Malware Theory - PE Malformations And Anomalies

We explore malformations and anomalies of the Portable Executable format. What kinds of malformations exist, why do they occur and how do they affect PE file parsers?
PoC PE files with malformations (Corkami): https://github.com/indrora/corkami/tr...
TinyPE: https://webserver2.tecgraf.puc-rio.br...
Portable Executable Malware: https://github.com/katjahahn/PortEx/r...
PortExAnalyzer: https://github.com/katjahahn/PortEx/t...

Malware Theory - PE Malformations And Anomalies
Reviewed by Anonymous
on
April 20, 2019
Rating:
