mandiant / mandiant/capa-rules
FP: check for time delay via GetTickCount
Open
false positive
- Dominant language
- No language data
- Stars
- 736
- Forks
- 245
- Avg merge
- 4d 53m
- Merged PRs (30d)
- 2
Description
5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a:1400016FB
- sub is just the stack from setup
- 0xFFFF... is checking for INVALID_HANDLE from CreateFileA, not GetTickCount
Contributor guide
Research direction
Start with the sample identified by hash 5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a and location 1400016FB; inspect how the rule interprets GetTickCount and CreateFileA, especially INVALID_HANDLE. Done means this sample no longer produces a false-positive time-delay capability report.
Written by the indexing model from the issue text.
Assessment
- Domain
- reverse-engineering
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100