mirror of
https://github.com/horsicq/Detect-It-Easy.git
synced 2026-06-24 01:54:08 +00:00
Move and update detection rules to db_extra directory
Several detection rule files were moved from db/ to db_extra/ for COM, ELF, MSDOS, and PE formats. Minor code style and comment updates were made to some scripts, and the about.txt file in db_extra was updated for clarity. The PE/Break_Into_Pattern.2.sg rule was renamed to Break-Into-Pattern.
This commit is contained in:
parent
02d3a13eb6
commit
980704a895
12 changed files with 205 additions and 203 deletions
|
|
@ -5,9 +5,8 @@ init("protector", "CC#3");
|
|||
|
||||
function detect() {
|
||||
if (Binary.compare("e9$$$$e800005d33db8bc3bf....893f81c3....532eff36....1f1e568d76..8bfbb9....f2a4c6")) {
|
||||
sOptions = "by ZeroCoder //XG";
|
||||
bDetected = true;
|
||||
}
|
||||
|
||||
return result();
|
||||
}
|
||||
|
||||
return result();
|
||||
}
|
||||
|
|
@ -1,12 +1,14 @@
|
|||
// Detect It Easy: detection rule file
|
||||
|
||||
// https://download.cnet.com/hide-protect/3000-2092_4-10380452.html
|
||||
init("protector", "Hide&Protect");
|
||||
|
||||
function detect() {
|
||||
if (PE.compareEP("909090E9D8..050095..5300954A5000")) {
|
||||
if (PE.compareEP("909090E9D8..050095..5300954A5000") ||
|
||||
PE.compareEP("909090E9........0000000000000000")) {
|
||||
sVersion = "1.016";
|
||||
bDetected = true;
|
||||
}
|
||||
|
||||
return result();
|
||||
}
|
||||
|
||||
return result();
|
||||
}
|
||||
|
|
@ -124,11 +124,10 @@ function detect() {
|
|||
sVersion = "0.1";
|
||||
sOptions = "PENightMare 2 Beta";
|
||||
}
|
||||
/* else if(PE.compareEP("909090909090909090909090909090909090909090909090909090909090909090909090")) // TODO Check
|
||||
{
|
||||
sVersion="0.1";
|
||||
sOptions="PENinja 1.31";
|
||||
bDetected=1;
|
||||
/* else if (PE.compareEP("909090909090909090909090909090909090909090909090909090909090909090909090")) { // TODO Check
|
||||
sVersion = "0.1";
|
||||
sOptions = "PENinja 1.31";
|
||||
bDetected = true;
|
||||
} */
|
||||
else if (PE.compareEP("60E82B0000009090909090909090909090909090909090909090909090909090909090909090909090909090909090CCCC")) {
|
||||
sVersion = "0.1";
|
||||
|
|
|
|||
44
db/COM/packers.2.sg → db_extra/COM/packers.2.sg
Executable file → Normal file
44
db/COM/packers.2.sg → db_extra/COM/packers.2.sg
Executable file → Normal file
|
|
@ -1,25 +1,25 @@
|
|||
// Detect It Easy: detection rule file
|
||||
// Author: hypn0 <hypn0@mail.ru>
|
||||
|
||||
init("packer", "Packer");
|
||||
|
||||
function detect() {
|
||||
if (Binary.compare("bf....be....b9....fdf3a5fceb$$8bf7bf....adad8be8b2..e9")) {
|
||||
sOptions = "by B. Vorontsov";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("565056fd8bfc83ef..b9....be....f3a447ffe7")) {
|
||||
sOptions = "1997 by CyberWare";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("be....bd....558bce8d72..bf....d1e9fd57f3a58d75..fcf9bf....c3")) {
|
||||
sOptions = "1997 by JES //CORE";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("be....bd....558bce8d72..bf....d1e9fd57f3a58d75..fcf98bfdc3")) {
|
||||
sVersion = "1.2b";
|
||||
sOptions = "1997 by JES //CORE";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("508cc890ba....05....3b06....72..b4..ba....cd21b8....cd21")) {
|
||||
sOptions = "1996 by LostSoul";
|
||||
bDetected = true;
|
||||
// Detect It Easy: detection rule file
|
||||
// Author: hypn0 <hypn0@mail.ru>
|
||||
|
||||
init("packer", "Packer");
|
||||
|
||||
function detect() {
|
||||
if (Binary.compare("bf....be....b9....fdf3a5fceb$$8bf7bf....adad8be8b2..e9")) {
|
||||
sOptions = "by B. Vorontsov";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("565056fd8bfc83ef..b9....be....f3a447ffe7")) {
|
||||
sOptions = "1997 by CyberWare";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("be....bd....558bce8d72..bf....d1e9fd57f3a58d75..fcf9bf....c3")) {
|
||||
sOptions = "1997 by JES //CORE";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("be....bd....558bce8d72..bf....d1e9fd57f3a58d75..fcf98bfdc3")) {
|
||||
sVersion = "1.2b";
|
||||
sOptions = "1997 by JES //CORE";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("508cc890ba....05....3b06....72..b4..ba....cd21b8....cd21")) {
|
||||
sOptions = "1996 by LostSoul";
|
||||
bDetected = true;
|
||||
}
|
||||
|
||||
return result();
|
||||
192
db/COM/patchers.1.sg → db_extra/COM/patchers.1.sg
Executable file → Normal file
192
db/COM/patchers.1.sg → db_extra/COM/patchers.1.sg
Executable file → Normal file
|
|
@ -1,99 +1,99 @@
|
|||
// Detect It Easy: detection rule file
|
||||
// Author: hypn0 <hypn0@mail.ru>
|
||||
|
||||
init("patcher", "Patcher");
|
||||
|
||||
function detect() {
|
||||
if (Binary.compare("bc....8cc88ec08ed8fcbe....b9....8ae180e4..ac32c48844..e2")) {
|
||||
sName = "Patch engine";
|
||||
sOptions = "by SoNiC //UTG";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$b80300cd10b409ba....cd21e8$$$$1eb8....8ed833c98a0e....fec95133d2fec68916....b4..b2..cd21")) {
|
||||
sName = "ByteHunter patch engine";
|
||||
sOptions = "by nOP & THE_q //Phrozen Crew";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$0e588ec08ed88d16....68....9d9c582d....72..33dbb9")) {
|
||||
sName = "GPatch";
|
||||
sVersion = "1.2b"
|
||||
sOptions = "by JES //C.O.R.E. team";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$0e588ec08ed8e8$$$$68....9d9c582d....73..8d3e....fbc3")) {
|
||||
sName = "GPatch";
|
||||
sVersion = "1.0c"
|
||||
sOptions = "by JES //C.O.R.E. team";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$e8$$$$50558becc746......5d0733ffb9....fcb8....f3abc3")) {
|
||||
sName = "Cracker";
|
||||
sOptions = "by NightIce //ByTe Enf0rcerZ";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("eb$$c8......e8$$$$6a..07bf....268a1d263a1d74..268a1db8....99e8....f7d0f7d2b9")) {
|
||||
sName = "AutoCRK";
|
||||
sVersion = "1.2x (uncrypted)";
|
||||
sOptions = "1995 by MACHiNE GUNgsTeR //BANG!";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("eb$$8bfc83ef..83ec..be....b9....57f3a45fffe7")) {
|
||||
sName = "AutoCRK";
|
||||
sVersion = "1.2x (crypted)";
|
||||
sOptions = "1995 by MACHiNE GUNgsTeR //BANG!";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("c8......e8$$$$6a..07bf....268a1d263a1d74..268a1db8....99")) {
|
||||
sName = "AutoCRK";
|
||||
sVersion = "1.15";
|
||||
sOptions = "1995 by MACHiNE GUNgsTeR //BANG!";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$ba....8bda438a2780fc..75..e8....3c..74..2e8b1e....83fb..75..e9")) {
|
||||
sName = "CRK2COM";
|
||||
sVersion = "1.10b";
|
||||
sOptions = "1993";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("'/MG/'eb$$c8......e8$$$$6a..07bf....268a1d263a1d74..268a1db8....99")) {
|
||||
sName = "AutoCRK";
|
||||
sVersion = "1.20";
|
||||
sOptions = "by MACHiNE GUNgsTeR //BANG!";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$e8$$$$bb....b9....8a0734..880743e2..c3")) {
|
||||
sName = "Crack Engine";
|
||||
sVersion = "0.2";
|
||||
sOptions = "by Prizna //PSP";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("'SNT'1af8b409ba....cd2133f6bd....b8....ba....cd21a3....72..33c933d28bd8")) {
|
||||
sName = "SNT patch";
|
||||
sOptions = "//SNT";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("eb$$0e1fb409ba....cd21be....e8....803e......74..b4..ba....cd21eb..b4..ba....cd21b8....cd21")) {
|
||||
sOptions = "by WOLVERiNE";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("bc....5406b8....cd21891e....8c06....b8....ba....cd21b8....ba....cd21071eb9....ba....b7..b8....cd10")) {
|
||||
sOptions = "by Randall Flagg of Razor 1911";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$b8....cd10ba....e8....ba....b8....cd2173..ba....e8....ba....e8....b44ccd2193ba....e8")) {
|
||||
sOptions = "by Nostromo";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$ba....b409cd21c706........c706........c706........c706........be....33c98a0e....80f9..74..5651")) {
|
||||
sName += " #1";
|
||||
sOptions = "by Drink Or Die (Dark Knight)";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$ba....b409cd2133c0cd16b4..33dbcd10feccb2..cd10c706........c706........c706........c706")) {
|
||||
sName += " #2";
|
||||
sOptions = "by Dark Knight";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("b409ba....eb$$cd21b409ba....eb$$cd21b409ba....eb$$cd21b409ba....eb")) {
|
||||
sOptions = "by Mr. KIM";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("9090ba....8bfab409cd21c606......ba....b8....cd2172..93b8....33c933d2cd2172")) {
|
||||
sOptions = "by SkorpyoN Team";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("9090ba....b409cd21b401cd1674..33c0cd1633c0cd163c..0f84")) {
|
||||
sOptions = "by +DzA kRAker";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("9090ba....8bfab409cd21b401cd1674..33c0cd1633c0cd163c..75")) {
|
||||
sOptions = "by +DzA kRAker";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("ba....b409cd21ba....b409cd21ba....b8....cd21ba....0f82....a3....ba....b409cd218b1e")) {
|
||||
sName = "MkPatch";
|
||||
sVersion = "1.0";
|
||||
sOptions = "by eGIS!";
|
||||
bDetected = true;
|
||||
// Detect It Easy: detection rule file
|
||||
// Author: hypn0 <hypn0@mail.ru>
|
||||
|
||||
init("patcher", "Patcher");
|
||||
|
||||
function detect() {
|
||||
if (Binary.compare("bc....8cc88ec08ed8fcbe....b9....8ae180e4..ac32c48844..e2")) {
|
||||
sName = "Patch engine";
|
||||
sOptions = "by SoNiC //UTG";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$b80300cd10b409ba....cd21e8$$$$1eb8....8ed833c98a0e....fec95133d2fec68916....b4..b2..cd21")) {
|
||||
sName = "ByteHunter patch engine";
|
||||
sOptions = "by nOP & THE_q //Phrozen Crew";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$0e588ec08ed88d16....68....9d9c582d....72..33dbb9")) {
|
||||
sName = "GPatch";
|
||||
sVersion = "1.2b"
|
||||
sOptions = "by JES //C.O.R.E. team";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$0e588ec08ed8e8$$$$68....9d9c582d....73..8d3e....fbc3")) {
|
||||
sName = "GPatch";
|
||||
sVersion = "1.0c"
|
||||
sOptions = "by JES //C.O.R.E. team";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$e8$$$$50558becc746......5d0733ffb9....fcb8....f3abc3")) {
|
||||
sName = "Cracker";
|
||||
sOptions = "by NightIce //ByTe Enf0rcerZ";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("eb$$c8......e8$$$$6a..07bf....268a1d263a1d74..268a1db8....99e8....f7d0f7d2b9")) {
|
||||
sName = "AutoCRK";
|
||||
sVersion = "1.2x (uncrypted)";
|
||||
sOptions = "1995 by MACHiNE GUNgsTeR //BANG!";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("eb$$8bfc83ef..83ec..be....b9....57f3a45fffe7")) {
|
||||
sName = "AutoCRK";
|
||||
sVersion = "1.2x (crypted)";
|
||||
sOptions = "1995 by MACHiNE GUNgsTeR //BANG!";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("c8......e8$$$$6a..07bf....268a1d263a1d74..268a1db8....99")) {
|
||||
sName = "AutoCRK";
|
||||
sVersion = "1.15";
|
||||
sOptions = "1995 by MACHiNE GUNgsTeR //BANG!";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$ba....8bda438a2780fc..75..e8....3c..74..2e8b1e....83fb..75..e9")) {
|
||||
sName = "CRK2COM";
|
||||
sVersion = "1.10b";
|
||||
sOptions = "1993";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("'/MG/'eb$$c8......e8$$$$6a..07bf....268a1d263a1d74..268a1db8....99")) {
|
||||
sName = "AutoCRK";
|
||||
sVersion = "1.20";
|
||||
sOptions = "by MACHiNE GUNgsTeR //BANG!";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$e8$$$$bb....b9....8a0734..880743e2..c3")) {
|
||||
sName = "Crack Engine";
|
||||
sVersion = "0.2";
|
||||
sOptions = "by Prizna //PSP";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("'SNT'1af8b409ba....cd2133f6bd....b8....ba....cd21a3....72..33c933d28bd8")) {
|
||||
sName = "SNT patch";
|
||||
sOptions = "//SNT";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("eb$$0e1fb409ba....cd21be....e8....803e......74..b4..ba....cd21eb..b4..ba....cd21b8....cd21")) {
|
||||
sOptions = "by WOLVERiNE";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("bc....5406b8....cd21891e....8c06....b8....ba....cd21b8....ba....cd21071eb9....ba....b7..b8....cd10")) {
|
||||
sOptions = "by Randall Flagg of Razor 1911";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$b8....cd10ba....e8....ba....b8....cd2173..ba....e8....ba....e8....b44ccd2193ba....e8")) {
|
||||
sOptions = "by Nostromo";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$ba....b409cd21c706........c706........c706........c706........be....33c98a0e....80f9..74..5651")) {
|
||||
sName += " #1";
|
||||
sOptions = "by Drink Or Die (Dark Knight)";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("e9$$$$ba....b409cd2133c0cd16b4..33dbcd10feccb2..cd10c706........c706........c706........c706")) {
|
||||
sName += " #2";
|
||||
sOptions = "by Dark Knight";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("b409ba....eb$$cd21b409ba....eb$$cd21b409ba....eb$$cd21b409ba....eb")) {
|
||||
sOptions = "by Mr. KIM";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("9090ba....8bfab409cd21c606......ba....b8....cd2172..93b8....33c933d2cd2172")) {
|
||||
sOptions = "by SkorpyoN Team";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("9090ba....b409cd21b401cd1674..33c0cd1633c0cd163c..0f84")) {
|
||||
sOptions = "by +DzA kRAker";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("9090ba....8bfab409cd21b401cd1674..33c0cd1633c0cd163c..75")) {
|
||||
sOptions = "by +DzA kRAker";
|
||||
bDetected = true;
|
||||
} else if (Binary.compare("ba....b409cd21ba....b409cd21ba....b8....cd21ba....0f82....a3....ba....b409cd218b1e")) {
|
||||
sName = "MkPatch";
|
||||
sVersion = "1.0";
|
||||
sOptions = "by eGIS!";
|
||||
bDetected = true;
|
||||
}
|
||||
|
||||
return result();
|
||||
16
db/ELF/ELFCrypt.2.sg → db_extra/ELF/ELFCrypt.2.sg
Executable file → Normal file
16
db/ELF/ELFCrypt.2.sg → db_extra/ELF/ELFCrypt.2.sg
Executable file → Normal file
|
|
@ -1,11 +1,11 @@
|
|||
// Detect It Easy: detection rule file
|
||||
|
||||
init("protector", "ELFCrypt");
|
||||
|
||||
function detect() {
|
||||
if (ELF.compareEP("eb0206c6609cbe")) {
|
||||
sVersion = "1.0";
|
||||
bDetected = true;
|
||||
// Detect It Easy: detection rule file
|
||||
|
||||
init("protector", "ELFCrypt");
|
||||
|
||||
function detect() {
|
||||
if (ELF.compareEP("eb0206c6609cbe")) {
|
||||
sVersion = "1.0";
|
||||
bDetected = true;
|
||||
}
|
||||
|
||||
return result();
|
||||
110
db/MSDOS/Cryptors.2.sg → db_extra/MSDOS/Cryptors.2.sg
Executable file → Normal file
110
db/MSDOS/Cryptors.2.sg → db_extra/MSDOS/Cryptors.2.sg
Executable file → Normal file
|
|
@ -1,58 +1,58 @@
|
|||
// Detect It Easy: detection rule file
|
||||
// Author: hypn0 <hypn0@mail.ru>
|
||||
|
||||
init("cryptor", "Cryptor");
|
||||
|
||||
function detect() {
|
||||
if (MSDOS.compareEP("b2..33f6b9....2e30144649e3..eb..b8....ffe0")) {
|
||||
sOptions = "by Rainor'99";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("1e8ccb8edbbb....8177......8177......8177......8177......8177......1f0eeb")) {
|
||||
sOptions = "by Papaev V.V., Moscow";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("50e8$$$$5b9c5825....509d8ccb81c3....81eb....53bb....53cb")) {
|
||||
sOptions = "1990-92 by Sergdesign";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("81c3....eb$$85fa85e8eb$$81c3....eb$$bb....81eb....81c3....f981e9....39f5ba....81ea....85de")) {
|
||||
sOptions = "by eGIS! //CORE";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("bd....8cdb83c3..8cd805....8ed88ec033ffbe....b9....ba....0bc975..0bd274..4ae8....eb..561e")) {
|
||||
sOptions = "1994 by FalCoN";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("e9$$$$e8$$$$bf....e9$$$$31d2eb$$eb$$e9$$$$8edae9$$$$e8$$$$8715e9$$$$52eb$$31f6e8$$bb....eb$$8737e9$$$$56e9$$$$e9$$$$e8$$$$bf....bb....2e8a1789d8")) {
|
||||
sOptions = "by Matrix Technologies";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("e9$$$$eb$$bf....e9$$$$29f6e8$$$$e9$$$$8edee8$$$$8735e8$$$$56e9$$$$e9$$$$31ede9$$$$bb....e9$$$$e8$$$$e9$$$$e8$$$$e9$$$$e9$$$$e8$$$$e8$$$$e8$$$$872f")) {
|
||||
sOptions = "by Matrix Technologies";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("e8$$$$33ed83ed..2ed0....5e0e8bfe81e7....f7df03fe2e893526a1....8ec0263b06....74..f92eff35")) {
|
||||
sOptions = "by DREAMMASTER";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("eb$$e8$$$$eb$$e4210c..e62133c08ed80e50558becc746......5dfa8f06....8f06....fb9c580d....509d")) {
|
||||
sOptions = "by RaZoR 1911";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("e9$$$$e80000fa9cfc505393584c4c3bc35b74..9de8....32e480c4..3065..47e2")) {
|
||||
sName += ' N1';
|
||||
sOptions = "by ZeroCoder //XG";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("3beb81c5....fc23eb13ec85fd1e0e33e985ee01ed23ee1f0e81d1....84e931dd073efe0e....e9")) {
|
||||
sOptions = "1996 by RAM Scanner //CiD";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("b8....15....72..d4..8ac4..c3....8ed8b9....f7d32e871e....ff77..ff378becc747......8c0f")) {
|
||||
sOptions = "by Thunderbyte";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("b8....15....72..d4..8ac4..c3..8ed8b9....f7d32e871e....ff77..ff378becc747......8c0f")) {
|
||||
sOptions = "by Thunderbyte";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("2e8c1e....2e8e06....33ff33f6b9....0e1f030e....f3a406b8....500e07cb")) {
|
||||
sOptions = "1994 by Paragon Technology Systems";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("87dbb8....15....72$$8cd315....72..d4..8ac483c3..8ed8b9....f7d32e87")) {
|
||||
sOptions = "1997 by Thunderbyte";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("50e8$$$$5b83c3..1e06530e1f83c3..90b0..b9....2e3007fec043e2")) {
|
||||
sOptions = "by Dr. Motorhead";
|
||||
bDetected = true;
|
||||
// Detect It Easy: detection rule file
|
||||
// Author: hypn0 <hypn0@mail.ru>
|
||||
|
||||
init("cryptor", "Cryptor");
|
||||
|
||||
function detect() {
|
||||
if (MSDOS.compareEP("b2..33f6b9....2e30144649e3..eb..b8....ffe0")) {
|
||||
sOptions = "by Rainor'99";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("1e8ccb8edbbb....8177......8177......8177......8177......8177......1f0eeb")) {
|
||||
sOptions = "by Papaev V.V., Moscow";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("50e8$$$$5b9c5825....509d8ccb81c3....81eb....53bb....53cb")) {
|
||||
sOptions = "1990-92 by Sergdesign";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("81c3....eb$$85fa85e8eb$$81c3....eb$$bb....81eb....81c3....f981e9....39f5ba....81ea....85de")) {
|
||||
sOptions = "by eGIS! //CORE";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("bd....8cdb83c3..8cd805....8ed88ec033ffbe....b9....ba....0bc975..0bd274..4ae8....eb..561e")) {
|
||||
sOptions = "1994 by FalCoN";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("e9$$$$e8$$$$bf....e9$$$$31d2eb$$eb$$e9$$$$8edae9$$$$e8$$$$8715e9$$$$52eb$$31f6e8$$bb....eb$$8737e9$$$$56e9$$$$e9$$$$e8$$$$bf....bb....2e8a1789d8")) {
|
||||
sOptions = "by Matrix Technologies";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("e9$$$$eb$$bf....e9$$$$29f6e8$$$$e9$$$$8edee8$$$$8735e8$$$$56e9$$$$e9$$$$31ede9$$$$bb....e9$$$$e8$$$$e9$$$$e8$$$$e9$$$$e9$$$$e8$$$$e8$$$$e8$$$$872f")) {
|
||||
sOptions = "by Matrix Technologies";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("e8$$$$33ed83ed..2ed0....5e0e8bfe81e7....f7df03fe2e893526a1....8ec0263b06....74..f92eff35")) {
|
||||
sOptions = "by DREAMMASTER";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("eb$$e8$$$$eb$$e4210c..e62133c08ed80e50558becc746......5dfa8f06....8f06....fb9c580d....509d")) {
|
||||
sOptions = "by RaZoR 1911";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("e9$$$$e80000fa9cfc505393584c4c3bc35b74..9de8....32e480c4..3065..47e2")) {
|
||||
sName += ' N1';
|
||||
sOptions = "by ZeroCoder //XG";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("3beb81c5....fc23eb13ec85fd1e0e33e985ee01ed23ee1f0e81d1....84e931dd073efe0e....e9")) {
|
||||
sOptions = "1996 by RAM Scanner //CiD";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("b8....15....72..d4..8ac4..c3....8ed8b9....f7d32e871e....ff77..ff378becc747......8c0f")) {
|
||||
sOptions = "by Thunderbyte";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("b8....15....72..d4..8ac4..c3..8ed8b9....f7d32e871e....ff77..ff378becc747......8c0f")) {
|
||||
sOptions = "by Thunderbyte";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("2e8c1e....2e8e06....33ff33f6b9....0e1f030e....f3a406b8....500e07cb")) {
|
||||
sOptions = "1994 by Paragon Technology Systems";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("87dbb8....15....72$$8cd315....72..d4..8ac483c3..8ed8b9....f7d32e87")) {
|
||||
sOptions = "1997 by Thunderbyte";
|
||||
bDetected = true;
|
||||
} else if (MSDOS.compareEP("50e8$$$$5b83c3..1e06530e1f83c3..90b0..b9....2e3007fec043e2")) {
|
||||
sOptions = "by Dr. Motorhead";
|
||||
bDetected = true;
|
||||
}
|
||||
|
||||
return result();
|
||||
|
|
@ -1,6 +1,6 @@
|
|||
// Detect It Easy: detection rule file
|
||||
|
||||
init("protector", "Break Into Pattern");
|
||||
init("protector", "Break-Into-Pattern");
|
||||
|
||||
function detect() {
|
||||
if (PE.compareEP("E9$$$$$$$$EB14")) {
|
||||
14
db/PE/ChainskiCrypter.1.sg → db_extra/PE/ChainskiCrypter.1.sg
Executable file → Normal file
14
db/PE/ChainskiCrypter.1.sg → db_extra/PE/ChainskiCrypter.1.sg
Executable file → Normal file
|
|
@ -1,10 +1,10 @@
|
|||
// Detect It Easy: detection rule file
|
||||
|
||||
init("cryptor", "ChainskiCrypter");
|
||||
|
||||
function detect() {
|
||||
if (PE.isNetObjectPresent("Chainski")) {
|
||||
bDetected = true;
|
||||
// Detect It Easy: detection rule file
|
||||
|
||||
init("cryptor", "ChainskiCrypter");
|
||||
|
||||
function detect() {
|
||||
if (PE.isNetObjectPresent("Chainski")) {
|
||||
bDetected = true;
|
||||
}
|
||||
|
||||
return result();
|
||||
|
|
@ -1,2 +1,4 @@
|
|||
"db_extra" contains detection rules and scripts that were not approved for inclusion in the main database.
|
||||
Some of these rules may trigger only a few positive detections across the entire internet. Use of this database by default is not recommended, as it is neither optimized nor actively maintained.
|
||||
Some of these rules may trigger only a few positive detections across the entire internet.
|
||||
|
||||
Using this default database is NOT RECOMMENDED as it is not optimized or actively maintained.
|
||||
Loading…
Add table
Add a link
Reference in a new issue