You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Some LNK files have data appended to the end. It would be useful if liblnk could detect that there is data at the end of the file and represent it as an offset value so it can be easily carved out. a8fac75d06cf1d4e30f9b118a962a24413d046dec622bd17dd594250252543e9 is one example of a LNK with a PE appended to the end of it. While easy to find the PE I have other examples with encrypted/compressed data on the end that are not easily recognizable.
The text was updated successfully, but these errors were encountered:
joachimmetz
changed the title
Support for overlay detection
Support for detecting trailing non-LNK data
Feb 4, 2023
Some LNK files have data appended to the end. It would be useful if liblnk could detect that there is data at the end of the file and represent it as an offset value so it can be easily carved out. a8fac75d06cf1d4e30f9b118a962a24413d046dec622bd17dd594250252543e9 is one example of a LNK with a PE appended to the end of it. While easy to find the PE I have other examples with encrypted/compressed data on the end that are not easily recognizable.
The text was updated successfully, but these errors were encountered: