J. M. Grau

20 papers Journal 19
YearRankTypeTitle / Venue / Authors
2025 J jnl
Appl. Math. Comput.
L. Bayón, P. Fortuy Ayuso, J. M. Grau, Antonio M. Oller-Marcén, M. M. Ruiz
2022 J jnl
Discret. Appl. Math.
L. Bayón, Pedro Fortuny Ayuso, J. M. Grau, Antonio M. Oller-Marcén, M. M. Ruiz
2019 J jnl
Appl. Math. Comput.
L. Bayón, Pedro Fortuny Ayuso, P. J. García Nieto, J. M. Grau, M. M. Ruiz
2019 J jnl
J. Comb. Optim.
L. Bayón, Pedro Fortuny, J. M. Grau, Antonio M. Oller-Marcén, M. M. Ruiz
2018 J jnl
J. Comb. Optim.
L. Bayón, Pedro Fortuny Ayuso, J. M. Grau, Antonio M. Oller-Marcén, M. M. Ruiz
2017 J jnl
Int. J. Algebra Comput.
Pedro Fortuny, J. M. Grau, Antonio M. Oller-Marcén, Ignacio F. Rúa
2014 J jnl
Int. J. Comput. Math.
L. Bayón, P. J. García Nieto, J. M. Grau, M. M. Ruiz, P. M. Suárez
2013 ch.
Handbook of Optimization
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2013 J jnl
Math. Comput. Model.
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2013 J jnl
Int. J. Comput. Math.
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2012 J jnl
J. Comput. Appl. Math.
Luis Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2011 J jnl
Comput. Math. Appl.
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2011 J jnl
Int. J. Comput. Math.
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2011 J jnl
Appl. Math. Comput.
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2009 J jnl
Appl. Math. Comput.
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2009 J jnl
Numer. Algorithms
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2009 J jnl
Int. J. Comput. Math.
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2008 J jnl
Int. J. Comput. Math.
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2007 J jnl
Appl. Math. Comput.
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
2005 J jnl
IMA J. Math. Control. Inf.
L. Bayón, J. M. Grau, M. M. Ruiz, P. M. Suárez
redb/extractors/pe_extractor.py
← Index redb/extractors/pe_extractor.py python
import logging
from abc import ABCMeta, abstractmethod
import inspect

import magic
import pefile
from dotnetfile import DotNetPE

from redb.extractors.extractor import Extractor

logger = logging.getLogger(__name__)


@abstractmethod
class PEExtractor(Extractor, metaclass=ABCMeta):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious
        )
        self.pe = pe if pe else self._generate_pefile_object()
        self.dotnet = None

    def _generate_pefile_object(self):
        pe = None
        try:
            pe = pefile.PE(self.filepath)
            if not pe:
                raise pefile.PEFormatError("Empty file?")
        except pefile.PEFormatError as e:
            self.log.error(f"Format error {self.hash.sha256} Full error : {e}")
        return pe

    def _generate_dotnetfile_object(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        dotnet = None
        error = None
        try:
            dotnet = DotNetPE(self.filepath)
            if not dotnet:
                raise Exception("Empty file?")
        except Exception as e:
            self.log.error(
                f"Format error dotnet file {self.hash.sha256} Full error : {e}"
            )
            error = e
        return dotnet, error

    def _check_dotnet(self):
        try:
            file_type = magic.from_buffer(self.binary)
            if ".Net" in file_type:
                return True
            for entry in self.pe.OPTIONAL_HEADER.DATA_DIRECTORY:
                # IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR is typically 14
                if (
                    entry.name == "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR"
                    and entry.Size > 0
                ):
                    return True
            return False
        except AttributeError as e:
            self.log.error(
                f"AttributeError error dotnet file {self.hash.sha256} Full error : {e}"
            )
            return False

    def _is_signed(self):
        address = self.pe.OPTIONAL_HEADER.DATA_DIRECTORY[
            pefile.DIRECTORY_ENTRY["IMAGE_DIRECTORY_ENTRY_SECURITY"]
        ].VirtualAddress
        if address == 0:
            return False
        return True

    def _has_overlay(self):
        return bool(self.pe.get_overlay())