Skip to content

Commit

Permalink
update examples with nicer output, verify
Browse files Browse the repository at this point in the history
  • Loading branch information
dobin committed May 27, 2022
1 parent 8231e8d commit 70849ed
Show file tree
Hide file tree
Showing 11 changed files with 620 additions and 794 deletions.
48 changes: 24 additions & 24 deletions examples/DripLoader.exe.txt
Original file line number Diff line number Diff line change
@@ -1,28 +1,26 @@
[INFO ][2022/05/27 16:37][pe_utils.py: 37] parse_pe() :: Section .text addr: 0x400 size: 79872
[INFO ][2022/05/27 16:37][pe_utils.py: 37] parse_pe() :: Section .rdata addr: 0x13c00 size: 8192
[INFO ][2022/05/27 16:37][pe_utils.py: 37] parse_pe() :: Section .data addr: 0x15c00 size: 1536
[INFO ][2022/05/27 16:37][pe_utils.py: 37] parse_pe() :: Section .pdata addr: 0x16200 size: 1536
[INFO ][2022/05/27 16:37][pe_utils.py: 37] parse_pe() :: Section .rsrc addr: 0x16800 size: 512
[INFO ][2022/05/27 16:37][pe_utils.py: 37] parse_pe() :: Section .reloc addr: 0x16a00 size: 512
[INFO ][2022/05/27 16:37][pe_utils.py: 37] parse_pe() :: Section Ressources addr: 0x19000 size: 480
[INFO ][2022/05/27 16:37][analyzer.py: 69] investigate() :: Section Detection: Zero section (leave all others)
[INFO ][2022/05/27 16:37][analyzer.py:136] findDetectedSections() :: Hide: .text -> Detected: False
[INFO ][2022/05/27 16:37][analyzer.py:136] findDetectedSections() :: Hide: .rdata -> Detected: True
[INFO ][2022/05/27 16:37][analyzer.py:136] findDetectedSections() :: Hide: .data -> Detected: True
[INFO ][2022/05/27 16:37][analyzer.py:136] findDetectedSections() :: Hide: .pdata -> Detected: True
[INFO ][2022/05/27 16:37][analyzer.py:136] findDetectedSections() :: Hide: .rsrc -> Detected: True
[INFO ][2022/05/27 16:37][analyzer.py:136] findDetectedSections() :: Hide: .reloc -> Detected: True
[INFO ][2022/05/27 16:37][analyzer.py:136] findDetectedSections() :: Hide: Ressources -> Detected: True
[INFO ][2022/05/27 16:37][analyzer.py: 77] investigate() :: 1 section(s) trigger the antivirus independantly
[INFO ][2022/05/27 16:37][analyzer.py: 80] investigate() :: section: .text
[INFO ][2022/05/27 16:37][analyzer.py: 95] investigate() :: Launching bytes analysis on section .text
[INFO ][2022/05/27 16:37][reducer_rutd.py: 56] scanSection() :: Result: 76177-76216 (39 bytes)
[INFO ][2022/05/27 16:37][reducer_rutd.py: 61] scanSection() ::
[INFO ][2022/05/27 20:32][pe_utils.py: 37] parse_pe() :: Section .text addr: 0x400 size: 79872
[INFO ][2022/05/27 20:32][pe_utils.py: 37] parse_pe() :: Section .rdata addr: 0x13c00 size: 8192
[INFO ][2022/05/27 20:32][pe_utils.py: 37] parse_pe() :: Section .data addr: 0x15c00 size: 1536
[INFO ][2022/05/27 20:32][pe_utils.py: 37] parse_pe() :: Section .pdata addr: 0x16200 size: 1536
[INFO ][2022/05/27 20:32][pe_utils.py: 37] parse_pe() :: Section .rsrc addr: 0x16800 size: 512
[INFO ][2022/05/27 20:32][pe_utils.py: 37] parse_pe() :: Section .reloc addr: 0x16a00 size: 512
[INFO ][2022/05/27 20:32][pe_utils.py: 37] parse_pe() :: Section Ressources addr: 0x19000 size: 480
[INFO ][2022/05/27 20:32][analyzer.py: 69] investigate() :: Section Detection: Zero section (leave all others)
[INFO ][2022/05/27 20:32][analyzer.py:136] findDetectedSections() :: Hide: .text -> Detected: False
[INFO ][2022/05/27 20:32][analyzer.py:136] findDetectedSections() :: Hide: .rdata -> Detected: True
[INFO ][2022/05/27 20:32][analyzer.py:136] findDetectedSections() :: Hide: .data -> Detected: True
[INFO ][2022/05/27 20:32][analyzer.py:136] findDetectedSections() :: Hide: .pdata -> Detected: True
[INFO ][2022/05/27 20:32][analyzer.py:136] findDetectedSections() :: Hide: .rsrc -> Detected: True
[INFO ][2022/05/27 20:32][analyzer.py:136] findDetectedSections() :: Hide: .reloc -> Detected: True
[INFO ][2022/05/27 20:32][analyzer.py:136] findDetectedSections() :: Hide: Ressources -> Detected: True
[INFO ][2022/05/27 20:32][analyzer.py: 77] investigate() :: 1 section(s) trigger the antivirus independantly
[INFO ][2022/05/27 20:32][analyzer.py: 80] investigate() :: section: .text
[INFO ][2022/05/27 20:32][analyzer.py: 95] investigate() :: Launching bytes analysis on section .text
[INFO ][2022/05/27 20:32][reducer_rutd.py: 58] scanSection() :: Result: 76177-76216 (39 bytes)
00000000: 48 81 C4 98 13 00 00 C3 CC CC CC CC CC CC CC C3 H...............
00000010: 4D 8B C2 49 C7 C2 01 00 00 00 4D 33 D2 49 C7 C2 M..I......M3.I..
00000020: 0A 00 00 00 4C 8B D1 ....L..
[INFO ][2022/05/27 16:37][reducer_rutd.py: 56] scanSection() :: Result: 76216-76372 (156 bytes)
[INFO ][2022/05/27 16:37][reducer_rutd.py: 61] scanSection() ::
[INFO ][2022/05/27 20:32][reducer_rutd.py: 58] scanSection() :: Result: 76216-76372 (156 bytes)
00000000: 33 C0 4D 2B C2 83 C0 18 4D 33 C0 0F 05 C3 48 83 3.M+....M3....H.
00000010: C1 0A 33 C0 4C 8B D1 83 C0 3A 49 83 EA 0A 48 83 ..3.L....:I...H.
00000020: E9 0A 0F 05 C3 49 83 C2 1C 33 C0 4C 8B D1 49 83 .....I...3.L..I.
Expand All @@ -33,8 +31,7 @@
00000070: 00 00 0F 05 48 83 F8 00 0F 84 6A FF FF FF 49 8B ....H.....j...I.
00000080: CC 49 8B D5 4D 8B C6 4D 8B CF 4C 8B D1 48 33 C0 .I..M..M..L..H3.
00000090: 05 BC 00 00 00 0F 05 48 83 F8 00 0F .......H....
[INFO ][2022/05/27 16:37][analyzer.py: 21] analyzeFile() :: [*] Signature between 76177 and 76372 size 195:
[INFO ][2022/05/27 16:37][analyzer.py: 24] analyzeFile() ::
[INFO ][2022/05/27 20:32][analyzer.py: 25] analyzeFile() :: [*] Signature between 76177 and 76372 size 195:
00000000: 48 81 C4 98 13 00 00 C3 CC CC CC CC CC CC CC C3 H...............
00000010: 4D 8B C2 49 C7 C2 01 00 00 00 4D 33 D2 49 C7 C2 M..I......M3.I..
00000020: 0A 00 00 00 4C 8B D1 33 C0 4D 2B C2 83 C0 18 4D ....L..3.M+....M
Expand All @@ -48,3 +45,6 @@
000000A0: 84 6A FF FF FF 49 8B CC 49 8B D5 4D 8B C6 4D 8B .j...I..I..M..M.
000000B0: CF 4C 8B D1 48 33 C0 05 BC 00 00 00 0F 05 48 83 .L..H3........H.
000000C0: F8 00 0F ...
[INFO ][2022/05/27 20:32][analyzer.py: 35] verifyFile() :: Patching file with results...
[INFO ][2022/05/27 20:32][analyzer.py: 39] verifyFile() :: Patch: 76177-76372 size 195
[INFO ][2022/05/27 20:32][analyzer.py: 44] verifyFile() :: Success, not detected!
Loading

0 comments on commit 70849ed

Please sign in to comment.