This new version of pecheck.py adds option -l to carve embedded PE files. This will be explained in detail in an upcoming blog post.
pecheck-v0_7_7.zip (https)
MD5: CEFCCC094EF9E29A539092A6ECB77EEE
SHA256: 91041D17A39C7FA4151830AF8FBD151680A04FC617CB0EADDA32D240E9AB9C03
[…] pecheck.py is an open-source tool to analyze PE files. It has an option (-l –locate) to search and select embedded PE files. Using option -l P on the embedded PNG file provides us with an overview of all embedded PE files: […]
Pingback by Malicious Spreadsheet Dropping a DLL – NVISO Labs — Wednesday 18 September 2019 @ 11:29
[…] Update: pecheck.py Version 0.7.7 […]
Pingback by Week 38 – 2019 – This Week In 4n6 — Sunday 22 September 2019 @ 7:56
[…] Update: pecheck.py Version 0.7.7 […]
Pingback by Overview of Content Published in September | Didier Stevens — Tuesday 1 October 2019 @ 0:00