], 'trailing' => ['offset' => 18, 'bytes' => ['/504b0506/']]]],
['mimeType' => '', 'extensions' => ['png'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/89504e470d0a1a0a/']]]],
+ ['mimeType' => '', 'extensions' => ['rar'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/526172211a0700/', '/526172211a070100/']]]],
+ ['mimeType' => '', 'extensions' => ['asf', 'wmv', 'wma'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/3026b2758e66cf11a6d900aa0062ce6c/']]]],
+ ['mimeType' => '', 'extensions' => ['ogg', 'oga', 'ogv'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/4f676753/']]]],
+ ['mimeType' => '', 'extensions' => ['psd'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/38425053/']]]],
+ ['mimeType' => '', 'extensions' => ['wav'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/52494646[0-9a-f]{8}57415645/']]]],
+ ['mimeType' => '', 'extensions' => ['avi'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/52494646[0-9a-f]{8}41564920/']]]],
+ ['mimeType' => '', 'extensions' => ['bmp', 'dib'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/424d/']]]],
+ ['mimeType' => '', 'extensions' => ['xml'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/3c3f786d6c20/']]]],
+ ['mimeType' => '', 'extensions' => ['rtf'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/7b5c72746631/']]]],
+ ['mimeType' => '', 'extensions' => ['mpg', 'mpeg'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/000001ba/', '/47/', '/000001b3/']]]],
+ ['mimeType' => '', 'extensions' => ['mp4'], 'signature' => ['starting' => ['offset' => 0, 'bytes' => ['/00000018667479706d703432/']]]],
];
/**