Sinisterly
pftriage - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools)
+--- Thread: pftriage (/Thread-pftriage)



pftriage - ZanGetsu - 10-16-2017

pftriage is a tool to help analyze files during malware triage. It allows an analyst to quickly view and extract properties of a file to help during the triage process. The tool also has an analyze function which can detect common malicious indicators used by malware.

Dependencies
  • pefile
  • filemagic

Code:
usage: pftriage [options] Show information about a file for triage. positional arguments:  file                  The file to triage. optional arguments:  -h, --help            show this help message and exit  -i, --imports         Display import tree  -s, --sections        Display overview of sections. For more detailed info                        pass the -v switch  --removeoverlay       Remove overlay data.  --extractoverlay      Extract overlay data.  -r, --resources       Display resource informations  -D DUMP_OFFSET, --dump DUMP_OFFSET                        Dump data using the passed offset or 'ALL'. Currently                        only works with resources.  -a, --analyze         Analyze the file.  -v, --verbose         Display version.  -V, --version         Print version and exit.

Analyze

PFTriage can performa a simple analysis of a file to identify malicious characteristics.:

Code:
[*] Loading File... [*] Analyzing File... [*] Analysis Complete...  [!] Checksum        Invalid CheckSum  [!] AntiDebug       AntiDebug Function import [GetTickCount]  [!] AntiDebug       AntiDebug Function import [QueryPerformanceCounter]  [!] Imports         Suspicious API Call [TerminateProcess]  [!] AntiDebug       AntiDebug Function import [SetUnhandledExceptionFilter]  [!] AntiDebug       AntiDebug Function import [IsDebuggerPresent]