Closed mr-tz closed 8 years ago
closed in 4a5017aad472875d4a2d821031cff7e61066ebbc
this is a detection issue
not sure how to solve... current features are something like:
this is not very much
perhaps the following instruction is interesting:
movsx eax, byte ptr [ecx+eax]
add a new heuristic for: mov/fetch a single byte using a base pointer and offset. this is commonly seen in byte-wise algorithms.
perhaps could use symbolic analysis to determine that the output buffer is a function of the input buffer. unsure of the feasibility. need johnk to complete his exploration of symboliks and provide some tutorials before we tackle this.
Decoding routine identification fails. With #201 emulation works.