![]() |
|
[HC Official] PE Analyzer, Reverse Engineering Tool - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: Hacking (https://sinister.ly/Forum-Hacking) +--- Forum: Hacking Tools (https://sinister.ly/Forum-Hacking-Tools) +--- Thread: [HC Official] PE Analyzer, Reverse Engineering Tool (/Thread-HC-Official-PE-Analyzer-Reverse-Engineering-Tool) |
[HC Official] PE Analyzer, Reverse Engineering Tool - Deque - 09-02-2014 PE Analyzer PE Analyzer is a static analysis tool for PE files (EXE, DLL, SYS, etc.), including:
Requirements: JRE 1.7 Usage: Code: usage: java -jar peana.jar [<options>] <PEfile>
-h,--help show help
-v,--version show version
-o,--output write report to output fileExample command for command line output: Code: usage: java -jar peana.jar myfile.exeExample command for file output: Code: usage: java -jar peana.jar -o report.txt myfile.exeExample Output: Code: ____ _____ _ _
| _ \| ____| / \ _ __ __ _| |_ _ _______ _ __
| |_) | _| / _ \ | '_ \ / _` | | | | |_ / _ \ '__|
| __/| |___ / ___ \| | | | (_| | | |_| |/ / __/ |
|_| _|_____| /_/ _ \_\_| |_|\__,_|_|\__, /___\___|_| _ _
| | | | __ _ ___| | _____ ___ _ __ |___/_ __ ___ _ _ _ __ (_) |_ _ _
| |_| |/ _` |/ __| |/ / __/ _ \| '_ ` _ \| '_ ` _ \| | | | '_ \| | __| | | |
| _ | (_| | (__| < (_| (_) | | | | | | | | | | | |_| | | | | | |_| |_| |
|_| |_|\__,_|\___|_|\_\___\___/|_| |_| |_|_| |_| |_|\__,_|_| |_|_|\__|\__, |
|___/
-by Deque-
Report For WinRar.exe
*********************
file size 0x12516a
full path /home/deque/portextestfiles/WinRar.exe
MSDOS Header
************
description value file offset
---------------------------------------------------------------------
signature word 0x5a4d 0x0
last page size 0x50 0x2
file pages 0x2 0x4
relocation items 0x0 0x6
header paragraphs 0x4 0x8
minimum number of paragraphs allocated 0xf 0xa
maximum number of paragraphs allocated 0xffff 0xc
initial SS value 0x0 0xe
initial SP value 0xb8 0x10
complemented checksum 0x0 0x12
initial IP value 0x0 0x14
pre-relocated initial CS value 0x0 0x16
relocation table offset 0x40 0x18
overlay number 0x1a 0x1a
Reserved word 0x1c 0x0 0x1c
Reserved word 0x1e 0x0 0x1e
Reserved word 0x20 0x0 0x20
Reserved word 0x22 0x0 0x22
OEM identifier 0x0 0x24
OEM information 0x0 0x26
Reserved word 0x28 0x0 0x28
Reserved word 0x2a 0x0 0x2a
Reserved word 0x2c 0x0 0x2c
Reserved word 0x2f 0x0 0x2e
Reserved word 0x30 0x0 0x30
Reserved word 0x32 0x0 0x32
Reserved word 0x34 0x0 0x34
Reserved word 0x36 0x0 0x36
Reserved word 0x38 0x0 0x38
Reserved word 0x3a 0x0 0x3a
PE signature offset 0x200 0x3c
COFF File Header
****************
time date stamp Jan 17, 2007 11:36:54 AM
machine type Intel 386 or later processors and compatible processors
characteristics * Image only, Windows CE, and Windows NT and later.
* Machine is based on a 32-bit-word architecture.
* Image only.
* COFF line numbers have been removed. DEPRECATED
* COFF symbol table entries for local symbols have been removed. DEPRECATED
description value file offset
-------------------------------------------------------------------
machine type 0x14c 0x204
number of sections 0x4 0x206
time date stamp 0x45adfc46 0x208
pointer to symbol table (deprecated) 0x0 0x20c
number of symbols (deprecated) 0x0 0x210
size of optional header 0xe0 0x214
characteristics 0x10f 0x216
Optional Header
***************
standard field value file offset
-----------------------------------------------------------------------
magic number 0x10b 0x218
major linker version 0x5 0x21a
minor linker version 0x0 0x21b
size of code 0x11000 0x21c
size of initialized data 0x4000 0x220
size of unitialized data 0x0 0x224
address of entry point 0x1000 0x228
address of base of code 0x1000 0x22c
address of base of data 0x12000 0x230
windows field value file offset
-----------------------------------------------------------------------
image base 0x400000 0x234
section alignment in bytes 0x1000 0x238
file alignment in bytes 0x200 0x23c
major operating system version 0x4 0x240
minor operating system version 0x0 0x242
major image version 0x0 0x244
minor image version 0x0 0x246
major subsystem version 0x4 0x248
minor subsystem version 0x0 0x24a
win32 version value (reserved) 0x0 0x24c
size of image in bytes 0x1d000 0x250
size of headers 0x400 0x254
checksum 0x0 0x258
subsystem 0x2 0x25c
dll characteristics 0x0 0x25e
size of stack reserve 0x100000 0x260
size of stack commit 0x2000 0x264
size of heap reserve 0x100000 0x268
size of heap commit 0x1000 0x26c
loader flags (reserved) 0x0 0x270
number of rva and sizes 0x10 0x274
data directory virtual address size file offset
-----------------------------------------------------------------------
import table 0x16000 0xf05 0x280
resource table 0x17000 0x6000 0x288
Section Table
*************
1. .text 2. .data 3. .idata 4. .rsrc
-----------------------------------------------------------------------------------------
Entropy 0.80 0.60 0.60 0.85
Pointer To Raw Data 0x600 0x10c00 0x11600 0x12600
Size Of Raw Data 0x10600 0xa00 0x1000 0x6000
Physical End 0x10c00 0x11600 0x12600 0x18600
Virtual Address 0x1000 0x12000 0x16000 0x17000
Virtual Size 0x11000 0x4000 0x1000 0x6000
Pointer To Relocations 0x0 0x0 0x0 0x0
Number Of Relocations 0x0 0x0 0x0 0x0
Pointer To Line Numbers 0x0 0x0 0x0 0x0
Number Of Line Numbers 0x0 0x0 0x0 0x0
Code x
Initialized Data x x x
Execute x
Write x
Imports
*******
ADVAPI32.DLL
rva: 90292 (0x160b4), name: RegCloseKey, hint: 0
rva: 90296 (0x160b8), name: RegCreateKeyExA, hint: 0
rva: 90300 (0x160bc), name: RegOpenKeyExA, hint: 0
rva: 90304 (0x160c0), name: RegQueryValueExA, hint: 0
rva: 90308 (0x160c4), name: RegSetValueExA, hint: 0
KERNEL32.DLL
rva: 90340 (0x160e4), name: CloseHandle, hint: 0
rva: 90344 (0x160e8), name: CompareStringA, hint: 0
rva: 90348 (0x160ec), name: CreateDirectoryA, hint: 0
rva: 90352 (0x160f0), name: CreateDirectoryW, hint: 0
rva: 90356 (0x160f4), name: CreateFileA, hint: 0
rva: 90360 (0x160f8), name: CreateFileW, hint: 0
rva: 90364 (0x160fc), name: DeleteFileA, hint: 0
rva: 90368 (0x16100), name: DeleteFileW, hint: 0
rva: 90372 (0x16104), name: DosDateTimeToFileTime, hint: 0
rva: 90376 (0x16108), name: ExitProcess, hint: 0
rva: 90380 (0x1610c), name: ExpandEnvironmentStringsA, hint: 0
rva: 90384 (0x16110), name: FileTimeToLocalFileTime, hint: 0
rva: 90388 (0x16114), name: FileTimeToSystemTime, hint: 0
rva: 90392 (0x16118), name: FindClose, hint: 0
rva: 90396 (0x1611c), name: FindFirstFileA, hint: 0
rva: 90400 (0x16120), name: FindFirstFileW, hint: 0
rva: 90404 (0x16124), name: FindNextFileA, hint: 0
rva: 90408 (0x16128), name: FindNextFileW, hint: 0
rva: 90412 (0x1612c), name: FindResourceA, hint: 0
rva: 90416 (0x16130), name: FreeLibrary, hint: 0
rva: 90420 (0x16134), name: GetCPInfo, hint: 0
rva: 90424 (0x16138), name: GetCommandLineA, hint: 0
rva: 90428 (0x1613c), name: GetCurrentDirectoryA, hint: 0
rva: 90432 (0x16140), name: GetDateFormatA, hint: 0
rva: 90436 (0x16144), name: GetFileAttributesA, hint: 0
rva: 90440 (0x16148), name: GetFileAttributesW, hint: 0
rva: 90444 (0x1614c), name: GetFileType, hint: 0
rva: 90448 (0x16150), name: GetFullPathNameA, hint: 0
rva: 90452 (0x16154), name: GetLastError, hint: 0
rva: 90456 (0x16158), name: GetLocaleInfoA, hint: 0
rva: 90460 (0x1615c), name: GetModuleFileNameA, hint: 0
rva: 90464 (0x16160), name: GetModuleHandleA, hint: 0
rva: 90468 (0x16164), name: GetNumberFormatA, hint: 0
rva: 90472 (0x16168), name: GetProcAddress, hint: 0
rva: 90476 (0x1616c), name: GetProcessHeap, hint: 0
rva: 90480 (0x16170), name: GetStdHandle, hint: 0
rva: 90484 (0x16174), name: GetTempPathA, hint: 0
rva: 90488 (0x16178), name: GetTickCount, hint: 0
rva: 90492 (0x1617c), name: GetTimeFormatA, hint: 0
rva: 90496 (0x16180), name: GetVersionExA, hint: 0
rva: 90500 (0x16184), name: GlobalAlloc, hint: 0
rva: 90504 (0x16188), name: HeapAlloc, hint: 0
rva: 90508 (0x1618c), name: HeapFree, hint: 0
rva: 90512 (0x16190), name: HeapReAlloc, hint: 0
rva: 90516 (0x16194), name: IsDBCSLeadByte, hint: 0
rva: 90520 (0x16198), name: LoadLibraryA, hint: 0
rva: 90524 (0x1619c), name: LocalFileTimeToFileTime, hint: 0
rva: 90528 (0x161a0), name: MoveFileA, hint: 0
rva: 90532 (0x161a4), name: MoveFileExA, hint: 0
rva: 90536 (0x161a8), name: MultiByteToWideChar, hint: 0
rva: 90540 (0x161ac), name: ReadFile, hint: 0
rva: 90544 (0x161b0), name: SetCurrentDirectoryA, hint: 0
rva: 90548 (0x161b4), name: SetEndOfFile, hint: 0
rva: 90552 (0x161b8), name: SetEnvironmentVariableA, hint: 0
rva: 90556 (0x161bc), name: SetFileAttributesA, hint: 0
rva: 90560 (0x161c0), name: SetFileAttributesW, hint: 0
rva: 90564 (0x161c4), name: SetFilePointer, hint: 0
rva: 90568 (0x161c8), name: SetFileTime, hint: 0
rva: 90572 (0x161cc), name: SetLastError, hint: 0
rva: 90576 (0x161d0), name: Sleep, hint: 0
rva: 90580 (0x161d4), name: SystemTimeToFileTime, hint: 0
rva: 90584 (0x161d8), name: WaitForSingleObject, hint: 0
rva: 90588 (0x161dc), name: WideCharToMultiByte, hint: 0
rva: 90592 (0x161e0), name: WriteFile, hint: 0
rva: 90596 (0x161e4), name: lstrcmpiA, hint: 0
rva: 90600 (0x161e8), name: lstrlenA, hint: 0
COMCTL32.DLL
ordinal: 17, rva: 90876 (0x162fc)
COMDLG32.DLL
rva: 90892 (0x1630c), name: CommDlgExtendedError, hint: 0
rva: 90896 (0x16310), name: GetOpenFileNameA, hint: 0
GDI32.DLL
rva: 90916 (0x16324), name: DeleteObject, hint: 0
SHELL32.DLL
rva: 90932 (0x16334), name: SHBrowseForFolderA, hint: 0
rva: 90936 (0x16338), name: SHChangeNotify, hint: 0
rva: 90940 (0x1633c), name: SHFileOperationA, hint: 0
rva: 90944 (0x16340), name: SHGetFileInfoA, hint: 0
rva: 90948 (0x16344), name: SHGetMalloc, hint: 0
rva: 90952 (0x16348), name: SHGetSpecialFolderLocation, hint: 0
rva: 90956 (0x1634c), name: ShellExecuteExA, hint: 0
rva: 90960 (0x16350), name: SHGetPathFromIDListA, hint: 0
USER32.DLL
rva: 91004 (0x1637c), name: CharToOemA, hint: 0
rva: 91008 (0x16380), name: CharToOemBuffA, hint: 0
rva: 91012 (0x16384), name: CharUpperA, hint: 0
rva: 91016 (0x16388), name: CopyRect, hint: 0
rva: 91020 (0x1638c), name: CreateWindowExA, hint: 0
rva: 91024 (0x16390), name: DefWindowProcA, hint: 0
rva: 91028 (0x16394), name: DestroyIcon, hint: 0
rva: 91032 (0x16398), name: DestroyWindow, hint: 0
rva: 91036 (0x1639c), name: DialogBoxParamA, hint: 0
rva: 91040 (0x163a0), name: DispatchMessageA, hint: 0
rva: 91044 (0x163a4), name: EnableWindow, hint: 0
rva: 91048 (0x163a8), name: EndDialog, hint: 0
rva: 91052 (0x163ac), name: FindWindowExA, hint: 0
rva: 91056 (0x163b0), name: GetClassNameA, hint: 0
rva: 91060 (0x163b4), name: GetClientRect, hint: 0
rva: 91064 (0x163b8), name: GetDlgItem, hint: 0
rva: 91068 (0x163bc), name: GetDlgItemTextA, hint: 0
rva: 91072 (0x163c0), name: GetMessageA, hint: 0
rva: 91076 (0x163c4), name: GetParent, hint: 0
rva: 91080 (0x163c8), name: GetSysColor, hint: 0
rva: 91084 (0x163cc), name: GetSystemMetrics, hint: 0
rva: 91088 (0x163d0), name: GetWindow, hint: 0
rva: 91092 (0x163d4), name: GetWindowLongA, hint: 0
rva: 91096 (0x163d8), name: GetWindowRect, hint: 0
rva: 91100 (0x163dc), name: GetWindowTextA, hint: 0
rva: 91104 (0x163e0), name: IsWindow, hint: 0
rva: 91108 (0x163e4), name: IsWindowVisible, hint: 0
rva: 91112 (0x163e8), name: LoadBitmapA, hint: 0
rva: 91116 (0x163ec), name: LoadCursorA, hint: 0
rva: 91120 (0x163f0), name: LoadIconA, hint: 0
rva: 91124 (0x163f4), name: LoadStringA, hint: 0
rva: 91128 (0x163f8), name: MapWindowPoints, hint: 0
rva: 91132 (0x163fc), name: MessageBoxA, hint: 0
rva: 91136 (0x16400), name: OemToCharA, hint: 0
rva: 91140 (0x16404), name: OemToCharBuffA, hint: 0
rva: 91144 (0x16408), name: PeekMessageA, hint: 0
rva: 91148 (0x1640c), name: PostMessageA, hint: 0
rva: 91152 (0x16410), name: RegisterClassExA, hint: 0
rva: 91156 (0x16414), name: SendDlgItemMessageA, hint: 0
rva: 91160 (0x16418), name: SendMessageA, hint: 0
rva: 91164 (0x1641c), name: SetDlgItemTextA, hint: 0
rva: 91168 (0x16420), name: SetFocus, hint: 0
rva: 91172 (0x16424), name: SetMenu, hint: 0
rva: 91176 (0x16428), name: SetWindowLongA, hint: 0
rva: 91180 (0x1642c), name: SetWindowPos, hint: 0
rva: 91184 (0x16430), name: SetWindowTextA, hint: 0
rva: 91188 (0x16434), name: ShowWindow, hint: 0
rva: 91192 (0x16438), name: TranslateMessage, hint: 0
rva: 91196 (0x1643c), name: UpdateWindow, hint: 0
rva: 91200 (0x16440), name: WaitForInputIdle, hint: 0
rva: 91204 (0x16444), name: wsprintfA, hint: 0
rva: 91208 (0x16448), name: wvsprintfA, hint: 0
OLE32.DLL
rva: 91428 (0x16524), name: CLSIDFromString, hint: 0
rva: 91432 (0x16528), name: CoCreateInstance, hint: 0
rva: 91436 (0x1652c), name: CreateStreamOnHGlobal, hint: 0
rva: 91440 (0x16530), name: OleInitialize, hint: 0
rva: 91444 (0x16534), name: OleUninitialize, hint: 0
Resources
*********
address: 0x12a04, size: 0x36b0, language -> ID: 1049, name -> , type -> ID: RT_BITMAP
address: 0x160b4, size: 0x8a8, language -> ID: 1049, name -> ID: 1, type -> ID: RT_ICON
address: 0x1695c, size: 0x568, language -> ID: 1049, name -> ID: 2, type -> ID: RT_ICON
address: 0x16ec4, size: 0x2e8, language -> ID: 1049, name -> ID: 3, type -> ID: RT_ICON
address: 0x171ac, size: 0x128, language -> ID: 1049, name -> ID: 4, type -> ID: RT_ICON
address: 0x172d4, size: 0xd8, language -> ID: 1049, name -> , type -> ID: RT_DIALOG
address: 0x173ac, size: 0x12e, language -> ID: 1049, name -> , type -> ID: RT_DIALOG
address: 0x174dc, size: 0x338, language -> ID: 1049, name -> , type -> ID: RT_DIALOG
address: 0x17814, size: 0x272, language -> ID: 1049, name -> , type -> ID: RT_DIALOG
address: 0x17a88, size: 0x22c, language -> ID: 1049, name -> ID: 7, type -> ID: RT_STRING
address: 0x17cb4, size: 0x376, language -> ID: 1049, name -> ID: 8, type -> ID: RT_STRING
address: 0x1802c, size: 0x200, language -> ID: 1049, name -> ID: 9, type -> ID: RT_STRING
address: 0x1822c, size: 0x10, language -> ID: 0, name -> , type -> ID: RT_RCDATA
address: 0x1823c, size: 0x3e, language -> ID: 1049, name -> ID: 100, type -> ID: RT_GROUP_ICON
address: 0x1827c, size: 0x331, language -> ID: 1049, name -> ID: 1, type -> ID: RT_MANIFEST
Overlay
*******
Overlay at offset 0x18600
Overlay size 0x10cb6a
Anomalies
*********
* Deprecated Characteristic in COFF File Header: IMAGE_FILE_LINE_NUMS_STRIPPED
* Deprecated Characteristic in COFF File Header: IMAGE_FILE_LOCAL_SYMS_STRIPPED
* Optional Header: Size of Headers should be 512, but is 1024
* Section Header 3 with name .idata should (but doesn't) contain the characteristics: Write
Hashes
******
MD5: 54e97d9059e3ba4e4dee6f0433fec960
SHA256: df7509783db57a7ed2b2c794cea04a08f1ca7c289999730c4b914237eeb3b072
Section Type Hash Value
---------------------------------------------------------------------------------------
1. .text MD5 496ecf611b45abe56f64ab3ab495faf3
SHA256 000048859a45a60fbca06ff292250bbc0e7249f85dad368288b573e2dcdd34be
2. .data MD5 23f563d2bed9b8916cb8f7b69b0902de
SHA256 6023c1b0fd34a9e2bf0e1cadc7fe762db6f2986f0094dd92bfa68f5d4dac68c5
3. .idata MD5 ad1f7c6cd9b9a20390018781b70fb1a3
SHA256 078455084d1ff6b9b2b44a940987bf79253307191de75a3a2b3cf64ef863864b
4. .rsrc MD5 03b360092b3b19a3cf43f2c213c54d5c
SHA256 57f13d22be498f7f77bd87afedc8732a550a0c7957ac3e641ef32a3dc2b0ea7eDownload: https://github.com/Doubleendedqueue/Papers/raw/master/peana.jar RE: [HCOfficial] PE Analyzer, Reverse Engineering Tool - h3r0 - 09-10-2014 (09-10-2014, 10:52 AM)tfxla Wrote: Thanks for this. Did you use this? Do you even know the purpose of this tool? Or are you just being a twat and commenting on something to comment on it? Either way Deque thanks for writing this it's an interesting tool and could make for a decent service given that it works on Linux. Code: ~/Desktop/test$ java -jar peana.jar -o data /var/lib/wine-browser-installer/FirefoxSetup.exe
____ _____ _ _
| _ \| ____| / \ _ __ __ _| |_ _ _______ _ __
| |_) | _| / _ \ | '_ \ / _` | | | | |_ / _ \ '__|
| __/| |___ / ___ \| | | | (_| | | |_| |/ / __/ |
|_| _|_____| /_/ _ \_\_| |_|\__,_|_|\__, /___\___|_| _ _
| | | | __ _ ___| | _____ ___ _ __ |___/_ __ ___ _ _ _ __ (_) |_ _ _
| |_| |/ _` |/ __| |/ / __/ _ \| '_ ` _ \| '_ ` _ \| | | | '_ \| | __| | | |
| _ | (_| | (__| < (_| (_) | | | | | | | | | | | |_| | | | | | |_| |_| |
|_| |_|\__,_|\___|_|\_\___\___/|_| |_| |_|_| |_| |_|\__,_|_| |_|_|\__|\__, |
|___/
-by Deque-
Creating report file...
Writing header reports...
Writing section reports...
Writing analysis reports...
Done!
~/Desktop/test$ less dataRE: [HCOfficial] PE Analyzer, Reverse Engineering Tool - Deque - 09-11-2014 (09-10-2014, 09:16 PM)h3r0 Wrote:(09-10-2014, 10:52 AM)tfxla Wrote: Thanks for this. I work on Linux, programmed and tested it mainly on Linux. Does your code-quote mean it didn't work for you? If it didn't, you can help me by giving me the file you tested it with. Or tell me the Firefox version and I try to get it myself. Edit: E.g. I get this for FirefoxSetup 2.0.0.20en Code: Report For Firefox_Setup_2.0.0.20en.exe
***************************************
file size 0x5939b0
full path /home/deque/Downloads/Firefox_Setup_2.0.0.20en.exe
MSDOS Header
************
description value file offset
---------------------------------------------------------------------
signature word 0x5a4d 0x0
last page size 0x90 0x2
file pages 0x3 0x4
relocation items 0x0 0x6
header paragraphs 0x4 0x8
minimum number of paragraphs allocated 0x0 0xa
maximum number of paragraphs allocated 0xffff 0xc
initial SS value 0x0 0xe
initial SP value 0xb8 0x10
complemented checksum 0x0 0x12
initial IP value 0x0 0x14
pre-relocated initial CS value 0x0 0x16
relocation table offset 0x40 0x18
overlay number 0x0 0x1a
Reserved word 0x1c 0x0 0x1c
Reserved word 0x1e 0x0 0x1e
Reserved word 0x20 0x0 0x20
Reserved word 0x22 0x0 0x22
OEM identifier 0x0 0x24
OEM information 0x0 0x26
Reserved word 0x28 0x0 0x28
Reserved word 0x2a 0x0 0x2a
Reserved word 0x2c 0x0 0x2c
Reserved word 0x2f 0x0 0x2e
Reserved word 0x30 0x0 0x30
Reserved word 0x32 0x0 0x32
Reserved word 0x34 0x0 0x34
Reserved word 0x36 0x0 0x36
Reserved word 0x38 0x0 0x38
Reserved word 0x3a 0x0 0x3a
PE signature offset 0xe0 0x3c
COFF File Header
****************
time date stamp Aug 16, 2006 12:27:50 AM
machine type Intel 386 or later processors and compatible processors
characteristics * Image only, Windows CE, and Windows NT and later.
* Machine is based on a 32-bit-word architecture.
* Image only.
* COFF line numbers have been removed. DEPRECATED
* COFF symbol table entries for local symbols have been removed. DEPRECATED
description value file offset
-------------------------------------------------------------------
machine type 0x14c 0xe4
number of sections 0x4 0xe6
time date stamp 0x44e24a66 0xe8
pointer to symbol table (deprecated) 0x0 0xec
number of symbols (deprecated) 0x0 0xf0
size of optional header 0xe0 0xf4
characteristics 0x10f 0xf6
Optional Header
***************
standard field value file offset
-----------------------------------------------------------------------
magic number 0x10b 0xf8
major linker version 0x6 0xfa
minor linker version 0x0 0xfb
size of code 0x12a00 0xfc
size of initialized data 0xb000 0x100
size of unitialized data 0x0 0x104
address of entry point 0x11f3f 0x108
address of base of code 0x1000 0x10c
address of base of data 0x14000 0x110
windows field value file offset
-----------------------------------------------------------------------
image base 0x400000 0x114
section alignment in bytes 0x1000 0x118
file alignment in bytes 0x200 0x11c
major operating system version 0x4 0x120
minor operating system version 0x0 0x122
major image version 0x0 0x124
minor image version 0x0 0x126
major subsystem version 0x4 0x128
minor subsystem version 0x0 0x12a
win32 version value (reserved) 0x0 0x12c
size of image in bytes 0x20000 0x130
size of headers 0x400 0x134
checksum 0x594962 0x138
subsystem 0x2 0x13c
dll characteristics 0x0 0x13e
size of stack reserve 0x100000 0x140
size of stack commit 0x1000 0x144
size of heap reserve 0x100000 0x148
size of heap commit 0x1000 0x14c
loader flags (reserved) 0x0 0x150
number of rva and sizes 0x10 0x154
data directory virtual address size file offset
-----------------------------------------------------------------------
import table 0x170e0 0x8c 0x160
resource table 0x19000 0x6988 0x168
certificate table 0x5923d8 0x15d8 0x178
IAT 0x14000 0x1b4 0x1b8
Section Table
*************
1. .text 2. .rdata 3. .data 4. .rsrc
-----------------------------------------------------------------------------------------
Entropy 0.80 0.52 0.41 0.72
Pointer To Raw Data 0x400 0x12e00 0x16800 0x17000
Size Of Raw Data 0x12a00 0x3a00 0x800 0x6a00
Physical End 0x12e00 0x16800 0x17000 0x1da00
Virtual Address 0x1000 0x14000 0x18000 0x19000
Virtual Size 0x129c2 0x39e2 0xaa4 0x6988
-> actual virtual size 0x13000 0x4000 0x1000 0x7000
Pointer To Relocations 0x0 0x0 0x0 0x0
Number Of Relocations 0x0 0x0 0x0 0x0
Pointer To Line Numbers 0x0 0x0 0x0 0x0
Number Of Line Numbers 0x0 0x0 0x0 0x0
Code x
Initialized Data x x x
Execute x
Write x
Imports
*******
COMCTL32.dll
ordinal: 17, rva: 94572 (0x1716c)
KERNEL32.dll
rva: 94580 (0x17174), name: DeleteCriticalSection, hint: 129
rva: 94584 (0x17178), name: InitializeCriticalSection, hint: 547
rva: 94588 (0x1717c), name: CloseHandle, hint: 52
rva: 94592 (0x17180), name: WaitForMultipleObjects, hint: 910
rva: 94596 (0x17184), name: SetEvent, hint: 790
rva: 94600 (0x17188), name: CreateThread, hint: 111
rva: 94604 (0x1718c), name: WaitForSingleObject, hint: 912
rva: 94608 (0x17190), name: ResetEvent, hint: 719
rva: 94612 (0x17194), name: VirtualAlloc, hint: 897
rva: 94616 (0x17198), name: VirtualFree, hint: 899
rva: 94620 (0x1719c), name: GetModuleHandleA, hint: 383
rva: 94624 (0x171a0), name: MultiByteToWideChar, hint: 629
rva: 94628 (0x171a4), name: WideCharToMultiByte, hint: 916
rva: 94632 (0x171a8), name: GetLastError, hint: 369
rva: 94636 (0x171ac), name: AreFileApisANSI, hint: 12
rva: 94640 (0x171b0), name: GetModuleFileNameA, hint: 381
rva: 94644 (0x171b4), name: GetModuleFileNameW, hint: 382
rva: 94648 (0x171b8), name: LocalFree, hint: 604
rva: 94652 (0x171bc), name: FormatMessageA, hint: 243
rva: 94656 (0x171c0), name: FormatMessageW, hint: 244
rva: 94660 (0x171c4), name: GetWindowsDirectoryA, hint: 499
rva: 94664 (0x171c8), name: SetFileAttributesA, hint: 793
rva: 94668 (0x171cc), name: SetFileAttributesW, hint: 794
rva: 94672 (0x171d0), name: RemoveDirectoryA, hint: 708
rva: 94676 (0x171d4), name: RemoveDirectoryW, hint: 709
rva: 94680 (0x171d8), name: CreateDirectoryA, hint: 75
rva: 94684 (0x171dc), name: CreateDirectoryW, hint: 78
rva: 94688 (0x171e0), name: DeleteFileA, hint: 131
rva: 94692 (0x171e4), name: DeleteFileW, hint: 132
rva: 94696 (0x171e8), name: lstrlenA, hint: 972
rva: 94700 (0x171ec), name: GetFullPathNameA, hint: 361
rva: 94704 (0x171f0), name: GetFullPathNameW, hint: 362
rva: 94708 (0x171f4), name: GetCurrentDirectoryA, hint: 320
rva: 94712 (0x171f8), name: SetCurrentDirectoryA, hint: 778
rva: 94716 (0x171fc), name: GetTempPathA, hint: 469
rva: 94720 (0x17200), name: GetTempFileNameA, hint: 467
rva: 94724 (0x17204), name: FindClose, hint: 206
rva: 94728 (0x17208), name: FindFirstFileA, hint: 210
rva: 94732 (0x1720c), name: FindFirstFileW, hint: 213
rva: 94736 (0x17210), name: FindNextFileA, hint: 220
rva: 94740 (0x17214), name: CreateFileA, hint: 83
rva: 94744 (0x17218), name: CreateFileW, hint: 86
rva: 94748 (0x1721c), name: GetFileSize, hint: 355
rva: 94752 (0x17220), name: SetFilePointer, hint: 795
rva: 94756 (0x17224), name: ReadFile, hint: 693
rva: 94760 (0x17228), name: SetFileTime, hint: 799
rva: 94764 (0x1722c), name: WriteFile, hint: 932
rva: 94768 (0x17230), name: SetEndOfFile, hint: 784
rva: 94772 (0x17234), name: CreateEventA, hint: 79
rva: 94776 (0x17238), name: LeaveCriticalSection, hint: 593
rva: 94780 (0x1723c), name: EnterCriticalSection, hint: 152
rva: 94784 (0x17240), name: Sleep, hint: 854
rva: 94788 (0x17244), name: CreateProcessA, hint: 102
rva: 94792 (0x17248), name: GetCommandLineW, hint: 273
rva: 94796 (0x1724c), name: GetVersionExA, hint: 489
rva: 94800 (0x17250), name: GetStartupInfoA, hint: 439
USER32.dll
rva: 94928 (0x172d0), name: EndDialog, hint: 198
rva: 94932 (0x172d4), name: KillTimer, hint: 437
rva: 94936 (0x172d8), name: PostMessageA, hint: 514
rva: 94940 (0x172dc), name: ShowWindow, hint: 658
rva: 94944 (0x172e0), name: SendMessageA, hint: 571
rva: 94948 (0x172e4), name: GetDlgItem, hint: 273
rva: 94952 (0x172e8), name: MessageBoxW, hint: 486
rva: 94956 (0x172ec), name: SetTimer, hint: 634
rva: 94960 (0x172f0), name: SetWindowTextW, hint: 647
rva: 94964 (0x172f4), name: SetWindowTextA, hint: 646
rva: 94968 (0x172f8), name: LoadStringW, hint: 460
rva: 94972 (0x172fc), name: LoadStringA, hint: 459
rva: 94976 (0x17300), name: DialogBoxParamW, hint: 159
rva: 94980 (0x17304), name: DialogBoxParamA, hint: 158
rva: 94984 (0x17308), name: SetWindowLongA, hint: 640
rva: 94988 (0x1730c), name: GetWindowLongA, hint: 366
rva: 94992 (0x17310), name: CharUpperW, hint: 55
rva: 94996 (0x17314), name: CharUpperA, hint: 52
rva: 95000 (0x17318), name: DestroyWindow, hint: 153
SHELL32.dll
rva: 94920 (0x172c8), name: ShellExecuteExA, hint: 265
OLEAUT32.dll
ordinal: 9, rva: 94908 (0x172bc)
ordinal: 2, rva: 94912 (0x172c0)
MSVCRT.dll
rva: 94808 (0x17258), name: __set_app_type, hint: 129
rva: 94812 (0x1725c), name: __p__fmode, hint: 111
rva: 94816 (0x17260), name: __p__commode, hint: 106
rva: 94820 (0x17264), name: _adjust_fdiv, hint: 157
rva: 94824 (0x17268), name: __setusermatherr, hint: 131
rva: 94828 (0x1726c), name: _initterm, hint: 271
rva: 94832 (0x17270), name: __getmainargs, hint: 88
rva: 94836 (0x17274), name: _acmdln, hint: 143
rva: 94840 (0x17278), name: exit, hint: 585
rva: 94844 (0x1727c), name: _XcptFilter, hint: 72
rva: 94848 (0x17280), name: _exit, hint: 211
rva: 94852 (0x17284), name: _onexit, hint: 390
rva: 94856 (0x17288), name: __dllonexit, hint: 85
rva: 94860 (0x1728c), name: _except_handler3, hint: 202
rva: 94864 (0x17290), name: ??1type_info@@UAE@XZ, hint: 14
rva: 94868 (0x17294), name: memcpy, hint: 663
rva: 94872 (0x17298), name: free, hint: 606
rva: 94876 (0x1729c), name: malloc, hint: 657
rva: 94880 (0x172a0), name: memmove, hint: 664
rva: 94884 (0x172a4), name: memcmp, hint: 662
rva: 94888 (0x172a8), name: _purecall, hint: 402
rva: 94892 (0x172ac), name: _CxxThrowException, hint: 65
rva: 94896 (0x172b0), name: __CxxFrameHandler, hint: 73
rva: 94900 (0x172b4), name: _controlfp, hint: 183
Resources
*********
address: 0x17328, size: 0x128, language -> ID: 1033, name -> ID: 1, type -> ID: RT_ICON
address: 0x17450, size: 0x2e8, language -> ID: 1033, name -> ID: 2, type -> ID: RT_ICON
address: 0x17738, size: 0x668, language -> ID: 1033, name -> ID: 3, type -> ID: RT_ICON
address: 0x17da0, size: 0x568, language -> ID: 1033, name -> ID: 4, type -> ID: RT_ICON
address: 0x18308, size: 0x8a8, language -> ID: 1033, name -> ID: 5, type -> ID: RT_ICON
address: 0x18bb0, size: 0xea8, language -> ID: 1033, name -> ID: 6, type -> ID: RT_ICON
address: 0x19a58, size: 0x468, language -> ID: 1033, name -> ID: 7, type -> ID: RT_ICON
address: 0x19ec0, size: 0x10a8, language -> ID: 1033, name -> ID: 8, type -> ID: RT_ICON
address: 0x1af68, size: 0x25a8, language -> ID: 1033, name -> ID: 9, type -> ID: RT_ICON
address: 0x1d510, size: 0xb8, language -> ID: 1033, name -> ID: 500, type -> ID: RT_DIALOG
address: 0x1d5c8, size: 0x94, language -> ID: 1033, name -> ID: 1, type -> ID: RT_STRING
address: 0x1d65c, size: 0x34, language -> ID: 1033, name -> ID: 5, type -> ID: RT_STRING
address: 0x1d690, size: 0x84, language -> ID: 1033, name -> ID: 159, type -> ID: RT_GROUP_ICON
address: 0x1d714, size: 0x274, language -> ID: 1033, name -> ID: 1, type -> ID: RT_VERSION
Overlay
*******
Overlay at offset 0x1da00
Overlay size 0x575fb0
Anomalies
*********
* Deprecated Characteristic in COFF File Header: IMAGE_FILE_LINE_NUMS_STRIPPED
* Deprecated Characteristic in COFF File Header: IMAGE_FILE_LOCAL_SYMS_STRIPPED
* Optional Header: Size of Headers should be 512, but is 1024
PEID Signatures
***************
[Microsoft Visual C++ v6.0] bytes matched: 32 at address: 70463
Hashes
******
MD5: 404c2851cea380c096ce7c3d96766d8c
SHA256: 8cf8be30a32f99d8b202668da681ce1df5d9883823a734cf6ef1d7c6fbd0ae97
Section Type Hash Value
---------------------------------------------------------------------------------------
1. .text MD5 134ae96a4d2102c3998093cf8d1bbec6
SHA256 a1ddf3c8bd2a47bea8af32865de441a98a1ec8b37c10487cbcfada726d9f8dee
2. .rdata MD5 bd48aee10388c276fc887238cd9773b2
SHA256 d59cd9d01949893539cc4b06d7f6b9d00a4c95034c17ac4aa0487e298065be13
3. .data MD5 8105363d079894d72eb40251b4c9060d
SHA256 6239f49b75d645aa3704f880425bb15b04c5a1eaee4a504d7a39bf4eb414c382
4. .rsrc MD5 cb709c2bb19bc69b9986eb7acda853d0
SHA256 7b82811f5f247e70f6ffac7d943146b6fb6c602a954e6b5d44791efe4c171f32RE: [HCOfficial] PE Analyzer, Reverse Engineering Tool - h3r0 - 09-11-2014 (09-11-2014, 07:23 AM)Deque Wrote: I work on Linux, programmed and tested it mainly on Linux. Oh no it worked fine, 100% out of the box. I was just saying that because I figured it was developed on windows since it is a PE analyzer. Just giving you test results. RE: [HCOfficial] PE Analyzer, Reverse Engineering Tool - Deque - 09-11-2014 (09-11-2014, 05:59 PM)h3r0 Wrote:(09-11-2014, 07:23 AM)Deque Wrote: I work on Linux, programmed and tested it mainly on Linux. Oh, thank you very much then for the feedback. Actually I started to develop it, because most PE parsers are only available for Windows and I did't want to start a VM just for doing a simple check with static analysis. |