Sucop virus analysis tool(File Format Identifier) v1.4

 http://www.google.cn/language_tools Dacheng world - Data Security Laboratory (DSW LABS) products This tool is a supplementary tool for the analysis of the virus, including file format recognition, the use of the format of Super Patrol Recognition Engine, set check carcasses, virtual machine Shelling, PE document editing, PE document reconstruction, grasping into Table admission (with some decrypt encrypted virtual machine into Table), the process of memory read / DUMP, additional data processing, the paper addresses conversion, PEID plug-in support, and MD5 quick calculation using the third-party tools, and other functions, suitable for analysis of virus Some of the Trojan virus samples for processing. The software products for free software, and non-commercial users can download, install, copy and distribute the software products. If the need for commercial sales, reproduce and distribute, such as anti-virus company to mass analysis Trojans, DSWLAB must have the authority and permission, commercial companies and team use the software must be DSWLAB authorization and permission. V1.4 new features: ★ automatic access into the new table function, the function of the use of virtual machine technology to the implementation of virtual table into the acquisition, with automatic encryption function that can easily access ImportREC unable to obtain the correct import table. (See section 9 below) to the function of the idea of more people welcome to contact us. ★ increase in more detail description of the PE file more detailed analysis of the wrong file / document invalid PE / PE unenforceable document reports wrong reasons. Pedro Lopez thanked the proposal this feature. ★ skin new features to make more beautiful interface can be set up to switch between their favorite style of the skin. Thank fly (unpack.cn) proposes this feature. ★ expand the integration Fly signatures collected the signatures. Thank fly (unpack.cn) authorized. ★ BUG several other amendments. V1.3 new features: ★ increase process Show, the termination function, supports three methods ump Full dump, and the Dump Region Dump Partial support automatically correct image size memory modules. (See section 8 below) V1.2 new features: ★ full support of plug-in function PEID. Use of the need to set up designated Load Plugins PEid can use the plug-in functions, without reopening FFI, plug-ins must be put plugins directory, set up after a good point Plugin>> you can see the corresponding plug-ins. ★ increased support for the reconstruction of PE function to repair damaged PE many documents, or after the document could not be re-Sabot Jiake situation. V1.1 new features: ★ increased use VMUnpacker Shelling engine shell function, the shell can be identified directly Unpack button click Remove to facilitate analysis Jiake Trojans, this version Shelling Shelling engine capacity equivalent to VMUnpacker V1.4. ★ Additional data on the increase in the handling of additional data can be deleted or stored document to facilitate further analysis. ★ increase PE documents address translation function can be conveniently converted RAV <-> RAW. Features detailed as follows: First, check Shell features: Supporting documents, drag, drag directory can be set up right on the files and directories searches shell function, in addition to the unpack.avd FFI since Shelled, but also can be used to expand the shell (to be named userdb.txt, the format of this PEID compatible with the format can be collected their shell userdb.txt Add to enhance detection function). Note: If you are using expanded Curry characteristics identified carcasses will be back in the shell * information signs. Second, the shell functions: If the check carcasses, Unpack buttons available, can be said of the current processing documents shell with a virtual machine sabot technology, you do not have to worry about dealing with the current document may endanger the system. Third, PE editing features: This procedure shows that the main interface can be checked at the entrance of the procedure / point of entry physical migration, section, and other information, and provide a powerful editing features. PE Section button which can later edit the current file of the table, after clicking on the Sections Editor window. Main features are: ★ show detailed segmental information ★ editor section to see the name, size, the implementation of attributes, and other related information. ★ remove the selected section title ★ with automated restoration of the section ★ from disk loading section ★ preservation section to disk ★ add a new section ★ deleted from the document section ★ first deleted from the PE section (section substance also) ★ filled with the specified data section SubSystem button after PE document can show detailed information to support detailed edit documents Dos PE first, NT priority information, support Show PE documents export tables, import sheet information, the project features too meticulous please refer to specific interface. Fourth, additional data detection: Application procedures can be scanned annex contains data, and to provide additional data in detail the initial location and size, can be used Del Overlay button and Save Overlay button corresponding treatment. 5. PEid support plug-ins: Point Options button to select Load Plugins PEid can use the plug-in functions, without reopening FFI, plug-ins must be put plugins directory, and then Plugin>> you can see the corresponding plug-in information. 6. ReBuild PE functions: This function is primarily used for the shell after the PE file repair, can be used to solve general Shelling Jiake after such issues can not be re-used ReguildPE button this feature. 7, third-party tools support: In the Options button, point Manage Tools button can be used to shortcut menu Add / Remove IDA / OllyDBG and other third-party tools, and that can be activated directly in the FFI, OllyDBG, IDA these tools to open the current file an anti-compilation. Note: Add third-party tools, point Plugin> "button can be seen on the tools you add the information, click on the tool can be used to open the documents. 8. Process DUMP: Point TaskView button, the process can be terminated, the process of the dump memory module currently supports three methods ump Full dump, and the Dump Partial Dump Region, also supports automatically correct image size of the main memory module. 9, crawl into Table: Get IAT button points, after the selection process can crawl into form, please fill in the former DumpFixer OEP correct information. If there can not be a function of identification information, you can set up virtual machine decryption step, in the form of information into the box by right point to decrypt the VM Decode function If you find crawling into the table some of the information is not what you want, in the form of information into the box by right point Del Thunk or Cut Thunk let disappear. If you are in the process of non-main module crawl into form, please Manipulation records window in the corresponding module information point right Load this module so that the crawl into this table is the module. 10, contact us at: If you encounter any problems or have any proposals, or we need to add new features, you can point Email to us send e-mail to us, if you think the current processing of documents on improving our FFI functions or revise its bug useful, can also treat it as Annex sent to us. http://u6.dswlab.com/ffi.zip http://rapidshare.com/files/91523894/ffi.zip
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
超级巡警病毒分析 File Format Identifier(自动查壳脱壳) v1.53 汉化中文版 本工具是一款辅助进行病毒分析的工具,它包括各种文件格式识别功能,使用超级巡警的格式识别引擎,集查壳、虚拟机脱壳、PE文件编辑、PE文件重建、导入表抓取(内置虚拟机解密某些加密导入表)、进程内存查看/DUMP、附加数据处理、文件地址转换、PEID插件支持、MD5计算以及快捷的第三方工具利用等功能,适合病毒分析中对一些病毒木马样本进行系统处理。 本软件产品为免费软件,用户可以非商业性地下载、安装、复制和散发本软件产品。如果需要进行商业性的销售、复制和散发,例如反病毒公司用来批量分析木马,必须获得DSWLAB的授权和许可,商业公司及团队使用本软件必须获得DSWLAB的授权和许可。 作为辅助进行病毒分析的工具,它包括各种文件格式识别功能,使用超级巡警的格式识别引擎,集查壳、虚拟机脱壳、PE文件编辑、PE文件重建、导入表抓取(内置虚拟机解密某些加密导入表)、进程内存查看/DUMP、附加数据处理、文件地址转换、PEID插件支持、MD5计算以及快捷的第三方工具利用等功能,适合病毒分析中对一些病毒木马样本进行系统处理。 V1.4新增功能: ★新增自动获取导入表功能,该功能使用虚拟机虚拟执行技术来进行导入表的获取,具备自动解密功能,可以轻松获取ImportREC无法正确获取的导入表。(详见下面节九)对该功能有更多想法的人欢迎联系我们。 ★增加的更多的细节描述,对PE文件进行更细致的解析,对错误文件/无效的PE文件/无法执行的PE文件报告错误原因。感谢Pedro Lopez建议此功能。 ★新增皮肤功能,使得界面更漂亮,可在设置中切换自己喜欢的皮肤风格。感谢fly(unpack.cn)建议此功能。 ★扩展签名库集成Fly收集的签名库。感谢fly(unpack.cn)授权。 ★其他几个BUG修正。 V1.3新增功能: ★增加进程查看、终止功能,支持三种dump方式:Dump Full、Dump Partial和Dump Region,支持自动修正模块内存镜像大小。(详见下面节八) V1.2新增功能: ★全面支持PEID插件功能。使用前需要在设置中指定Load Plugins就可以使用PEid的插件功能,无需重启FFI,插件必须放plugins目录下,设置好后点Plugin>>就可看到相应插件。 ★增加支持重建PE的功能,用以修复许多损坏的PE文件,或者脱壳后文件无法重新加壳的情况。 V1.1新增功能: ★增加使用VMUnpacker脱壳引擎进行脱壳的功能,对识别出来的壳可直接点击Unpack按钮脱掉,方便分析加壳木马,本版本脱壳引擎脱壳能力等同于VMUnpacker V1.4 。 ★增加对附加数据的处理,可将附加数据直接删除或者保存为文件,方便进一步分析。 ★增加PE文件的地址转换功能,可方便的换算RAV<->RAW 。 详细功能说明如下: 一、查壳功能: 支持文件拖拽,目录拖拽,可设置右键对文件和目录的查壳功能,除了FFI自带壳库unpack.avd外,还可以使用扩展壳库(必须命名为userdb.txt,此库格式兼容PEID库格式,可以把自己收集的userdb.txt放入增强壳检测功能)。 注:如果是使用扩展库里特征查出的壳,在壳信息后面会有 * 标志。 二、脱壳功能: 如果在查壳后,Unpack按钮可用,则表示可以对当前处理文件进行脱壳处理,采用虚拟机脱壳技术,您不必担心当前处理文件可能危害系统。 三、PE编辑功能: 本程序主界面可显示被检查的程序的入口点/入口点物理偏移,区段等信息,并且提供强大的编辑功能。 其中PE Section后按钮可以编辑当前文件的节表,点击后出现Sections Editor窗口。 主要功能有: ★显示详细的节段信息 ★可查看编辑区段名称、大小、执行属性等相关信息。 ★清除选定的区段名称 ★对区段进行自动修复 ★从磁盘加载区段 ★保存区段到磁盘 ★增加一个新的区段 ★从文件中删除区段 ★从PE头中删除区段(区段内容实质还在) ★用指定的数据填充区段 SubSystem后按钮可以显示PE文件的详细信息,支持详细编辑PE文件的Dos头,NT头等信息,支持查看PE文件的导出表、导入表信息,本项目功能太细致具体请参考界面。 四、附加数据检测: 可扫描应用程序是否包含附件数据,并提供了附加数据详细的起始位置和大小,可以用Del Overlay按钮和Save Overlay按钮进行相应的处理。 五、支持PEid插件: 点Options按钮选择Load Plugins就可以使用PEid的插件功能,无需重启FFI,插件必须放plugins目录下,然后点Plugin>>就可看到相应插件信息。 六、ReBuild PE 功能: 本功能主要是用来对脱壳后的PE文件进行修复,一般可用来解决脱壳后无法重新加壳等问题,使用ReguildPE按钮即可完成此功能。 七、第三方工具支持: 在Options按钮中,点Manage Tools按钮,可以用右键菜单添加/删除IDA/OllyDBG等第三方工具,这样就可以直接在FFI里启动OllyDBG、IDA这些工具来打开当前文件进行反汇编。 注:添加第三方工具后,点Plugin>>按钮就可以看到您添加的工具信息了,点击即可用此工具打开当前处理文件。 八、进程DUMP: 点TaskView按钮后,可以进行进程的终止,进程中模块内存的dump,目前支持三种dump方式:Dump Full、Dump Partial和Dump Region,还支持自动修正主模块内存镜像大小。 九、导入表抓取: 点Get IAT按钮后,选择进程后就可以抓取导入表,在DumpFixer前请填上正确的OEP信息。 如果出现不可识别的函数信息,您可以设置虚拟机解密步数,在导入表信息框中用右键点VM Decode尝试解密这个函数 如果您发现抓取的导入表信息有些不是您想要的,可以在导入表信息框中用右键点Del Thunk或者Cut Thunk让其消失。 如果您要对进程的非主模块抓取导入表,请在Manipulation records窗口中对相应模块信息点右键Load this module,这样抓取的导入表就是这个模块的了。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值