Detect-It-Easy/dbs_min/db/Binary/shellcode_donut.1.sg
2026-01-25 13:51:16 +03:00

8 lines
No EOL
350 B
JavaScript

function detect(){bDetected=0
var e=Binary.readByte(0)
if(232==e&&Binary.readWord(1)==Binary.readWord(5)){e=Binary.readDword(1)+5
if(89==Binary.readByte(e))switch(bDetected=1,16777215&Binary.readDword(e+1)){case 5394778:sOptions="x86"
break
case 4767793:sOptions="x86 + AMD64"
break
default:sOptions="AMD64"}}return result()}meta("shellcode","Donut")