Manbir Sodhi

14 papers B 1C 1Misc 1Journal 2Unranked 9
YearRankTypeTitle / Venue / Authors
2023 Misc conf
FCCM
Maximilian Jakob Heer, José Quevedo, Marwan F. Abdelatti, Resit Sendag, Manbir Sodhi
2023 conf
GECCO Companion
José Quevedo, Maximilian Jakob Heer, Marwan F. Abdelatti, Resit Sendag, Manbir Sodhi
2022 conf
HPEC
Marwan F. Abdelatti, Manbir Sodhi, Resit Sendag
2021 conf
GECCO Companion
Marwan F. Abdelatti, Abdeltawab M. Hendawi, Manbir Sodhi
2021 conf
GECCO Companion
Justin Fellers, José Quevedo, Marwan F. Abdelatti, Meghan Steinhaus, Manbir Sodhi
2021 J jnl
Comput. Oper. Res.
Mohsen Mosayebi, Manbir Sodhi, Thomas A. Wettergren
2021 conf
GECCO Companion
José Quevedo, Marwan F. Abdelatti, Farhad Imani, Manbir Sodhi
2020 conf
GECCO Companion
Mohsen Mosayebi, Manbir Sodhi
2016 conf
SSCI
Arash Nasrolahi Shirazi, Meghan Steinhaus, Matthew Agostinelli, Manbir Sodhi
2015 conf
CSE
Meghan Steinhaus, Arash Nasrolahi Shirazi, Manbir Sodhi
2010 conf
OR
James Ferguson, Manbir Sodhi
2006 C conf
FUSION
Manbir Sodhi, Peter Swaszek, Edoardo Bovio
2006 J jnl
Comput. Ind. Eng.
Bryan Reimer, Manbir Sodhi, Vaidyanathan Jayaraman
2002 B conf
ETRA
Manbir Sodhi, Bryan Reimer, J. L. Cohen, E. Vastenburg, R. Kaars, Susan S. Kirschenbaum
redb/extractors/pe_extractor.py
← Index redb/extractors/pe_extractor.py python
import logging
from abc import ABCMeta, abstractmethod
import inspect

import magic
import pefile
from dotnetfile import DotNetPE

from redb.extractors.extractor import Extractor

logger = logging.getLogger(__name__)


@abstractmethod
class PEExtractor(Extractor, metaclass=ABCMeta):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious
        )
        self.pe = pe if pe else self._generate_pefile_object()
        self.dotnet = None

    def _generate_pefile_object(self):
        pe = None
        try:
            pe = pefile.PE(self.filepath)
            if not pe:
                raise pefile.PEFormatError("Empty file?")
        except pefile.PEFormatError as e:
            self.log.error(f"Format error {self.hash.sha256} Full error : {e}")
        return pe

    def _generate_dotnetfile_object(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        dotnet = None
        error = None
        try:
            dotnet = DotNetPE(self.filepath)
            if not dotnet:
                raise Exception("Empty file?")
        except Exception as e:
            self.log.error(
                f"Format error dotnet file {self.hash.sha256} Full error : {e}"
            )
            error = e
        return dotnet, error

    def _check_dotnet(self):
        try:
            file_type = magic.from_buffer(self.binary)
            if ".Net" in file_type:
                return True
            for entry in self.pe.OPTIONAL_HEADER.DATA_DIRECTORY:
                # IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR is typically 14
                if (
                    entry.name == "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR"
                    and entry.Size > 0
                ):
                    return True
            return False
        except AttributeError as e:
            self.log.error(
                f"AttributeError error dotnet file {self.hash.sha256} Full error : {e}"
            )
            return False

    def _is_signed(self):
        address = self.pe.OPTIONAL_HEADER.DATA_DIRECTORY[
            pefile.DIRECTORY_ENTRY["IMAGE_DIRECTORY_ENTRY_SECURITY"]
        ].VirtualAddress
        if address == 0:
            return False
        return True

    def _has_overlay(self):
        return bool(self.pe.get_overlay())