Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PE module sanity check to strict #295

Closed
gljiva opened this issue Apr 9, 2015 · 1 comment
Closed

PE module sanity check to strict #295

gljiva opened this issue Apr 9, 2015 · 1 comment

Comments

@gljiva
Copy link

gljiva commented Apr 9, 2015

Hi, "resource_dir->Characteristics != 0" is preventing yara from performing resource checks. I've found valid PE samples with working resources using characteristics!=0. This breaks some of my sigs and gives false negative results while scanning such samples. Removing this check seems safe and fixes the problem.

@nyx0
Copy link
Contributor

nyx0 commented May 10, 2015

@gljiva Can you share the file please?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants