4n0nym0us
Level 1
4n4lDetector v3.6 is here, bringing greater stability, optimization, and security for analysts. As always, focused on defending creativity and delivering value through unique capabilities for Windows PE malware static analysis.
Enjoy
Download:
https://github.com/4n0nym0us/4n4lDetector/releases/download/v3.6/4n4lDetectorV3.6.zip
v3.6
[+] The PE Carve module received memory optimizations and fixed a file truncation bug.
[+] Fixed an intermittent issue where Exception Table information might not be displayed.
[+] Fixed an intermittent issue that could affect the VirusTotal report generation process.
[+] Applied security checks and optimizations related to iteration, size validation, and memory management.
[+] Entry Point and Disassembler instructions now calculate addresses using the corresponding RVA and ImageBase across all architectures.
[+] Fixed an issue where instructions located in the last bytes of a file might not be disassembled from the visual view.
[+] Added a new feature that allows Highlights to be completely hidden by right-clicking on their information panel.
[+] Implemented VA calculation in Flow Anomalies detections for more accurate execution target representation.
[+] Added new Highlight detection labels based on the latest analysis features.
[+] Restructured the TLS Callbacks and Exceptions module descriptions to improve information clarity.
[+] Reworked suspicious API detection.
.... [-] APIs have been removed from the rules file.
.... [-] Existing APIs were integrated into the application's internal database along with their descriptions.
.... [-] Added new suspicious APIs to be highlighted in the main report.
[+] New Entry Point Flow Analysis (EP Flow Analysis) module.
.... [-] Detection of NOP sleds and padding instructions at the Entry Point.
.... [-] Identification of JMP SHORT and JMP NEAR redirections.
.... [-] Automatic tracking of jump chains and execution trampolines.
.... [-] Detection of invalid destinations or targets outside the PE image.
.... [-] Identification of possible Original Entry Point (OEP) relocations.
.... [-] Detection of backward redirections to code located before the Entry Point.
.... [-] Pre-Jump Analysis of instructions executed before the first redirection.
.... [-] Heuristic scoring system for classification of suspicious redirections.
Enjoy
Download:
https://github.com/4n0nym0us/4n4lDetector/releases/download/v3.6/4n4lDetectorV3.6.zip
v3.6
[+] The PE Carve module received memory optimizations and fixed a file truncation bug.
[+] Fixed an intermittent issue where Exception Table information might not be displayed.
[+] Fixed an intermittent issue that could affect the VirusTotal report generation process.
[+] Applied security checks and optimizations related to iteration, size validation, and memory management.
[+] Entry Point and Disassembler instructions now calculate addresses using the corresponding RVA and ImageBase across all architectures.
[+] Fixed an issue where instructions located in the last bytes of a file might not be disassembled from the visual view.
[+] Added a new feature that allows Highlights to be completely hidden by right-clicking on their information panel.
[+] Implemented VA calculation in Flow Anomalies detections for more accurate execution target representation.
[+] Added new Highlight detection labels based on the latest analysis features.
[+] Restructured the TLS Callbacks and Exceptions module descriptions to improve information clarity.
[+] Reworked suspicious API detection.
.... [-] APIs have been removed from the rules file.
.... [-] Existing APIs were integrated into the application's internal database along with their descriptions.
.... [-] Added new suspicious APIs to be highlighted in the main report.
[+] New Entry Point Flow Analysis (EP Flow Analysis) module.
.... [-] Detection of NOP sleds and padding instructions at the Entry Point.
.... [-] Identification of JMP SHORT and JMP NEAR redirections.
.... [-] Automatic tracking of jump chains and execution trampolines.
.... [-] Detection of invalid destinations or targets outside the PE image.
.... [-] Identification of possible Original Entry Point (OEP) relocations.
.... [-] Detection of backward redirections to code located before the Entry Point.
.... [-] Pre-Jump Analysis of instructions executed before the first redirection.
.... [-] Heuristic scoring system for classification of suspicious redirections.