Skip to content

Conversation

@maxDcb
Copy link

@maxDcb maxDcb commented Jan 16, 2025

The variable inst->amsi is actually "amsi" lower case. However we search for "AMSI" uppercase so the "if(*Signature == *(PDWORD)inst->amsi)" doesn't work.
This quick fix is working to patch the context check done by AmsiScanBuffer at offset 0x7D.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants