Add Advanced Installer Detection (#32)

* Add Advanced Installer Detection

* Updated README

* Address comments
This commit is contained in:
SilasLaspada
2021-03-21 23:36:01 -06:00
committed by GitHub
parent 557114d92d
commit 6b8f8957de
2 changed files with 21 additions and 0 deletions

View File

@@ -0,0 +1,20 @@
using System;
using System.IO;
namespace BurnOutSharp.PackerType
{
// TODO: Add extraction and verify that all versions are detected
public class AdvancedInstaller : IContentCheck
{
/// <inheritdoc/>
public string CheckContents(string file, byte[] fileContent, bool includePosition = false)
{
// Software\Caphyon\Advanced Installer
byte?[] check = new byte?[] { 0x53, 0x6F, 0x66, 0x74, 0x77, 0x61, 0x72, 0x65, 0x5C, 0x43, 0x61, 0x70, 0x68, 0x79, 0x6F, 0x6E, 0x5C, 0x41, 0x64, 0x76, 0x61, 0x6E, 0x63, 0x65, 0x64, 0x20, 0x49, 0x6E, 0x73, 0x74, 0x61, 0x6C, 0x6C, 0x65, 0x72 };
if (fileContent.FirstPosition(check, out int position))
return "Caphyon Advanced Installer" + (includePosition ? $" (Index {position})" : string.Empty);
return null;
}
}
}

View File

@@ -88,6 +88,7 @@ Below is a list of the protections that can be detected using this code:
Below is a list of the executable packers that can be detected using this code:
- Advanced Installer
- Armadillo
- CExe
- dotFuscator