diff --git a/descriptions/AntiCheat.TheiaAntiTamper.md b/descriptions/AntiCheat.TheiaAntiTamper.md new file mode 100644 index 000000000..c7c946b19 --- /dev/null +++ b/descriptions/AntiCheat.TheiaAntiTamper.md @@ -0,0 +1,2 @@ +Theia is an anti-tamper system developed by [**ZeroITLab**](https://zeroitlab.com/). +Theia provides detections for tools commonly used to reverse engineer games such as IDA Pro, X64DBG and pe-bear. diff --git a/rules.ini b/rules.ini index 7488953e1..119a6e000 100644 --- a/rules.ini +++ b/rules.ini @@ -254,6 +254,7 @@ PunkBuster[] = (?:^|/)pbsv\.dll$ PunkBuster[] = (?:^|/)Punkbuster(?:$|/) Ricochet = (?:^|/)Randgrid\.sys$ TenProtect = (?:^|/)TP3Helper\.exe$ +TheiaAntiTamper = (?:^|/)preloader(?:_l)?\.dll$ XIGNCODE3 = \.xem$ [SDK] diff --git a/tests/types/AntiCheat.TheiaAntiTamper.txt b/tests/types/AntiCheat.TheiaAntiTamper.txt new file mode 100644 index 000000000..05aecdc59 --- /dev/null +++ b/tests/types/AntiCheat.TheiaAntiTamper.txt @@ -0,0 +1,8 @@ +/preloader.dll +/preloader_l.dll +preloader.dll +preloader_l.dll +Win64/preloader.dll +Win64/preloader_l.dll +Sub/Win64/preloader.dll +Sub/Win64/preloader_l.dll