-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathpyPEOF.py
61 lines (50 loc) · 2.23 KB
/
pyPEOF.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
import os
import argparse
from pefile import PE, PEFormatError
def main():
parser = argparse.ArgumentParser()
parser.add_argument("-f", "--file", required=True,
type=open, help="PE file to read")
args = parser.parse_args()
file = args.file
print("[+] Reading PE file...")
try:
image_size = 0
pefile = PE(file.name)
# check if pe file is valid,e_magic must be 0x5a4d
if (hex(pefile.DOS_HEADER.e_magic) != "0x5a4d"):
print("[+] PE file is invalid!")
else:
print("[+] PE file is valid!")
architecture = 32 if hex(pefile.FILE_HEADER.Machine) == "0x14c" else 64
print("[+] Image architecture is %sbit." % architecture)
# adding the IMAGE_DIRERCTORY_ENTRY_SECURITY if target application is signed otherwise the full image size wont match.
image_size += (pefile.OPTIONAL_HEADER.SizeOfHeaders +
pefile.OPTIONAL_HEADER.DATA_DIRECTORY[4].Size)
# enumerate each section and add to current mesured image size.
for section in pefile.sections:
image_size += section.SizeOfRawData
AFileSize = os.path.getsize(file.name)
eof_size = (AFileSize - image_size)
if eof_size > 0: # checking if eof data is present in target file.
print("[+] %s bytes of EOF data detected." % eof_size)
# read eof data #
file.seek(-eof_size, 2)
eof_data = file.read(eof_size)
prompt = input(
"Do you want to print the EOF data? (y/n): ")
if prompt == "y" or prompt == "yes":
print("[+] Printing EOF data: \n%s" % eof_data)
prompt = input("Do you want to dump the EOF data? (y/n): ")
if prompt == "y" or prompt == "yes":
with open("%s.dump" % file.name, "wb") as dump:
dump.write(eof_data)
print("[+] EOF data successfully dumped!")
else:
print("[+] No EOF data detected.")
except PEFormatError:
print("Are you sure you're trying to read a PE file?")
except OSError:
print("[+] %s does not exist or is inaccessible." % file.name)
if __name__ == "__main__":
main()