Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

In artefacts scan: misaligned offsets of artefacts #25

Closed
hasherezade opened this issue Dec 6, 2018 · 1 comment
Closed

In artefacts scan: misaligned offsets of artefacts #25

hasherezade opened this issue Dec 6, 2018 · 1 comment
Assignees
Labels

Comments

@hasherezade
Copy link
Owner

hasherezade commented Dec 6, 2018

Test case

e757457b62788c658d38e4d77a0c8cfd5272c5690389e6f51bf4349795311c63

Problem

PE Image Base was found after section headers:
section_hdrs_after_base
Dumped memory region: 55a075c86f2529613dd7df289d2fb6e828fa2e50b6f0be6d483d29f5393d5c90

Comment

A possible reason was that the memory area contained some bogus artefacts, that misguided the scan. This kind of situation should be prevented by additional checks.

@hasherezade
Copy link
Owner Author

Fixed:

The same sample scanned with the improved scanner:
workingset_scan

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant