I often get errors when using VTDiff ; how can I get results?
The main reason you will get an error with no results is because the files provided for inclusion don't share relevant snippets.
For example, let's say that a malware family has two stages, eg: a dropper with variants A, B and C and a separate 2nd stage payload with variants X and Y.
VTDiff will often have problems if you do a single workflow including the 5 samples A, B, C, X and Y.
VTDiff will work much better if you do separate workflows:
- A first analysis including the droppers samples A, B and C.
- Second, a separate analysis with the 2nd stage samples X and Y.