mandiant / mandiant/capa-rules

FP: check for time delay via GetTickCount

Open
#1,180 1 comment 0 reactions 0 assignees View on GitHub
false positive
Dominant language
No language data
Stars
736
Forks
245
Avg merge
4d 53m
Merged PRs (30d)
2

Description

5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a:1400016FB

Image

- sub is just the stack from setup
- 0xFFFF... is checking for INVALID_HANDLE from CreateFileA, not GetTickCount

Contributor guide

Open the contributing guide

Research direction

Start with the sample identified by hash 5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a and location 1400016FB; inspect how the rule interprets GetTickCount and CreateFileA, especially INVALID_HANDLE. Done means this sample no longer produces a false-positive time-delay capability report.

Written by the indexing model from the issue text.

Assessment

Domain
reverse-engineering
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.