Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PE-Bear crashes with this file #42

Closed
tonykarg opened this issue Jan 11, 2022 · 8 comments
Closed

PE-Bear crashes with this file #42

tonykarg opened this issue Jan 11, 2022 · 8 comments
Assignees
Labels

Comments

@tonykarg
Copy link

Hello!

I tried to view this file:
https://www.virustotal.com/gui/file/db9de8ff7ed80cf7563502c25d6aad2e2fee258da407c52a6c4a2192f9170d14/details
with latest version of PE-Bear (0.5.5).
image
It loads layout of this file in left pane. I can see tabs with sections names, headers, etc.
Also when I hover mouse pointer over right pane a rounding circle is showing instead of simple arrow:

Then when I try to click on any tab PE-Bear hangs and closes without errors after 2-3 seconds.

This is sample from Bluenoroff group (sub-group of Lazarus that specializes only on financial attacks):
https://apt.securelist.com/apt/bluenoroff
It is packed with ENIGMA commercial packer.
This hash is seen here:
https://documents.trendmicro.com/assets/Appendix_ratankba-delving-into-large-scale-watering-holes-against-enterprises.pdf

I think this article can show some info about it:
https://www.trendmicro.com/en_us/research/17/b/ratankba-watering-holes-against-enterprises.html

I would be glad if PE-Bear can handle this file.

@hasherezade
Copy link
Owner

Thank you for the report! I will take care of this soon.

@hasherezade hasherezade self-assigned this Jan 11, 2022
@hasherezade
Copy link
Owner

@Kargin - I fixed it, please check out the new release: https://github.com/hasherezade/pe-bear-releases/releases/tag/0.5.5.1

@tonykarg
Copy link
Author

tonykarg commented Jan 12, 2022

@hasherezade
Thank you for such fast fix, but I got a problem.

Ran PE-Bear from archive x64_win_vs13 and got this error:
image
Also there are no win_vs17 versions for some reason. I prefer them :)
Tried next OS:
Windows 10 Pro x64 10.0.17763
Windows 10 Pro x64 10.0.19042

Older version (0.5.5.0) x64_win_vs13 runs with out errors.

Other versions:
qt4_x86_win_vs10
x86_win_vs13

ran without errors and fix worked:
image

@hasherezade
Copy link
Owner

@Kargin - ok, I am sorry: I see what happened. I was in a hurry, and mistakenly I uploaded the 64 bit build along with 32 bit DLLs, I will reupload the valid package shortly.

@hasherezade
Copy link
Owner

hasherezade commented Jan 12, 2022

ok, the new one is uploaded, check it out. win_vs17 will be added later today.

@tonykarg
Copy link
Author

@hasherezade Thank you very much! x64_win_vs13 works now!

@hasherezade
Copy link
Owner

@Kargin - the win_vs17 builds are ready! please check them out, and feel free to close this issue once you are sure that everything is ok.

@tonykarg
Copy link
Author

@hasherezade Thank you very much!
All versions work!
Closing issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants