mirror of
https://github.com/Cisco-Talos/clamav.git
synced 2026-02-02 19:11:25 -05:00
docs/signatures.pdf: cover Mach-O files
This commit is contained in:
@@ -1,3 +1,7 @@
|
||||
Mon Jul 13 21:40:51 CEST 2009 (tk)
|
||||
----------------------------------
|
||||
* docs/signatures.pdf: cover Mach-O files
|
||||
|
||||
Mon Jul 13 21:24:05 CEST 2009 (tk)
|
||||
----------------------------------
|
||||
* libclamav: handle Mach-O files with type-9 signatures; all special offsets are
|
||||
|
||||
Binary file not shown.
@@ -166,6 +166,8 @@ MalwareName:TargetType:Offset:HexSignature[:MinEngineFunctionalityLevel:[Max]]
|
||||
\item 5 = Graphics
|
||||
\item 6 = ELF
|
||||
\item 7 = ASCII text file (normalized)
|
||||
\item 8 = Disassembler data
|
||||
\item 9 = Mach-O files
|
||||
\end{itemize}
|
||||
And \verb+Offset+ is an asterisk or a decimal number \verb+n+ possibly
|
||||
combined with a special modifier:
|
||||
@@ -174,7 +176,7 @@ MalwareName:TargetType:Offset:HexSignature[:MinEngineFunctionalityLevel:[Max]]
|
||||
\item \verb+n+ = absolute offset
|
||||
\item \verb+EOF-n+ = end of file minus \verb+n+ bytes
|
||||
\end{itemize}
|
||||
Signatures for PE and ELF files additionally support:
|
||||
Signatures for PE, ELF and Mach-O files additionally support:
|
||||
\begin{itemize}
|
||||
\item \verb#EP+n# = entry point plus n bytes (\verb#EP+0# for \verb+EP+)
|
||||
\item \verb#EP-n# = entry point minus n bytes
|
||||
|
||||
Reference in New Issue
Block a user