Improve the detection of AutoIT files compiled to binary.#757
Merged
Conversation
Member
|
Let's run TeamCity tests. |
s3rvac
requested changes
Apr 30, 2020
Member
There was a problem hiding this comment.
The changes themselves are alright and all tests pass, but could you please rebase the branch with the current master and fix conflicts in the following two files?
support/yara_patterns/tools/pe/x64/compilers.yara
support/yara_patterns/tools/pe/x86/compilers.yara
They were caused by the merge of #756.
Contributor
Author
Certainly, it did not occur to me those two PR's can conflict with each other. I'm right on it. |
AutoIT files compiled to binary using Aut2Exe are a regular PE file that has its script embedded. This commit adds additional checks to catch and detect previously undetected version of the compiler.
0be7970 to
1e95eb1
Compare
Contributor
Author
|
Rebased and conflicts resolved. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
AutoIT files compiled to binary using Aut2Exe are a regular PE file that
has its script embedded. This commit adds additional checks to catch and
detect the previously undetected version of the compiler.
The tests have been added here