Skip to main content

peframe (peframe-ds on pypi)

peframe is an open source tool to perform static analysis on Portable Executable malware and generic suspicious files. It can help malware researchers to detect packers, xor, digital signatures, mutex, anti-debug, anti-virtual machine, suspicious sections and functions, macros and much more.

Prerequisites

The following prerequisites are necessary before you can install and use peframe.

python >= 3.6.6
python3-pip
python3-dev
build-essential
libmagic-dev
libssl-dev
swig

Install Methods

Manual Download and Install

sudo apt install git
git clone https://github.com/digitalsleuth/peframe.git
cd peframe
sudo python3 -m pip install .

One-step Install

sudo python3 -m pip install git+https://github.com/digitalsleuth/peframe.git

OR

sudo python3 -m pip install peframe-ds

Usage

peframe -h

peframe filename            Short output analysis
peframe -i filename         Interactive mode
peframe -j filename         Full output analysis JSON format
peframe -x STRING filename  Search xored string
peframe -s filename         Strings output

Note

You can edit "config-peframe.json" file in "config" folder to configure virustotal API key. After installation you can use "peframe -h" to find api_config path.

How it works

MS Office (macro) document analysis with peframe 6.0.1

image

PE file analysis with peframe 6.0.1

image

Talk about...

Other

This version of peframe is currently maintained by Corey Forman and includes the recent and relevant pull requests from the original repo.

The originator of this software is Gianni 'guelfoweb' Amato, who can be contacted at guelfoweb@gmail.com or twitter @guelfoweb. Suggestions and criticism are welcome.

Metadata

Release files for peframe-ds 7.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for peframe-ds 7.0.0
File Size Uploaded
peframe_ds-7.0.0.tar.gz 861.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for peframe-ds 7.0.0
File Interpreter ABI Platform
peframe_ds-7.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 1.8 MB

Release files / peframe_ds-7.0.0.tar.gz

Download URL peframe_ds-7.0.0.tar.gz
Size 861.5 kB
Tags Source
SHA-256 checksum
How to use checksums
67dfe1303df0e1961c7cf31b2d4bb22a14b5c16193d7563781d54d56a49d86f8
BLAKE2b-256 checksum
How to use checksums
2bd4e240aa6732abb30d2f6d55276b231981bdf99a7cbdb3e08e3d65e9633194
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.12.3

Release files / peframe_ds-7.0.0-py3-none-any.whl

Download URL peframe_ds-7.0.0-py3-none-any.whl
Size 888.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
28c012e7d40590cdd861a402f882db9d464ce6918fb6b9fcb350e6922e38e830
BLAKE2b-256 checksum
How to use checksums
3773cdde012fc0f91cf2b6e6c8c2711c808af945e56506f94d7b375b873e1436
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

7.0.0 This release

2 release files

6.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page