This new version of pecheck.py, my tool to analyze PE files, brings some extra information on overlays:

MD5: 8D85E40E4770D9F29C08CBE3D7BE57F0
SHA256: 596848BC8BD03936604212E4CBE9545A03EE629BE6125D08A4E28068F1952961
This new version of pecheck.py, my tool to analyze PE files, brings some extra information on overlays:

RSS feed for comments on this post. TrackBack URI
This site uses Akismet to reduce spam. Learn how your comment data is processed.
[…] Update: pecheck.py Version 0.7.15 […]
Pingback by Week 22 – 2022 – This Week In 4n6 — Sunday 29 May 2022 @ 4:21
[…] jpegdump.py, base64dump.py, pecheck.py, […]
Pingback by James Webb JPEG With Malware – Didier Stevens Videos — Saturday 3 September 2022 @ 7:56
[…] 1768.py, xor-kpa.py, pecheck.py, translate.py, […]
Pingback by An Obfuscated Beacon – Extra XOR Layer – Didier Stevens Videos — Tuesday 6 September 2022 @ 7:59
[…] Tools: base64dump.py, zipdump.py, isodump.py, pecheck.py […]
Pingback by Analysis of a Malicious HTML File (QBot) – Didier Stevens Videos — Thursday 13 October 2022 @ 22:28
[…] pngdump.py, pecheck.py, […]
Pingback by PNG + mimikatz.exe – Didier Stevens Videos — Thursday 13 October 2022 @ 22:40