Closed 0xnobody closed 4 years ago
Certain VMP versions include dead instructions before the NOP instruction, which leads to failed import stub scans. Possible fix: use another method (instruction count / analysis) to filter import stub calls before VTIL analysis.
Fixed by https://github.com/0xnobody/vmpdump/commit/49b37db85e8dfd106cf971498e51b82aa47db4b7
Certain VMP versions include dead instructions before the NOP instruction, which leads to failed import stub scans. Possible fix: use another method (instruction count / analysis) to filter import stub calls before VTIL analysis.