Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Inconsistency of entropy values to its graph #103

Open
dyussekeyev opened this issue Nov 12, 2021 · 4 comments
Open

Inconsistency of entropy values to its graph #103

dyussekeyev opened this issue Nov 12, 2021 · 4 comments

Comments

@dyussekeyev
Copy link

Dear developers,

When I analyzed a malware sample (MD5 73AFAC6E5799747168D49B8957AA757E) I have found an inconsistency of entropy values to its graph.

I tried to use various versions of the software: 3.02, 3.03 pre-release and 1.01. At the picture below I might see that the entropy of section '.data' is 2.4, but it does not correlate with a graph. Similar issues for other sections.

die

Is it a bug or normal behaviour?

Best regards,
Askar.

@horsicq
Copy link
Owner

horsicq commented Nov 12, 2021

It is normal behavior. We are using 100 parts of the file to draw the graph.
We need more parts to make the entropy of the section is more visible.
I will make a custom parameter "count" to increase number of parts.

@dyussekeyev
Copy link
Author

Understood. Thank you.

Could you please to modify the code so that one section should be not less that 1 part to ensure that it will be shown on a graph.

@horsicq
Copy link
Owner

horsicq commented Nov 12, 2021

Yes. I will make it. I will release version 3.03 in a few days,
It will be in version 3.04.

@dyussekeyev
Copy link
Author

Checked this sample again. Looks well in the 3.04. Thank you.

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants