|
Bytes with offset from entry point, ?? as wildcard allowed.
Usage
ephex=<offset(int)>|<hh>[hh[hh[hh[hh]...]]]
Examples
ephex=0|558BEC83C4F0
Would detect the following code at the entry point of the file:
PUSH EBP
MOV EBP, ESP
ADD ESP, F0
Description
Use offset to specify an offset to the file entry point (has to be a Portable Executable file).
See also
Similar parameters
Similar commands
|