-
-
[转帖]PE-bear v0.7.0
-
发表于: 2024-9-15 06:42 2917
-
PE-bear v0.7.0
PE-bear is a multiplatform reversing tool for PE files with a friendly GUI.
Its objective is to deliver fast and flexible “first view” for malware analysts, stable and capable to handle malformed PE files.
Features
• handles PE32 and PE64
• views multiple files in parallel
• recognizes known packers (by signatures)
• fast disassembler – starting from any chosen RVA/File offset
• visualization of sections layout
• selective comparing of two chosen PE files
• adding new elements (sections, imports)
• and more…
V0.7.0 (2024-09-14)
FEATURE
• Updated to build with Qt6
• Added support for ARM64 PEs
• New icon
• Upgraded sig_finder: faster search; allow for patterns with masked nibbles
BUGFIX
• Allow to open files from Unicode paths from the Explorer menu (and commandline) ( Issue #56 )
• Fixed invalid mapping of NT 3.1 executables ( Issue #45 )
• Fixed wrong interpretation of the section flag ( Issue #54 )
PE-bear
97bK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Z5M7$3S2J5P5X3c8Q4x3X3g2%4L8%4u0V1M7s2u0W2M7%4y4Q4x3X3g2U0L8$3#2Q4x3V1k6H3k6g2)9J5k6r3u0W2j5i4u0Q4x3V1j5`.
e7fK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6Z5j5i4y4Z5k6i4u0W2P5X3q4V1k6g2)9J5c8Y4m8W2i4K6u0V1j5X3g2S2M7R3`.`.
156K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6Z5j5i4y4Z5k6i4u0W2P5X3q4V1k6g2)9J5c8Y4m8W2i4K6u0V1j5X3g2S2M7W2)9J5c8Y4u0W2L8r3g2S2M7$3g2K6
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课