<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[الفريق العربي للهندسة العكسية - برامج فحص الملفات - PE Scanning Tools]]></title>
		<link>https://www.at4re.net/f/</link>
		<description><![CDATA[الفريق العربي للهندسة العكسية - https://www.at4re.net/f]]></description>
		<pubDate>Fri, 01 May 2026 17:41:31 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Detect It Easy 3.20 New Version]]></title>
			<link>https://www.at4re.net/f/thread-5138.html</link>
			<pubDate>Tue, 21 Apr 2026 22:35:32 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=279">vosiyons</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-5138.html</guid>
			<description><![CDATA[<div style="text-align: center;" class="mycode_align">[+] Build instructions for openSuse, Fedora, Arch Linux, WSL<br />
[+] Improved Heuristic module for PE by DosX_dev<br />
[+] New detects and optimization of all scripts (thanks to DosX_dev, hypn0, Kae, BJNFNE and all contributors)<br />
[+] New scanning method: PEiD<br />
[+] Some GUI changes<br />
[+] Many bugs have been fixed<br />
[+] Add AVX2 and SSE2 optimisation</div><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/txt.png" title="Text Document" border="0" alt=".txt" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=3598" target="_blank" title="">Detect It Easy 3.20 New Version.txt</a> (الحجم : 205 bytes / التحميلات : 2)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;" class="mycode_align">[+] Build instructions for openSuse, Fedora, Arch Linux, WSL<br />
[+] Improved Heuristic module for PE by DosX_dev<br />
[+] New detects and optimization of all scripts (thanks to DosX_dev, hypn0, Kae, BJNFNE and all contributors)<br />
[+] New scanning method: PEiD<br />
[+] Some GUI changes<br />
[+] Many bugs have been fixed<br />
[+] Add AVX2 and SSE2 optimisation</div><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/txt.png" title="Text Document" border="0" alt=".txt" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=3598" target="_blank" title="">Detect It Easy 3.20 New Version.txt</a> (الحجم : 205 bytes / التحميلات : 2)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[ExeinfoPE v0.0.9.5 [ViP]]]></title>
			<link>https://www.at4re.net/f/thread-5109.html</link>
			<pubDate>Thu, 02 Apr 2026 17:51:15 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=3511">sadwide</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-5109.html</guid>
			<description><![CDATA[The latest version of the ExeinfoPE tool for detecting compression or protection<br />
 <br />
<pre class="block-code line-numbers"><code class="language-none">https://github.com/ExeinfoASL/ASL/releases
</code></pre>]]></description>
			<content:encoded><![CDATA[The latest version of the ExeinfoPE tool for detecting compression or protection<br />
 <br />
<pre class="block-code line-numbers"><code class="language-none">https://github.com/ExeinfoASL/ASL/releases
</code></pre>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[PE API Replacer]]></title>
			<link>https://www.at4re.net/f/thread-4923.html</link>
			<pubDate>Wed, 17 Dec 2025 01:55:46 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=6230">altair</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-4923.html</guid>
			<description><![CDATA[أداة واجهة مستخدم رسومية احترافية لاستبدال استيرادات واجهة برمجة التطبيقات في ملفات PE (EXE، DLL، VST، SYS). معالجة مجمعة لملفات Windows القابلة للتنفيذ باستخدام IAT وتصحيح سداسي عشري، ونسخ احتياطية تلقائية، وتسجيل تفصيلي. مصممة باستخدام PyQt6.<br />
<img src="https://i.ibb.co/21LYQQMM/2uxmdlkj.png" loading="lazy"  alt="[صورة مرفقة: 2uxmdlkj.png]" class="mycode_img" /><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/txt.png" title="Text Document" border="0" alt=".txt" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=3491" target="_blank" title="">PE API Replacer.txt</a> (الحجم : 73 bytes / التحميلات : 3)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[أداة واجهة مستخدم رسومية احترافية لاستبدال استيرادات واجهة برمجة التطبيقات في ملفات PE (EXE، DLL، VST، SYS). معالجة مجمعة لملفات Windows القابلة للتنفيذ باستخدام IAT وتصحيح سداسي عشري، ونسخ احتياطية تلقائية، وتسجيل تفصيلي. مصممة باستخدام PyQt6.<br />
<img src="https://i.ibb.co/21LYQQMM/2uxmdlkj.png" loading="lazy"  alt="[صورة مرفقة: 2uxmdlkj.png]" class="mycode_img" /><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/txt.png" title="Text Document" border="0" alt=".txt" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=3491" target="_blank" title="">PE API Replacer.txt</a> (الحجم : 73 bytes / التحميلات : 3)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Detect It Easy (DiE)]]></title>
			<link>https://www.at4re.net/f/thread-4825.html</link>
			<pubDate>Thu, 13 Nov 2025 17:05:50 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=2469">capcom2008</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-4825.html</guid>
			<description><![CDATA[<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">Detect It Easy (DiE)</span> is a powerful tool for file type identification, popular among <span style="font-weight: bold;" class="mycode_b">malware analysts</span>, <span style="font-weight: bold;" class="mycode_b">cybersecurity experts</span>, and <span style="font-weight: bold;" class="mycode_b">reverse engineers</span> worldwide. Supporting both <span style="font-weight: bold;" class="mycode_b">signature-based</span> and <span style="font-weight: bold;" class="mycode_b">heuristic analysis</span>, DiE enables efficient file inspections across a broad range of platforms, including <span style="font-weight: bold;" class="mycode_b">Windows, Linux, and MacOS</span>. Its adaptable, script-driven detection architecture makes it one of the most versatile tools in the field, with a comprehensive list of supported OS images.<br />
<img src="https://github.com/horsicq/Detect-It-Easy/raw/master/docs/1.png" loading="lazy"  alt="[صورة مرفقة: 1.png]" class="mycode_img" /><br />
Download link from Github<br />
<a href="https://github.com/horsicq/DIE-engine/releases/download/3.10/die_win64_portable_3.10_x64.zip" target="_blank" rel="noopener" class="mycode_url">https://github.com/horsicq/DIE-engine/re...10_x64.zip</a></div>]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">Detect It Easy (DiE)</span> is a powerful tool for file type identification, popular among <span style="font-weight: bold;" class="mycode_b">malware analysts</span>, <span style="font-weight: bold;" class="mycode_b">cybersecurity experts</span>, and <span style="font-weight: bold;" class="mycode_b">reverse engineers</span> worldwide. Supporting both <span style="font-weight: bold;" class="mycode_b">signature-based</span> and <span style="font-weight: bold;" class="mycode_b">heuristic analysis</span>, DiE enables efficient file inspections across a broad range of platforms, including <span style="font-weight: bold;" class="mycode_b">Windows, Linux, and MacOS</span>. Its adaptable, script-driven detection architecture makes it one of the most versatile tools in the field, with a comprehensive list of supported OS images.<br />
<img src="https://github.com/horsicq/Detect-It-Easy/raw/master/docs/1.png" loading="lazy"  alt="[صورة مرفقة: 1.png]" class="mycode_img" /><br />
Download link from Github<br />
<a href="https://github.com/horsicq/DIE-engine/releases/download/3.10/die_win64_portable_3.10_x64.zip" target="_blank" rel="noopener" class="mycode_url">https://github.com/horsicq/DIE-engine/re...10_x64.zip</a></div>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[فحص أصدارة البرامج و ملفات الـ DLL المشابة و مقارنة الأصدارات الخاصة بها]]></title>
			<link>https://www.at4re.net/f/thread-4615.html</link>
			<pubDate>Thu, 26 Jun 2025 20:30:33 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=3325">H@wk0</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-4615.html</guid>
			<description><![CDATA[الأداة File Ver أداة مجانية مفيدة عند الرغبة في معرفة الأصدارات المختلفة من ملف Exe أو DLL متوفر في جهازك و مقارنته مع كل الأصدارات المختلفة من نفس الملف من حيث الأصدار و الحجم و موقع الملفات المشابة في الجهاز.<br />
<br />
أداة خفيفة و سريعة ..<br />
 <br />
<div style="text-align: center;" class="mycode_align"><img src="https://i.ibb.co/3mGL2LG6/screenshot.png" loading="lazy"  width="400" height="458" alt="[صورة مرفقة: screenshot.png]" class="mycode_img" /></div>
رابط البرنامج:<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php">https://www.nodesoft.com/filever
</code></pre>]]></description>
			<content:encoded><![CDATA[الأداة File Ver أداة مجانية مفيدة عند الرغبة في معرفة الأصدارات المختلفة من ملف Exe أو DLL متوفر في جهازك و مقارنته مع كل الأصدارات المختلفة من نفس الملف من حيث الأصدار و الحجم و موقع الملفات المشابة في الجهاز.<br />
<br />
أداة خفيفة و سريعة ..<br />
 <br />
<div style="text-align: center;" class="mycode_align"><img src="https://i.ibb.co/3mGL2LG6/screenshot.png" loading="lazy"  width="400" height="458" alt="[صورة مرفقة: screenshot.png]" class="mycode_img" /></div>
رابط البرنامج:<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php">https://www.nodesoft.com/filever
</code></pre>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[الأداة Dumpbin.exe]]></title>
			<link>https://www.at4re.net/f/thread-4614.html</link>
			<pubDate>Thu, 26 Jun 2025 17:21:58 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=3325">H@wk0</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-4614.html</guid>
			<description><![CDATA[الكثير يعاني من عدم توفر بعض الأدوات لدية لفحص الملفات المستهدفة و بالذات ملفات الـ DLL، في حين ان البعض الأخر يخشى أستخدام بعض الأدوات المتعارف عليها في مجال الهندسة العكسية لعدة أسباب منها الخوف أن تكون مصابة بفيروس ما أو ملغمة ببرامج خبيثة. خاصة المتوفر منها على بعض المواقع الأجنبية الغير موثوقة. و اليوم سنتكلم عن أداة جميلة و بسيطة و رسمية من شركة مايكروسوفت تدعى Dumpbin.exe.<br />
<br />
تتوفر هذه الأداة ضمن الأدوات المتوفرة مع برنامج ++Visual Studio C، و يمكن تفعيلها أثناء عملية التنصيب:<br />
 <br />
<div style="text-align: center;" class="mycode_align"><img src="https://i.ibb.co/M5B7yT98/DkZLR.png" loading="lazy"  width="230" height="322" alt="[صورة مرفقة: DkZLR.png]" class="mycode_img" /></div>
<div style="text-align: right;" class="mycode_align">
<br />
و يمكن تشغيل الأداة من Visual Studio Command Prompt أو من خلال أستخدام رابط مثل:<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php">&quot;C:\Program Files\Microsoft Visual Studio\2022\Professional\VC\Tools\MSVC\14.43.34808\bin\Hostx86\x86\dumpbin.exe&quot;
</code></pre><div style="text-align: left;" class="mycode_align"> </div>
و هذا المسار بالمناسبة خاص بالأصدارة VS C++ 2022.<br />
<br />
أحد الأستخدامات الجميلة لهذه الأداة هو الخيار Export:<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php"> dumpbin.exe /exports xyz.dll
</code></pre><br />
و هذا مثال لأحد نتائج هذا الخيار:<br />
 <br />
<div style="text-align: center;" class="mycode_align"><img src="https://i.ibb.co/vgHbYfN/Screenshot-2025-06-26-200723.png" loading="lazy"  width="400" height="350" alt="[صورة مرفقة: Screenshot-2025-06-26-200723.png]" class="mycode_img" /></div>
<br />
و الخيارات الأخرى المتاحة تشمل ما يلي:<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php">/ALL
/ARCHIVEMEMBERS
/CLRHEADER
/DEPENDENTS
/DIRECTIVES
/DISASM[:{BYTES|NOBYTES}]
/ERRORREPORT:{NONE|PROMPT|QUEUE|SEND} (Deprecated)
/EXPORTS
/FPO
/HEADERS
/IMPORTS[:filename]
/LINENUMBERS
/LINKERMEMBER[:{1|2}]
/LOADCONFIG
/NOPDB
/OUT:filename
/PDATA
/PDBPATH[:VERBOSE]
/RANGE:vaMin[,vaMax]
/RAWDATA[:{NONE|1|2|4|8}[,#]]
/RELOCATIONS
/SECTION:name
/SUMMARY
/SYMBOLS
/TLS
</code></pre><br />
هذه الأداة بسيطة ولا تعد أفضل من الأدوات الأخرى المتخصصة في هذا المجال و لكنها قد تكون في متناول اليد بسهولة و أستخدامها آمن في بعض الظروف التي يصعب فيها التحقق من سلامة الأدوات المتواجدة على الأنترنت أو في حال الأضطرار إلى أستخدامها في بيئة نظام التشغيل الأساسي و ليس الوهمي، حيث قد يكون أستخدام الأدوات الأخرى محفوف بالمخاطر، أو أن مكافح الفيروسات المتوفر لديك قد يسبب أشكالات مع الأدوات الأخرى.<br />
<br />
</div>]]></description>
			<content:encoded><![CDATA[الكثير يعاني من عدم توفر بعض الأدوات لدية لفحص الملفات المستهدفة و بالذات ملفات الـ DLL، في حين ان البعض الأخر يخشى أستخدام بعض الأدوات المتعارف عليها في مجال الهندسة العكسية لعدة أسباب منها الخوف أن تكون مصابة بفيروس ما أو ملغمة ببرامج خبيثة. خاصة المتوفر منها على بعض المواقع الأجنبية الغير موثوقة. و اليوم سنتكلم عن أداة جميلة و بسيطة و رسمية من شركة مايكروسوفت تدعى Dumpbin.exe.<br />
<br />
تتوفر هذه الأداة ضمن الأدوات المتوفرة مع برنامج ++Visual Studio C، و يمكن تفعيلها أثناء عملية التنصيب:<br />
 <br />
<div style="text-align: center;" class="mycode_align"><img src="https://i.ibb.co/M5B7yT98/DkZLR.png" loading="lazy"  width="230" height="322" alt="[صورة مرفقة: DkZLR.png]" class="mycode_img" /></div>
<div style="text-align: right;" class="mycode_align">
<br />
و يمكن تشغيل الأداة من Visual Studio Command Prompt أو من خلال أستخدام رابط مثل:<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php">&quot;C:\Program Files\Microsoft Visual Studio\2022\Professional\VC\Tools\MSVC\14.43.34808\bin\Hostx86\x86\dumpbin.exe&quot;
</code></pre><div style="text-align: left;" class="mycode_align"> </div>
و هذا المسار بالمناسبة خاص بالأصدارة VS C++ 2022.<br />
<br />
أحد الأستخدامات الجميلة لهذه الأداة هو الخيار Export:<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php"> dumpbin.exe /exports xyz.dll
</code></pre><br />
و هذا مثال لأحد نتائج هذا الخيار:<br />
 <br />
<div style="text-align: center;" class="mycode_align"><img src="https://i.ibb.co/vgHbYfN/Screenshot-2025-06-26-200723.png" loading="lazy"  width="400" height="350" alt="[صورة مرفقة: Screenshot-2025-06-26-200723.png]" class="mycode_img" /></div>
<br />
و الخيارات الأخرى المتاحة تشمل ما يلي:<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php">/ALL
/ARCHIVEMEMBERS
/CLRHEADER
/DEPENDENTS
/DIRECTIVES
/DISASM[:{BYTES|NOBYTES}]
/ERRORREPORT:{NONE|PROMPT|QUEUE|SEND} (Deprecated)
/EXPORTS
/FPO
/HEADERS
/IMPORTS[:filename]
/LINENUMBERS
/LINKERMEMBER[:{1|2}]
/LOADCONFIG
/NOPDB
/OUT:filename
/PDATA
/PDBPATH[:VERBOSE]
/RANGE:vaMin[,vaMax]
/RAWDATA[:{NONE|1|2|4|8}[,#]]
/RELOCATIONS
/SECTION:name
/SUMMARY
/SYMBOLS
/TLS
</code></pre><br />
هذه الأداة بسيطة ولا تعد أفضل من الأدوات الأخرى المتخصصة في هذا المجال و لكنها قد تكون في متناول اليد بسهولة و أستخدامها آمن في بعض الظروف التي يصعب فيها التحقق من سلامة الأدوات المتواجدة على الأنترنت أو في حال الأضطرار إلى أستخدامها في بيئة نظام التشغيل الأساسي و ليس الوهمي، حيث قد يكون أستخدام الأدوات الأخرى محفوف بالمخاطر، أو أن مكافح الفيروسات المتوفر لديك قد يسبب أشكالات مع الأدوات الأخرى.<br />
<br />
</div>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[ExeinfoPE v0.0.9.0 - 1214  181 - x64 signatures]]></title>
			<link>https://www.at4re.net/f/thread-4605.html</link>
			<pubDate>Mon, 16 Jun 2025 17:15:34 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=4830">karakoro</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-4605.html</guid>
			<description><![CDATA[<div style="text-align: center;" class="mycode_align"><img src="https://www.at4re.net/f/images/smilies/Salam.gif" alt="Salam" title="Salam" class="smilie smilie_72" /><br />
اخر اصدار من اداة  ExeinfoPE للكشف عن الضغط  او الحماية</div>
<div style="text-align: center;" class="mycode_align">ExeinfoPE v0.0.9.0 - 1214  181 - x64 signatures</div>
<div style="text-align: center;" class="mycode_align">
<br />
<img src="https://i.ibb.co/GfKQM68g/exeinfo-screen.png" loading="lazy"  alt="[صورة مرفقة: exeinfo-screen.png]" class="mycode_img" /></div><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/txt.png" title="Text Document" border="0" alt=".txt" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=3224" target="_blank" title="">link.txt</a> (الحجم : 111 bytes / التحميلات : 6)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;" class="mycode_align"><img src="https://www.at4re.net/f/images/smilies/Salam.gif" alt="Salam" title="Salam" class="smilie smilie_72" /><br />
اخر اصدار من اداة  ExeinfoPE للكشف عن الضغط  او الحماية</div>
<div style="text-align: center;" class="mycode_align">ExeinfoPE v0.0.9.0 - 1214  181 - x64 signatures</div>
<div style="text-align: center;" class="mycode_align">
<br />
<img src="https://i.ibb.co/GfKQM68g/exeinfo-screen.png" loading="lazy"  alt="[صورة مرفقة: exeinfo-screen.png]" class="mycode_img" /></div><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/txt.png" title="Text Document" border="0" alt=".txt" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=3224" target="_blank" title="">link.txt</a> (الحجم : 111 bytes / التحميلات : 6)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Armadillo_x64_Tools]]></title>
			<link>https://www.at4re.net/f/thread-4245.html</link>
			<pubDate>Sat, 11 Jan 2025 12:37:23 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=64">TeRcO</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-4245.html</guid>
			<description><![CDATA[<img src="https://i.imgur.com/kshiGYV.png" loading="lazy"  alt="[صورة مرفقة: kshiGYV.png]" class="mycode_img" /><br />
 <br />
<pre class="block-code line-numbers"><code class="language-none">1.  Armadillo x64 Inline Patch ECDSA Verify v0.2 - inline ECDSA signature patcher, supports EXE and DLL protected by Armadillo x64.

2. Armadillo x64 Version Info v0.1 - version and protection options detection, supports EXE and DLL protected by Armadillo x64.

Programming language - assembler.

Support all versions of Armadillo x64, up to 9.64

</code></pre><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/zip.gif" title="ZIP File" border="0" alt=".zip" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=2881" target="_blank" title="">Armadillo_x64_Tools.zip</a> (الحجم : 48.17 KB / التحميلات : 34)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[<img src="https://i.imgur.com/kshiGYV.png" loading="lazy"  alt="[صورة مرفقة: kshiGYV.png]" class="mycode_img" /><br />
 <br />
<pre class="block-code line-numbers"><code class="language-none">1.  Armadillo x64 Inline Patch ECDSA Verify v0.2 - inline ECDSA signature patcher, supports EXE and DLL protected by Armadillo x64.

2. Armadillo x64 Version Info v0.1 - version and protection options detection, supports EXE and DLL protected by Armadillo x64.

Programming language - assembler.

Support all versions of Armadillo x64, up to 9.64

</code></pre><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/zip.gif" title="ZIP File" border="0" alt=".zip" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=2881" target="_blank" title="">Armadillo_x64_Tools.zip</a> (الحجم : 48.17 KB / التحميلات : 34)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Exeinfo PE O.O.8.3 by A.S.L- 1183+169 sign 2024.01.02]]></title>
			<link>https://www.at4re.net/f/thread-4035.html</link>
			<pubDate>Mon, 20 May 2024 09:56:11 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=1777">sitifis</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-4035.html</guid>
			<description><![CDATA[<span style="color: #3498db;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Exeinfo PE O.O.8.3 by A.S.L- 1183+169 sign 2024.01.02</span></span><br />
<br />
<br />
<img src="https://i.postimg.cc/bJ9FwbZ8/Exeinfo.png" loading="lazy"  alt="[صورة مرفقة: Exeinfo.png]" class="mycode_img" /><br />
<br />
 Added pack .lzma , .lzma Undetectable , .lzma unpacker<br />
config : added [Internet Browset ] change to user path<br />
Viewer : added [ Save to File - window log ]<br />
fixed VMprotect v3.5+<br />
added : Inno unpacker script view<br />
Exe Rippers - save to created Directory : !Rip_exe_{file_name}<br />
added overlay detector l + section ovl scan [ Python .Zlib Archive "PYZ"<br />
added Function : Detect_BoxedApp_SDK32<br />
Ripper .7z xor FF - fixed , detect crypted 7z v.0.4 in Advanced Installer [ v19.x ]<br />
Set Buffer for exe file : 336 MB<br />
Lzma packer ( now you can send malware file via gmail ) :<br />
exeinfope.exe FileName /plzma - pack file with lzma packer ( 7z compatible )<br />
for many files ( mask files ) :<br />
console mode - exeinfope.exe FileName* /plzma - pack file with lzma packer<br />
Lzma unpacker :<br />
exeinfope.exe FileName /ulzma - unpack file with lzma packer ( 7z compatible )<br />
for many files ( mask files ) :<br />
console mode - exeinfope.exe FileName* /ulzma - unpack file with lzma packer<br />
update Obsidium v1.5 - 1.8.2.2<br />
added detector for DLL 32bit : [ plugin for : AutoPlay Media Studio ] v8.5 <a href="http://www.indigorose.com/" target="_blank" rel="noopener" class="mycode_url">http://www.indigorose.com</a><br />
added detector for DLL 64bit : [ .PYD Python C Extensions library ]<br />
added console mode :<br />
unpack all exe files and Inno script from InnoSetup installer<br />
( work only if you don't have installed Inno Extractor - Exeinfo Pe internal unpacker )<br />
parameter example : exeinfope.exe file_name /unp-inno-exe<br />
added Skater v24.2.0.51 2024 ( protected DLL still not detected )<br />
Delphi version resolver Added ( not 100% ) :<br />
Delphi XE7 - v10.4 , Delphi v10.4 Sydney , Delphi v10.4 Rio , Delphi v11.0 Alexandria , Delphi v12 Yukon , Delphi v10.2 Tokyo , Delphi v10.1 Berlin<br />
added Config GUI : Wow64 redirect<br />
added [Internet Browset ] change to user path<br />
added Inno extractor - view inno script<br />
added to NOT EXE - .7z 7-ZIP Archive v.0.4<br />
[ AES - detected - password required ]<br />
[ Mode : DEFLATE ]<br />
[ Mode : P7Z_BCJ ]<br />
[ Mode : LZMA:21 BCJ ]<br />
added detector for protected 7zip : Ripper don't ripp "protected .7z archives by CryptoNickSof"<br />
but Exeinfo PE detect it !<br />
and others ...<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php">https://github.com/ExeinfoASL/ASL/releases/tag/exeinfo
</code></pre>]]></description>
			<content:encoded><![CDATA[<span style="color: #3498db;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Exeinfo PE O.O.8.3 by A.S.L- 1183+169 sign 2024.01.02</span></span><br />
<br />
<br />
<img src="https://i.postimg.cc/bJ9FwbZ8/Exeinfo.png" loading="lazy"  alt="[صورة مرفقة: Exeinfo.png]" class="mycode_img" /><br />
<br />
 Added pack .lzma , .lzma Undetectable , .lzma unpacker<br />
config : added [Internet Browset ] change to user path<br />
Viewer : added [ Save to File - window log ]<br />
fixed VMprotect v3.5+<br />
added : Inno unpacker script view<br />
Exe Rippers - save to created Directory : !Rip_exe_{file_name}<br />
added overlay detector l + section ovl scan [ Python .Zlib Archive "PYZ"<br />
added Function : Detect_BoxedApp_SDK32<br />
Ripper .7z xor FF - fixed , detect crypted 7z v.0.4 in Advanced Installer [ v19.x ]<br />
Set Buffer for exe file : 336 MB<br />
Lzma packer ( now you can send malware file via gmail ) :<br />
exeinfope.exe FileName /plzma - pack file with lzma packer ( 7z compatible )<br />
for many files ( mask files ) :<br />
console mode - exeinfope.exe FileName* /plzma - pack file with lzma packer<br />
Lzma unpacker :<br />
exeinfope.exe FileName /ulzma - unpack file with lzma packer ( 7z compatible )<br />
for many files ( mask files ) :<br />
console mode - exeinfope.exe FileName* /ulzma - unpack file with lzma packer<br />
update Obsidium v1.5 - 1.8.2.2<br />
added detector for DLL 32bit : [ plugin for : AutoPlay Media Studio ] v8.5 <a href="http://www.indigorose.com/" target="_blank" rel="noopener" class="mycode_url">http://www.indigorose.com</a><br />
added detector for DLL 64bit : [ .PYD Python C Extensions library ]<br />
added console mode :<br />
unpack all exe files and Inno script from InnoSetup installer<br />
( work only if you don't have installed Inno Extractor - Exeinfo Pe internal unpacker )<br />
parameter example : exeinfope.exe file_name /unp-inno-exe<br />
added Skater v24.2.0.51 2024 ( protected DLL still not detected )<br />
Delphi version resolver Added ( not 100% ) :<br />
Delphi XE7 - v10.4 , Delphi v10.4 Sydney , Delphi v10.4 Rio , Delphi v11.0 Alexandria , Delphi v12 Yukon , Delphi v10.2 Tokyo , Delphi v10.1 Berlin<br />
added Config GUI : Wow64 redirect<br />
added [Internet Browset ] change to user path<br />
added Inno extractor - view inno script<br />
added to NOT EXE - .7z 7-ZIP Archive v.0.4<br />
[ AES - detected - password required ]<br />
[ Mode : DEFLATE ]<br />
[ Mode : P7Z_BCJ ]<br />
[ Mode : LZMA:21 BCJ ]<br />
added detector for protected 7zip : Ripper don't ripp "protected .7z archives by CryptoNickSof"<br />
but Exeinfo PE detect it !<br />
and others ...<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php">https://github.com/ExeinfoASL/ASL/releases/tag/exeinfo
</code></pre>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Exeinfo 0.0.8.3]]></title>
			<link>https://www.at4re.net/f/thread-3807.html</link>
			<pubDate>Tue, 09 Apr 2024 07:29:32 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=2483">motaghred</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-3807.html</guid>
			<description><![CDATA[<div style="text-align: left;" class="mycode_align">Added pack .lzma , .lzma Undetectable , .lzma unpacker</div>
<div style="text-align: left;" class="mycode_align">config : added [Internet Browset ] change to user path</div>
<div style="text-align: left;" class="mycode_align">Viewer : added [ Save to File - window log ]</div>
<div style="text-align: left;" class="mycode_align">fixed VMprotect v3.5+</div>
<div style="text-align: left;" class="mycode_align">added : Inno unpacker script view</div>
<div style="text-align: left;" class="mycode_align">Exe Rippers - save to created Directory : !Rip_exe_{file_name}</div>
<div style="text-align: left;" class="mycode_align">added overlay detector l + section ovl scan [ Python .Zlib Archive "PYZ"</div>
<div style="text-align: left;" class="mycode_align">added Function : Detect_BoxedApp_SDK32</div>
<div style="text-align: left;" class="mycode_align">Ripper .7z xor FF - fixed , detect crypted 7z v.0.4 in Advanced Installer [ v19.x ]</div>
<div style="text-align: left;" class="mycode_align">Set Buffer for exe file : 336 MB</div>
<div style="text-align: left;" class="mycode_align">Lzma packer ( now you can send malware file via gmail ) :<br />
exeinfope.exe FileName /plzma - pack file with lzma packer ( 7z compatible )<br />
for many files ( mask files ) :<br />
console mode - exeinfope.exe FileName* /plzma - pack file with lzma packer</div>
<div style="text-align: left;" class="mycode_align">Lzma unpacker :<br />
exeinfope.exe FileName /ulzma - unpack file with lzma packer ( 7z compatible )<br />
for many files ( mask files ) :<br />
console mode - exeinfope.exe FileName* /ulzma - unpack file with lzma packer</div>
<div style="text-align: left;" class="mycode_align">update Obsidium v1.5 - 1.8.2.2</div>
<div style="text-align: left;" class="mycode_align">added detector for DLL 32bit : [ plugin for : AutoPlay Media Studio ] v8.5 <a href="http://www.indigorose.com/" target="_blank" rel="noopener" class="mycode_url">http://www.indigorose.com</a></div>
<div style="text-align: left;" class="mycode_align">added detector for DLL 64bit : [ .PYD Python C Extensions library ]</div>
<div style="text-align: left;" class="mycode_align">added console mode :<br />
unpack all exe files and Inno script from InnoSetup installer<br />
( work only if you don't have installed Inno Extractor - Exeinfo Pe internal unpacker )<br />
parameter example : exeinfope.exe file_name /unp-inno-exe</div>
<div style="text-align: left;" class="mycode_align">added Skater v24.2.0.51 2024 ( protected DLL still not detected )</div>
<div style="text-align: left;" class="mycode_align">Delphi version resolver Added ( not 100% ) :<br />
Delphi XE7 - v10.4 , Delphi v10.4 Sydney , Delphi v10.4 Rio , Delphi v11.0 Alexandria , Delphi v12 Yukon , Delphi v10.2 Tokyo , Delphi v10.1 Berlin</div>
<div style="text-align: left;" class="mycode_align">added Config GUI : Wow64 redirect<br />
added [Internet Browset ] change to user path</div>
<div style="text-align: left;" class="mycode_align">added Inno extractor - view inno script</div>
<div style="text-align: left;" class="mycode_align">added to NOT EXE - .7z 7-ZIP Archive v.0.4<br />
[ AES - detected - password required ]<br />
[ Mode : DEFLATE ]<br />
[ Mode : P7Z_BCJ ]<br />
[ Mode : LZMA:21 BCJ ]</div>
<div style="text-align: left;" class="mycode_align">added detector for protected 7zip : Ripper don't ripp "protected .7z archives by CryptoNickSof"<br />
but Exeinfo PE detect it !</div>
<div style="text-align: left;" class="mycode_align">
and others ...<br />
<br />
<a href="https://github.com/ExeinfoASL/ASL/releases/tag/exeinfo" target="_blank" rel="noopener" class="mycode_url">https://github.com/ExeinfoASL/ASL/releases/tag/exeinfo</a></div><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/rar.png" title="RAR File" border="0" alt=".rar" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=2753" target="_blank" title="">exeinfope 0.0.8.3.part1.rar</a> (الحجم : 1 MB / التحميلات : 14)
<!-- end: postbit_attachments_attachment --><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/rar.png" title="RAR File" border="0" alt=".rar" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=2754" target="_blank" title="">exeinfope 0.0.8.3.part2.rar</a> (الحجم : 946.98 KB / التحميلات : 16)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[<div style="text-align: left;" class="mycode_align">Added pack .lzma , .lzma Undetectable , .lzma unpacker</div>
<div style="text-align: left;" class="mycode_align">config : added [Internet Browset ] change to user path</div>
<div style="text-align: left;" class="mycode_align">Viewer : added [ Save to File - window log ]</div>
<div style="text-align: left;" class="mycode_align">fixed VMprotect v3.5+</div>
<div style="text-align: left;" class="mycode_align">added : Inno unpacker script view</div>
<div style="text-align: left;" class="mycode_align">Exe Rippers - save to created Directory : !Rip_exe_{file_name}</div>
<div style="text-align: left;" class="mycode_align">added overlay detector l + section ovl scan [ Python .Zlib Archive "PYZ"</div>
<div style="text-align: left;" class="mycode_align">added Function : Detect_BoxedApp_SDK32</div>
<div style="text-align: left;" class="mycode_align">Ripper .7z xor FF - fixed , detect crypted 7z v.0.4 in Advanced Installer [ v19.x ]</div>
<div style="text-align: left;" class="mycode_align">Set Buffer for exe file : 336 MB</div>
<div style="text-align: left;" class="mycode_align">Lzma packer ( now you can send malware file via gmail ) :<br />
exeinfope.exe FileName /plzma - pack file with lzma packer ( 7z compatible )<br />
for many files ( mask files ) :<br />
console mode - exeinfope.exe FileName* /plzma - pack file with lzma packer</div>
<div style="text-align: left;" class="mycode_align">Lzma unpacker :<br />
exeinfope.exe FileName /ulzma - unpack file with lzma packer ( 7z compatible )<br />
for many files ( mask files ) :<br />
console mode - exeinfope.exe FileName* /ulzma - unpack file with lzma packer</div>
<div style="text-align: left;" class="mycode_align">update Obsidium v1.5 - 1.8.2.2</div>
<div style="text-align: left;" class="mycode_align">added detector for DLL 32bit : [ plugin for : AutoPlay Media Studio ] v8.5 <a href="http://www.indigorose.com/" target="_blank" rel="noopener" class="mycode_url">http://www.indigorose.com</a></div>
<div style="text-align: left;" class="mycode_align">added detector for DLL 64bit : [ .PYD Python C Extensions library ]</div>
<div style="text-align: left;" class="mycode_align">added console mode :<br />
unpack all exe files and Inno script from InnoSetup installer<br />
( work only if you don't have installed Inno Extractor - Exeinfo Pe internal unpacker )<br />
parameter example : exeinfope.exe file_name /unp-inno-exe</div>
<div style="text-align: left;" class="mycode_align">added Skater v24.2.0.51 2024 ( protected DLL still not detected )</div>
<div style="text-align: left;" class="mycode_align">Delphi version resolver Added ( not 100% ) :<br />
Delphi XE7 - v10.4 , Delphi v10.4 Sydney , Delphi v10.4 Rio , Delphi v11.0 Alexandria , Delphi v12 Yukon , Delphi v10.2 Tokyo , Delphi v10.1 Berlin</div>
<div style="text-align: left;" class="mycode_align">added Config GUI : Wow64 redirect<br />
added [Internet Browset ] change to user path</div>
<div style="text-align: left;" class="mycode_align">added Inno extractor - view inno script</div>
<div style="text-align: left;" class="mycode_align">added to NOT EXE - .7z 7-ZIP Archive v.0.4<br />
[ AES - detected - password required ]<br />
[ Mode : DEFLATE ]<br />
[ Mode : P7Z_BCJ ]<br />
[ Mode : LZMA:21 BCJ ]</div>
<div style="text-align: left;" class="mycode_align">added detector for protected 7zip : Ripper don't ripp "protected .7z archives by CryptoNickSof"<br />
but Exeinfo PE detect it !</div>
<div style="text-align: left;" class="mycode_align">
and others ...<br />
<br />
<a href="https://github.com/ExeinfoASL/ASL/releases/tag/exeinfo" target="_blank" rel="noopener" class="mycode_url">https://github.com/ExeinfoASL/ASL/releases/tag/exeinfo</a></div><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/rar.png" title="RAR File" border="0" alt=".rar" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=2753" target="_blank" title="">exeinfope 0.0.8.3.part1.rar</a> (الحجم : 1 MB / التحميلات : 14)
<!-- end: postbit_attachments_attachment --><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/rar.png" title="RAR File" border="0" alt=".rar" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=2754" target="_blank" title="">exeinfope 0.0.8.3.part2.rar</a> (الحجم : 946.98 KB / التحميلات : 16)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[اداة 4n4lDetector]]></title>
			<link>https://www.at4re.net/f/thread-3695.html</link>
			<pubDate>Fri, 24 Nov 2023 14:29:38 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=2483">motaghred</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-3695.html</guid>
			<description><![CDATA[برنامج لفحص البرامج المحمية <br />
<br />
<a href="https://github.com/4n0nym0us/4n4lDetector" target="_blank" rel="noopener" class="mycode_url">https://github.com/4n0nym0us/4n4lDetector</a>]]></description>
			<content:encoded><![CDATA[برنامج لفحص البرامج المحمية <br />
<br />
<a href="https://github.com/4n0nym0us/4n4lDetector" target="_blank" rel="noopener" class="mycode_url">https://github.com/4n0nym0us/4n4lDetector</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Enigma Info v0.11]]></title>
			<link>https://www.at4re.net/f/thread-3528.html</link>
			<pubDate>Fri, 03 Mar 2023 08:02:23 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=3325">H@wk0</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-3528.html</guid>
			<description><![CDATA[برنامج بسيط لفحص البرامج المحمية بواسطة Enigma v5.0 و ما قبله حيت يمكن الحصول على معلومات تفصيلية تساعد في فك الحماية.<br />
<br />
ملاحظة: الأصدارات اللاحقة لأصدارة 5 من Enigma يمكن فحصها بواسطة ال code injection و لا يتوفر برنامج جاهز بهذا الخصوص و لكن يمكن عملها يدوياً<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php">https://www.mediafire.com/file/buchy3xjpy5q2zd/Enigma+Info+v0.11.zip/file
</code></pre>]]></description>
			<content:encoded><![CDATA[برنامج بسيط لفحص البرامج المحمية بواسطة Enigma v5.0 و ما قبله حيت يمكن الحصول على معلومات تفصيلية تساعد في فك الحماية.<br />
<br />
ملاحظة: الأصدارات اللاحقة لأصدارة 5 من Enigma يمكن فحصها بواسطة ال code injection و لا يتوفر برنامج جاهز بهذا الخصوص و لكن يمكن عملها يدوياً<br />
 <br />
<pre class="block-code line-numbers"><code class="language-php">https://www.mediafire.com/file/buchy3xjpy5q2zd/Enigma+Info+v0.11.zip/file
</code></pre>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[WinTools.net Premium]]></title>
			<link>https://www.at4re.net/f/thread-3102.html</link>
			<pubDate>Tue, 10 May 2022 19:40:27 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=279">vosiyons</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-3102.html</guid>
			<description><![CDATA[Hello, my dear brothers and sisters, I am sharing with you the program I use for register analysis, <br />
<br />
the training showing the use of the program is attached.   <br />
<br />
<br />
Rar Pas: <a href="http://www.at4re.net" target="_blank" rel="noopener" class="mycode_url">www.at4re.net</a><br />
<br />
<br />
<a href="https://www.hizliresim.com/hhg0ey8" target="_blank" rel="noopener" class="mycode_url"><img src="https://i.hizliresim.com/hhg0ey8.jpg" loading="lazy"  alt="[صورة مرفقة: hhg0ey8.jpg]" class="mycode_img" /></a><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/txt.png" title="Text Document" border="0" alt=".txt" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=2219" target="_blank" title="">WinTools.net Premium.txt</a> (الحجم : 117 bytes / التحميلات : 66)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[Hello, my dear brothers and sisters, I am sharing with you the program I use for register analysis, <br />
<br />
the training showing the use of the program is attached.   <br />
<br />
<br />
Rar Pas: <a href="http://www.at4re.net" target="_blank" rel="noopener" class="mycode_url">www.at4re.net</a><br />
<br />
<br />
<a href="https://www.hizliresim.com/hhg0ey8" target="_blank" rel="noopener" class="mycode_url"><img src="https://i.hizliresim.com/hhg0ey8.jpg" loading="lazy"  alt="[صورة مرفقة: hhg0ey8.jpg]" class="mycode_img" /></a><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://www.at4re.net/f/images/attachtypes/txt.png" title="Text Document" border="0" alt=".txt" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=2219" target="_blank" title="">WinTools.net Premium.txt</a> (الحجم : 117 bytes / التحميلات : 66)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[PE Anatomist]]></title>
			<link>https://www.at4re.net/f/thread-2634.html</link>
			<pubDate>Fri, 05 Mar 2021 15:10:21 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=35">Th3-R3p4ck3r</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-2634.html</guid>
			<description><![CDATA[<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">PE Anatomist<br />
0.2.1.125<br />
<br />
<img src="https://rammerlabs.alidml.ru/images/screenshot-640.gif" loading="lazy"  alt="[صورة مرفقة: screenshot-640.gif]" class="mycode_img" /></span><br />
 0.2.1.125 (2021-03-04)PEAnatomist.exe SHA256: <br />
<pre class="block-code line-numbers"><code class="language-none">BC52CBE85FD779878F0E06624C2BF8A2A4995EBBBD381A400385AE01620B531A
</code></pre><ul class="mycode_list"><li>110B.009: Significant improvement to the MSVC ILStore (CxxIL) symbols parser and increased compatibility with different VS versions<br />
</li>
<li>1111.027: Decoding of local symbols table (.cil&#36;sy) of MSVC ILStore (CxxIL) format in OBJ files<br />
</li>
<li>1117.033: Displaying the line number of the beginning of the function in the source file in the description of symbols MSVC ILStore (CxxIL)<br />
</li>
<li>1117.034: Fixed display of source file names in MSVC ILStore (CxxIL) symbols descriptions for VS 2002 and 2003 versions (encoding is not UTF8)<br />
</li>
<li>1118.035: Fixed decoding of LF_POINTER in CodeView and MSVC ILStore (CxxIL) type tables if the described type is a pointer to a class member<br />
</li>
<li>1119.036: Changed the names of some keys in the configuration file for portability in future versions<br />
</li>
<li>111B.039: Fixed display of CodeView type description in MSVC ILStore (CxxIL) tables, if debug information is moved to PDB<br />
</li>
<li>111C.046: Fixed error displaying the incorrect name in the description of a CodeView type referenced by another type or symbol (in rare cases)<br />
</li>
<li>1201.071: Accelerated access to sections and their data in OBJ files<br />
</li>
<li>1205.081: Added support for ExtendedObj files (a.k.a. BIGOBJ, obj files with more than 0xFEFF sections)<br />
</li>
<li>1207.094: For some types of CodeView debug information, a more detailed description is available (for example, for LF_POINTER, LF_MODIFIER, LF_ARRAY and LF_BITFIELD, the description of the type to which they refer and some properties are displayed)<br />
</li>
<li>120C.110: Clarified interpretation of data from Rich signature<br />
</li>
<li>121B.116: The program license was changed from MIT to Freeware (the text of the License Agreement is located in the "Readme" file)<br />
</li>
<li>1303.122: Fixed a bug with parsing version information from the resources section in some cases<br />
</li>
<li>1304.123: Fixed error getting a member name for LIB archives created by BSD-compatible toolkit<br />
</li>
<li>1304.124: Support for ARM64EC in OBJ files<br />
</li>
</ul>
<a href="https://rammerlabs.alidml.ru/files/PEAnatomist-0.2.1.zip" target="_blank" rel="noopener" class="mycode_url">Download</a></div>]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">PE Anatomist<br />
0.2.1.125<br />
<br />
<img src="https://rammerlabs.alidml.ru/images/screenshot-640.gif" loading="lazy"  alt="[صورة مرفقة: screenshot-640.gif]" class="mycode_img" /></span><br />
 0.2.1.125 (2021-03-04)PEAnatomist.exe SHA256: <br />
<pre class="block-code line-numbers"><code class="language-none">BC52CBE85FD779878F0E06624C2BF8A2A4995EBBBD381A400385AE01620B531A
</code></pre><ul class="mycode_list"><li>110B.009: Significant improvement to the MSVC ILStore (CxxIL) symbols parser and increased compatibility with different VS versions<br />
</li>
<li>1111.027: Decoding of local symbols table (.cil&#36;sy) of MSVC ILStore (CxxIL) format in OBJ files<br />
</li>
<li>1117.033: Displaying the line number of the beginning of the function in the source file in the description of symbols MSVC ILStore (CxxIL)<br />
</li>
<li>1117.034: Fixed display of source file names in MSVC ILStore (CxxIL) symbols descriptions for VS 2002 and 2003 versions (encoding is not UTF8)<br />
</li>
<li>1118.035: Fixed decoding of LF_POINTER in CodeView and MSVC ILStore (CxxIL) type tables if the described type is a pointer to a class member<br />
</li>
<li>1119.036: Changed the names of some keys in the configuration file for portability in future versions<br />
</li>
<li>111B.039: Fixed display of CodeView type description in MSVC ILStore (CxxIL) tables, if debug information is moved to PDB<br />
</li>
<li>111C.046: Fixed error displaying the incorrect name in the description of a CodeView type referenced by another type or symbol (in rare cases)<br />
</li>
<li>1201.071: Accelerated access to sections and their data in OBJ files<br />
</li>
<li>1205.081: Added support for ExtendedObj files (a.k.a. BIGOBJ, obj files with more than 0xFEFF sections)<br />
</li>
<li>1207.094: For some types of CodeView debug information, a more detailed description is available (for example, for LF_POINTER, LF_MODIFIER, LF_ARRAY and LF_BITFIELD, the description of the type to which they refer and some properties are displayed)<br />
</li>
<li>120C.110: Clarified interpretation of data from Rich signature<br />
</li>
<li>121B.116: The program license was changed from MIT to Freeware (the text of the License Agreement is located in the "Readme" file)<br />
</li>
<li>1303.122: Fixed a bug with parsing version information from the resources section in some cases<br />
</li>
<li>1304.123: Fixed error getting a member name for LIB archives created by BSD-compatible toolkit<br />
</li>
<li>1304.124: Support for ARM64EC in OBJ files<br />
</li>
</ul>
<a href="https://rammerlabs.alidml.ru/files/PEAnatomist-0.2.1.zip" target="_blank" rel="noopener" class="mycode_url">Download</a></div>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Detect It Easy v3.00]]></title>
			<link>https://www.at4re.net/f/thread-1971.html</link>
			<pubDate>Sat, 01 Aug 2020 17:05:14 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.at4re.net/f/member.php?action=profile&uid=35">Th3-R3p4ck3r</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.at4re.net/f/thread-1971.html</guid>
			<description><![CDATA[<div style="text-align: center;" class="mycode_align"> <br />
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"><img src="https://github.com/horsicq/Detect-It-Easy/raw/master/screenshot.jpg?raw=true" loading="lazy"  alt="[صورة مرفقة: screenshot.jpg?raw=true]" class="mycode_img" /><br />
<br />
DIE" is a cross-platform application, apart from Windows version there are also available versions for Linux and Mac OS.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">Many programs of the kind (PEID, PE tools) allow to use third-party signatures. Unfortunately, those signatures scan only bytes by the pre-set mask, and it is not possible to specify additional parameters. As the result, false triggering often occur. More complicated algorithms are usually strictly set in the program itself. Hence, to add a new complex detect one needs to recompile the entire project. No one, except the authors themselves, can change the algorithm of a detect. As time passes, such programs lose relevance without the constant support.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">Detect It Easy has totally open architecture of signatures. You can easily add your own algorithms of detects or modify those that already exist. This is achieved by using scripts. The script language is very similar to JavaScript and any person, who understands the basics of programming, will understand easily how it works. Possibly, someone may decide the scripts are working very slow. Indeed, scripts run slower than compiled code, but, thanks to the good optimization of Script Engine, this doesn't cause any special inconvenience. The possibilities of open architecture compensate these limitations.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">DIE exists in three versions. Basic version ("DIE"), Lite version ("DIEL") and console version ("DIEC"). All the three use the same signatures, which are located in the folder "db". If you open this folder, nested sub-folders will be found ("Binary", "PE" and others). The names of sub-folders correspond to the types of files. First, DIE determines the type of file, and then sequentially loads all the signatures, which lie in the corresponding folder. Currently the program defines the following types:</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"><span style="color: #c0392b;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Whats New</span></span></span></span></span></div><ul class="mycode_list"><li><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">[+] Qt 5.12.8.</span></span></span><br />
</li>
<li><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">[+] New HEX editor</span></span></span><br />
</li>
<li><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">[+] New Disassembler</span></span></span><br />
</li>
<li><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">[+] New scan engine</span></span></span><br />
</li>
</ul>
</div>
<div style="text-align: center;" class="mycode_align">
<span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"><a href="http://ntinfo.biz/" target="_blank" rel="noopener" class="mycode_url">Homepage</a> / <a href="https://n10info.blogspot.com/" target="_blank" rel="noopener" class="mycode_url">NTinfo</a></span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"><a href="https://github.com/horsicq/DIE-engine/releases" target="_blank" rel="noopener" class="mycode_url">DIE-GitHub</a></span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">Download Links:</span></span></span></span></div>
<ol type="a" class="mycode_list"><li><a href="https://github.com/horsicq/DIE-engine/releases/download/3.00/die_mac_portable_3.00.dmg" target="_blank" rel="noopener" class="mycode_url">Download DIE</a> - Mac OS X, DMG<br />
</li>
<li><a href="https://github.com/horsicq/DIE-engine/releases/download/3.00/die_mac_portable_3.00.zip" target="_blank" rel="noopener" class="mycode_url">Download DIE</a> - Mac OS X, ZIP<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b"><a href="https://github.com/horsicq/DIE-engine/releases/download/3.00/die_win32_portable_3.00.zip" target="_blank" rel="noopener" class="mycode_url">Download DIE</a> - Windows</span><br />
</li>
<li><a href="https://github.com/horsicq/DIE-engine/releases/download/3.00/die_winxp_portable_3.00.zip" target="_blank" rel="noopener" class="mycode_url">Download DIE</a> - Windows XP<br />
</li>
<li><a href="https://github.com/horsicq/DIE-engine/releases/download/3.00/die_lin64_portable_3.00.tar.gz" target="_blank" rel="noopener" class="mycode_url">Download DIE</a> - Linux Ubuntu 64-bit<br />
</li>
</ol>
]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;" class="mycode_align"> <br />
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"><img src="https://github.com/horsicq/Detect-It-Easy/raw/master/screenshot.jpg?raw=true" loading="lazy"  alt="[صورة مرفقة: screenshot.jpg?raw=true]" class="mycode_img" /><br />
<br />
DIE" is a cross-platform application, apart from Windows version there are also available versions for Linux and Mac OS.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">Many programs of the kind (PEID, PE tools) allow to use third-party signatures. Unfortunately, those signatures scan only bytes by the pre-set mask, and it is not possible to specify additional parameters. As the result, false triggering often occur. More complicated algorithms are usually strictly set in the program itself. Hence, to add a new complex detect one needs to recompile the entire project. No one, except the authors themselves, can change the algorithm of a detect. As time passes, such programs lose relevance without the constant support.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">Detect It Easy has totally open architecture of signatures. You can easily add your own algorithms of detects or modify those that already exist. This is achieved by using scripts. The script language is very similar to JavaScript and any person, who understands the basics of programming, will understand easily how it works. Possibly, someone may decide the scripts are working very slow. Indeed, scripts run slower than compiled code, but, thanks to the good optimization of Script Engine, this doesn't cause any special inconvenience. The possibilities of open architecture compensate these limitations.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">DIE exists in three versions. Basic version ("DIE"), Lite version ("DIEL") and console version ("DIEC"). All the three use the same signatures, which are located in the folder "db". If you open this folder, nested sub-folders will be found ("Binary", "PE" and others). The names of sub-folders correspond to the types of files. First, DIE determines the type of file, and then sequentially loads all the signatures, which lie in the corresponding folder. Currently the program defines the following types:</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"><span style="color: #c0392b;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Whats New</span></span></span></span></span></div><ul class="mycode_list"><li><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">[+] Qt 5.12.8.</span></span></span><br />
</li>
<li><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">[+] New HEX editor</span></span></span><br />
</li>
<li><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">[+] New Disassembler</span></span></span><br />
</li>
<li><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font">[+] New scan engine</span></span></span><br />
</li>
</ul>
</div>
<div style="text-align: center;" class="mycode_align">
<span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"><a href="http://ntinfo.biz/" target="_blank" rel="noopener" class="mycode_url">Homepage</a> / <a href="https://n10info.blogspot.com/" target="_blank" rel="noopener" class="mycode_url">NTinfo</a></span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"><a href="https://github.com/horsicq/DIE-engine/releases" target="_blank" rel="noopener" class="mycode_url">DIE-GitHub</a></span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="font-size: small;" class="mycode_size"><span style="color: #57595c;" class="mycode_color"><span style="font-family: open sans,helvetica neue,Helvetica,Arial,sans-serif;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">Download Links:</span></span></span></span></div>
<ol type="a" class="mycode_list"><li><a href="https://github.com/horsicq/DIE-engine/releases/download/3.00/die_mac_portable_3.00.dmg" target="_blank" rel="noopener" class="mycode_url">Download DIE</a> - Mac OS X, DMG<br />
</li>
<li><a href="https://github.com/horsicq/DIE-engine/releases/download/3.00/die_mac_portable_3.00.zip" target="_blank" rel="noopener" class="mycode_url">Download DIE</a> - Mac OS X, ZIP<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b"><a href="https://github.com/horsicq/DIE-engine/releases/download/3.00/die_win32_portable_3.00.zip" target="_blank" rel="noopener" class="mycode_url">Download DIE</a> - Windows</span><br />
</li>
<li><a href="https://github.com/horsicq/DIE-engine/releases/download/3.00/die_winxp_portable_3.00.zip" target="_blank" rel="noopener" class="mycode_url">Download DIE</a> - Windows XP<br />
</li>
<li><a href="https://github.com/horsicq/DIE-engine/releases/download/3.00/die_lin64_portable_3.00.tar.gz" target="_blank" rel="noopener" class="mycode_url">Download DIE</a> - Linux Ubuntu 64-bit<br />
</li>
</ol>
]]></content:encoded>
		</item>
	</channel>
</rss>