Sabyasachi Mitra
Sabyasachi Mitra
@mike-hunhoff Sir I am interested to take up this issue can you assign it to me ?
@zdwg42 can you give me a sample PE which does the dynamic loading like this
@zdwg42 I hope these testfiles are not live malware ?
@zdwg42 can you describe me how were you analyzing the PE in capa which commands you used . I don't think Capa extracts the api by itself it used vivisect...
you analysed the NtFsControlFile dynamic call in ghidra right ?
I think the rule you proposed - runtime_resolved: true can be implemented by a vivisect script of searching for the GetProcAddress api or LoadLibrary and seeing the parameter that is...
@williballenthin Sir , can you assign me this work ? Describe me the necessary changes in detail and any prerequisites knowledge I need to know .
@williballenthin @mike-hunhoff can you confirm if this issue is still there and how to reproduce it ? I do not see capa rendering any string .
@Valentin-Metz Sir I am interested to work on your issue . Can you confirm is it still there , can you give me what it says if done with --debug...
@Siradankullanici see the debug input I think he had unpacked it .