Detect-It-Easy/db/PE/HackShield.2.sg
2024-11-12 20:11:38 +03:00

17 lines
No EOL
488 B
JavaScript
Executable file

// Detect It Easy: detection rule file
init("protector", "HackShield");
function detect() {
var nImportSection = PE.getImportSection();
if (nImportSection != 0) {
var nOffset = PE.section[nImportSection].FileOffset;
var nSize = PE.section[nImportSection].FileSize;
nSize = Math.min(nSize, 0x2048);
if (PE.findString(nOffset, nSize, "TerminateHackShield") != -1) {
bDetected = true;
}
}
return result();
}