본문 바로가기
Python/0x15-immunity-debugger1.85

immunity debugger library 분석 ][ libs > findpacker.py

by SpeeDr00t 2019. 9. 11.
반응형

immunity debugger library 분석 ][ libs > findpacker.py

■ 사용법

#
# test by kyoung chip, jang
# immunity debugger 1.8.5
# Libs > findpacker.py
#
import pefile
import peutils
# Libs > pefile.py > pe
pe = pefile.PE( './Notepad.exe' )
# Data > UserDB.TXT
# Libs > peutils.py > SignatureDatabase
sig_db = peutils.SignatureDatabase('UserDB.TXT')
# Libs > peutils.py > match
ret = sig_db.match( pe )
if not ret :
print(" No Packer found")
else :
for( addr , name ) in ret :
print(" packer found ! : %s at 0x%08x" % ( name , addr ) )
view raw findpacker.py hosted with ❤ by GitHub

UserDB.TXT 위치
pefile.py peutil.py 위치

반응형