Skip to content

Dump PE exports and build a hashtable out of them. Includes proof of concept for API imports by hash.

Notifications You must be signed in to change notification settings

jbramette/HashAPI

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

16 Commits
 
 
 
 
 
 

Repository files navigation

exports.exe - Anti API-hashing tool

This program dumps every exports from given PE files using multi-threading, and builds a hashtable from a user supplied hash function. This is useful when reverse-engineering programs (generally malwares) that use an import-by-hash anti-analysis feature.

Features

  • multi-threading
  • customized hash function via Python
  • JSON format output
  • lazy format output
  • process directories recursively
  • no dependency, except Python

License

MIT

About

Dump PE exports and build a hashtable out of them. Includes proof of concept for API imports by hash.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published