{"id":1075,"date":"2012-06-21T18:44:37","date_gmt":"2012-06-21T18:44:37","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=1075"},"modified":"2012-06-22T12:34:31","modified_gmt":"2012-06-22T12:34:31","slug":"hexdive-0-2","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2012\/06\/21\/hexdive-0-2\/","title":{"rendered":"HexDive 0.2"},"content":{"rendered":"<p>I just released a new version of HexDive. Added really lots of new strings so it should be picking up more juice from malicious samples \ud83d\ude42<\/p>\n<p>New strings include:<\/p>\n<ul>\n<li>pcap (winpcap related strings)<\/li>\n<li>libraries<\/li>\n<li>mime types<\/li>\n<li>charset encodings<\/li>\n<li>formatted strings patterns<\/li>\n<li>OS file names<\/li>\n<li>protocols<\/li>\n<li>IPs<\/li>\n<li>User agents<\/li>\n<li>information-stealing related keywords<\/li>\n<li>and more<\/li>\n<\/ul>\n<p>Note, at this stage HexDive doesn&#8217;t search for any regexes (e.g. URLs\/emails\/etc ), but it is in the making, so stay tuned.<\/p>\n<p>You can download it <a href=\"https:\/\/hexacorn.com\/download.php?f=hdive.exe\">here<\/a>.<\/p>\n<p>If your .exe download is blocked, you can try a <a href=\"https:\/\/hexacorn.com\/download.php?f=hdive.zip\">zip file<\/a>.<\/p>\n<p><strong>Note1:<\/strong><\/p>\n<p>If you find HexDive is missing strings, please let me know and I will add them. At some stage I plan to release all of the strings ofr free, but before I do it I want to ensure they are at least classified to some extent. Yes, I will do the dirty job \ud83d\ude42 just let me know what is missing. Thanks!<\/p>\n<p><strong>Note2:<\/strong><\/p>\n<p>hdive can be ran on static samples (unpacked) and process memory dumps as well; for the benchmark purposes &#8211; an example when it is ran on a 27MB file which is a process memory dump of a simple trojan takes 12-13 seconds.<\/p>\n<p>TimeThis :\u00a0 Command Line :\u00a0 hdive malware.DMP<br \/>\nTimeThis :\u00a0\u00a0\u00a0 Start Time :\u00a0 Fri Jun 22 20:24:02 2012<\/p>\n<p>TimeThis :\u00a0 Command Line :\u00a0 hdive malware.DMP<br \/>\nTimeThis :\u00a0\u00a0\u00a0 Start Time :\u00a0 Fri Jun 22 20:24:02 2012<br \/>\nTimeThis :\u00a0\u00a0\u00a0\u00a0\u00a0 End Time :\u00a0 Fri Jun 22 20:24:15 2012<br \/>\nTimeThis :\u00a0 Elapsed Time :\u00a0 00:00:12.683<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I just released a new version of HexDive. Added really lots of new strings so it should be picking up more juice from malicious samples \ud83d\ude42 New strings include: pcap (winpcap related strings) libraries mime types charset encodings formatted strings &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2012\/06\/21\/hexdive-0-2\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[23,9],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/1075"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=1075"}],"version-history":[{"count":7,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/1075\/revisions"}],"predecessor-version":[{"id":1078,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/1075\/revisions\/1078"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=1075"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=1075"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=1075"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}