Closed hasherezade closed 5 years ago
e757457b62788c658d38e4d77a0c8cfd5272c5690389e6f51bf4349795311c63
PE Image Base was found after section headers: Dumped memory region: 55a075c86f2529613dd7df289d2fb6e828fa2e50b6f0be6d483d29f5393d5c90
A possible reason was that the memory area contained some bogus artefacts, that misguided the scan. This kind of situation should be prevented by additional checks.
The same sample scanned with the improved scanner:
Test case
e757457b62788c658d38e4d77a0c8cfd5272c5690389e6f51bf4349795311c63
Problem
PE Image Base was found after section headers: Dumped memory region: 55a075c86f2529613dd7df289d2fb6e828fa2e50b6f0be6d483d29f5393d5c90
Comment
A possible reason was that the memory area contained some bogus artefacts, that misguided the scan. This kind of situation should be prevented by additional checks.