Detect-It-Easy/db/PE/NTShell.2.sg
2024-11-12 20:11:38 +03:00

13 lines
No EOL
373 B
JavaScript
Executable file

// Detect It Easy: detection rule file
// Author: hypn0 <hypn0@mail.ru>
init("packer", "NTSHELL");
function detect() {
if (PE.compareEP("55e8........5d81ed........eb$$eb$$8d85........8dbd........eb$$8db5........eb$$8bcfeb$$2bc84ffdeb$$33dbeb$$8a07eb$$d2c8eb$$2a....eb$$E8")) {
sVersion = "5.0";
bDetected = true;
}
return result();
}