Detecting CD-COPS String in CDCOPS.DLL #70

Closed
opened 2026-01-29 21:05:38 +00:00 by claunia · 2 comments
Owner

Originally created by @Flashfire42 on GitHub (Mar 9, 2022).

image
In 2 of the 3 samples I have been able to examine so far of the CDCOPS.DLL this string is at the same offset every time in the third sample it is off by 1 but the string is still there. The files are all NEEXE according to virustotal which may make things more difficult to parse. If I get further info on the dll I will update this issue. They are also reportably all 16bit windows applications

Originally created by @Flashfire42 on GitHub (Mar 9, 2022). ![image](https://user-images.githubusercontent.com/40415824/157557462-5c0fc757-ad77-4534-a191-c0a718fe3ac3.png) In 2 of the 3 samples I have been able to examine so far of the CDCOPS.DLL this string is at the same offset every time in the third sample it is off by 1 but the string is still there. The files are all NEEXE according to virustotal which may make things more difficult to parse. If I get further info on the dll I will update this issue. They are also reportably all 16bit windows applications
Author
Owner

@mnadareski commented on GitHub (Jul 11, 2022):

If you can provide samples, this would be helpful. Otherwise, check latest to see if it's taken care of already.

@mnadareski commented on GitHub (Jul 11, 2022): If you can provide samples, this would be helpful. Otherwise, check latest to see if it's taken care of already.
Author
Owner

@TheRogueArchivist commented on GitHub (Dec 14, 2022):

I can confirm that this check is now present and functional.

@TheRogueArchivist commented on GitHub (Dec 14, 2022): I can confirm that this check is now present and functional.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SabreTools/BinaryObjectScanner#70