It is currently Mon Dec 18, 2017 12:49 am

All times are UTC - 8 hours




Post new topic Reply to topic  [ 18 posts ]  Go to page 1, 2  Next
Author Message
 Post subject: PPEE - Professional PE file Explorer
PostPosted: Fri Apr 22, 2016 11:45 am 
Offline

Joined: Sat Jun 23, 2012 4:28 pm
Posts: 454
https://mzrst.com/

Quote:
PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details.
Puppy is free and tries to be small, fast, nimble and friendly as your puppy!

Features
Puppy is robust against malformed and crafted PE files which makes it handy for reversers, malware researchers and those who want to inspect PE files in more details. All directories in a PE file including Export, Import, Resource, Exception, Certificate(Relies on Windows API), Base Relocation, Debug, TLS, Load Config, Bound Import, IAT, Delay Import and CLR are supported.

  • Both PE32 and PE64 support
  • Parsing exe, dll, sys, scr, drv, cpl, ocx and more
  • Entropy and MD5 calculation of the sections and resource items
  • View strings embedded in files
  • Built in hex editor
  • Edit most of the data directory structures
  • Descriptive information for data members
  • Refresh, Save and Save as menu commands
  • List view columns can sort data in an appropriate way
  • Plugin enabled

There are lots of tools out there for statically analyzing malicious binaries, but they are ordinary tools for ordinary files. Puppy is a lightweight yet strong tool for static investigation of suspicious files. A companion plugin is also provided to take one-click technical information about the file such as its size, entropy, attributes, hashes, version info and so on.


Image
Image
Image
Image
Image
Image

DL - https://mzrst.com/puppy/PPEE(puppy)%201.05.zip (91.44 KB)
Portable/Stealth
Alternative to corrupted pestudio


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Fri Apr 22, 2016 5:54 pm 
Offline
User avatar

Joined: Thu Aug 07, 2008 4:51 am
Posts: 4139
That is a nice find; thanks for posting about PPEE, billon.

Tested v1.05: Portable

billon wrote:
Alternative to corrupted pestudio


That is an unfair comment :evil:

_________________
Bəəs 2.0


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Thu Jul 07, 2016 11:04 pm 
Offline

Joined: Sat Jun 23, 2012 4:28 pm
Posts: 454
Current version: 1.06 (2016-07-08)

Quote:
  • GUI is improved
  • Anomaly detection added
  • Check update menu item added
  • Toolbar and Statusbar Added
  • Added RightClick context menu to copy or search
  • Dump Sections, Resources and .Net assembly directories
  • Separated items for URL, Registry, File strings
  • Minor bugs in .Net directory fixed
  • Fuzzy hash(ssdeep) support by plugin


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Fri Jul 08, 2016 5:16 am 
Offline
User avatar

Joined: Mon Dec 07, 2009 7:09 am
Posts: 3887
Location: Sol3
I completely missed this topic. PPEE (Puppy? Looks like peepee from here... :oops:) is a great find. Will test ASAP. 8)


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Fri Jul 08, 2016 7:30 am 
Offline

Joined: Wed Jun 26, 2013 2:09 am
Posts: 413
Good find indeed.

Only annoyance so far: lacking tooltips for a few non-intuitive toolbar icons.
Just dropped PPEE's developer a suggestion to remedy this minor lapse.


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Fri Jul 08, 2016 1:11 pm 
Offline

Joined: Sat Apr 08, 2006 7:12 pm
Posts: 480
Location: Illinois/Indiana
79kB download, 93kB installed. Very fast and snappy. Works on XP too.


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Sun Jul 10, 2016 4:31 am 
Offline

Joined: Wed Jun 26, 2013 2:09 am
Posts: 413
A little bird told me PPEE tooltips are forthcoming...

Ask and thou shalt be given, and there will be joy forever after... ;-)


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Sat Sep 10, 2016 11:12 am 
Offline

Joined: Sat Jun 23, 2012 4:28 pm
Posts: 454
Current version: 1.07 (2016-09-10)

Quote:
- Virustotal and OPSWAT's Metadefender query report is added to the plugin (Without submitting the file)
- Suspicious strings treeview item added (Customizable via Suspicious.txt file)
- Timedate stamp now shown in UTC standard, with days passed
- Statusbar shows basic PE info
- Minor bug fixes


From ReadMe.txt:
Quote:
Greetings
--------------
... __philippe ...

:)


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Sun Sep 11, 2016 7:25 am 
Offline

Joined: Wed Jun 26, 2013 2:09 am
Posts: 413
@billon

Cor Blimey, the little bird did come home to roost indeed...;-)


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Sun Oct 09, 2016 12:38 pm 
Offline
User avatar

Joined: Sat Jun 22, 2013 3:24 am
Posts: 1770
Location: Aeaea
When I try to open PPEE web-site I got a warning that This Connection is Untrusted.


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Sun Oct 09, 2016 1:20 pm 
Offline
User avatar

Joined: Thu Jul 14, 2011 9:42 am
Posts: 170
Location: Island of Lost Minds
smaragdus wrote:
When I try to open PPEE web-site I got a warning that This Connection is Untrusted.

Looks like their TLS certificate expired this Sunday:
Quote:
mzrst.com verwendet ein ungültiges Sicherheitszertifikat.
Das Zertifikat ist am Sonntag, 9. Oktober 2016 01:59 abgelaufen. Die aktuelle Zeit ist Sonntag, 9. Oktober 2016 22:56.

They will need to buy a new certificate for their domain. Or switch to a free service like "Let's Encrypt", which will constantly renew your certificate...

_________________
„One of my most productive days was throwing away 1,000 lines of code“ – Ken Thompson

Dreamatorium | In Search Of The Disembodied Sounds | Best Regards!


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Wed Oct 12, 2016 6:37 pm 
Offline
User avatar

Joined: Sat Jun 22, 2013 3:24 am
Posts: 1770
Location: Aeaea
@deathcubek
Thanks for the detailed explanation. Now PPEE web-site is back to normal.


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Wed Dec 21, 2016 7:07 pm 
Offline

Joined: Sat Jun 23, 2012 4:28 pm
Posts: 454
Added to the database, please vote


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Thu Dec 22, 2016 2:56 am 
Offline

Joined: Wed Jun 26, 2013 2:09 am
Posts: 413
Voted.

Tiny PPEE (108kb) has supplanted PEstudio (3Mb) as my preferred PE explorer utility.
Looking forward to future updates.


Top
 Profile  
 
 Post subject: Re: PPEE - Professional PE file Explorer
PostPosted: Thu Dec 22, 2016 5:49 pm 
Offline
User avatar

Joined: Sat Jun 22, 2013 3:24 am
Posts: 1770
Location: Aeaea
@billon
Thank you for taking your time to add Professional PE Explorer to the database, its place there is well-deserved.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 18 posts ]  Go to page 1, 2  Next

All times are UTC - 8 hours


Who is online

Users browsing this forum: No registered users and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Protected by Anti-Spam ACP Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group