use an alignmemt based on the cpu arch, not the pool header size

this fixes an issue with pool scanning on win10 32-bit samples, because the size of a pool header increased to 16 bytes, but we still want 8 byte alignment on 32-bit machines
This commit is contained in:
Analyst
2019-03-20 11:53:26 -05:00
parent 2138152b10
commit 93e66381ad
@@ -70,7 +70,10 @@ class _POOL_HEADER(objects.Struct):
# otherwise we have an executive object in the pool
else:
alignment = pool_header_size
if symbols.symbol_table_is_64bit(self._context, symbol_table_name):
alignment = 16
else:
alignment = 8
# FIXME: calculate and cache this
max_optional_headers_length = 0x60