Xiaobing Gan

15 papers Journal 2Unranked 13
YearRankTypeTitle / Venue / Authors
2023 conf
WHICEB (2)
Xiaobing Gan, Ting Guo, Yang Wang, Zhenzhen Zhu, Yongjie Zhou
2022 conf
ICSI (1)
Xiaobing Gan, Tianwei Zhou, Yuhan Mai, Huifen Zhong, Xiuyun Zhang, Qinge Xiao
2020 conf
ICIC (2)
Xiaobing Gan, Baoyu Xiao
2020 conf
ICSI
Xiaobing Gan, Baoyu Xiao
2020 conf
ICEME
Xiaobing Gan, Baoyu Xiao, Chuhan Wang
2018 conf
ICSI (1)
Xiaobing Gan, Entao Jiang, Yingying Peng, Shuang Geng, Mijat Kustudic
2018 conf
DMBD
Xiaobing Gan, Yanmin Jiao, Lei Liu, Yanhua Zhang
2016 conf
ICSI (2)
Xiaobing Gan, L. J. Liu, J. S. Chen, Ben Niu
2015 conf
ICIC (2)
Xiaobing Gan, Lijiao Liu, Ben Niu, Lijing Tan, Fangfang Zhang, Jing Liu
2014 J jnl
J. Intell. Inf. Syst.
Feng Pan, Guangwei Song, Xiaobing Gan, Qiwei Gu
2014 conf
ICIC (2)
Xiaobing Gan, Junbiao Kuang, Ben Niu
2013 conf
ICIC (2)
Xiaobing Gan, Yan Wang, Ye Yu, Ben Niu
2013 J jnl
J. Comput.
Xiaobing Gan, Jingyi Wang
2007 conf
ESCAPE
Xiaobing Gan, Yanhong Gu, George L. Vairaktarakis, Xiaoqiang Cai, Quanle Chen
2005 conf
CIS (1)
Xiaobing Gan, Ying Liu, Francis R. Austin
redb/extractors/pe_extractor.py
← Index redb/extractors/pe_extractor.py python
import logging
from abc import ABCMeta, abstractmethod
import inspect

import magic
import pefile
from dotnetfile import DotNetPE

from redb.extractors.extractor import Extractor

logger = logging.getLogger(__name__)


@abstractmethod
class PEExtractor(Extractor, metaclass=ABCMeta):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious
        )
        self.pe = pe if pe else self._generate_pefile_object()
        self.dotnet = None

    def _generate_pefile_object(self):
        pe = None
        try:
            pe = pefile.PE(self.filepath)
            if not pe:
                raise pefile.PEFormatError("Empty file?")
        except pefile.PEFormatError as e:
            self.log.error(f"Format error {self.hash.sha256} Full error : {e}")
        return pe

    def _generate_dotnetfile_object(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        dotnet = None
        error = None
        try:
            dotnet = DotNetPE(self.filepath)
            if not dotnet:
                raise Exception("Empty file?")
        except Exception as e:
            self.log.error(
                f"Format error dotnet file {self.hash.sha256} Full error : {e}"
            )
            error = e
        return dotnet, error

    def _check_dotnet(self):
        try:
            file_type = magic.from_buffer(self.binary)
            if ".Net" in file_type:
                return True
            for entry in self.pe.OPTIONAL_HEADER.DATA_DIRECTORY:
                # IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR is typically 14
                if (
                    entry.name == "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR"
                    and entry.Size > 0
                ):
                    return True
            return False
        except AttributeError as e:
            self.log.error(
                f"AttributeError error dotnet file {self.hash.sha256} Full error : {e}"
            )
            return False

    def _is_signed(self):
        address = self.pe.OPTIONAL_HEADER.DATA_DIRECTORY[
            pefile.DIRECTORY_ENTRY["IMAGE_DIRECTORY_ENTRY_SECURITY"]
        ].VirtualAddress
        if address == 0:
            return False
        return True

    def _has_overlay(self):
        return bool(self.pe.get_overlay())