docs/signatures.pdf: cover Mach-O files

0.96
Tomasz Kojm 16 years ago
parent 8af7ccd0af
commit 4c82fd9fd0
  1. 4
      ChangeLog
  2. BIN
      docs/signatures.pdf
  3. 4
      docs/signatures.tex

@ -1,3 +1,7 @@
Mon Jul 13 21:40:51 CEST 2009 (tk)
----------------------------------
* docs/signatures.pdf: cover Mach-O files
Mon Jul 13 21:24:05 CEST 2009 (tk)
----------------------------------
* libclamav: handle Mach-O files with type-9 signatures; all special offsets are

Binary file not shown.

@ -166,6 +166,8 @@ MalwareName:TargetType:Offset:HexSignature[:MinEngineFunctionalityLevel:[Max]]
\item 5 = Graphics
\item 6 = ELF
\item 7 = ASCII text file (normalized)
\item 8 = Disassembler data
\item 9 = Mach-O files
\end{itemize}
And \verb+Offset+ is an asterisk or a decimal number \verb+n+ possibly
combined with a special modifier:
@ -174,7 +176,7 @@ MalwareName:TargetType:Offset:HexSignature[:MinEngineFunctionalityLevel:[Max]]
\item \verb+n+ = absolute offset
\item \verb+EOF-n+ = end of file minus \verb+n+ bytes
\end{itemize}
Signatures for PE and ELF files additionally support:
Signatures for PE, ELF and Mach-O files additionally support:
\begin{itemize}
\item \verb#EP+n# = entry point plus n bytes (\verb#EP+0# for \verb+EP+)
\item \verb#EP-n# = entry point minus n bytes

Loading…
Cancel
Save