2017-08-24 19:21:52 +02:00
|
|
|
#!/usr/bin/env python
|
2017-07-21 18:47:10 +02:00
|
|
|
# -*- coding: utf-8 -*-
|
|
|
|
|
2019-02-06 11:31:05 +01:00
|
|
|
import sys
|
2020-01-23 10:27:40 +01:00
|
|
|
from io import BytesIO
|
2017-12-09 13:35:44 +01:00
|
|
|
|
2020-02-07 11:51:44 +01:00
|
|
|
from . import FileObject
|
2017-08-30 12:47:32 +02:00
|
|
|
from ..exceptions import MISPObjectException
|
2017-11-08 03:10:04 +01:00
|
|
|
import logging
|
2020-01-23 10:27:40 +01:00
|
|
|
from typing import Optional
|
2017-11-08 03:10:04 +01:00
|
|
|
|
|
|
|
logger = logging.getLogger('pymisp')
|
2017-07-21 18:47:10 +02:00
|
|
|
|
|
|
|
try:
|
2020-01-23 10:27:40 +01:00
|
|
|
import lief # type: ignore
|
|
|
|
from lief import Logger # type: ignore
|
2017-08-25 15:57:12 +02:00
|
|
|
Logger.disable()
|
2017-07-21 18:47:10 +02:00
|
|
|
HAS_LIEF = True
|
2020-02-07 11:51:44 +01:00
|
|
|
|
|
|
|
from .peobject import make_pe_objects
|
|
|
|
from .elfobject import make_elf_objects
|
|
|
|
from .machoobject import make_macho_objects
|
|
|
|
|
2017-07-21 18:47:10 +02:00
|
|
|
except ImportError:
|
|
|
|
HAS_LIEF = False
|
|
|
|
|
|
|
|
|
|
|
|
class FileTypeNotImplemented(MISPObjectException):
|
|
|
|
pass
|
|
|
|
|
|
|
|
|
2020-01-23 10:27:40 +01:00
|
|
|
def make_binary_objects(filepath: Optional[str]=None, pseudofile: Optional[BytesIO]=None, filename: Optional[str]=None, standalone: bool=True, default_attributes_parameters: dict={}):
|
2017-12-12 17:34:09 +01:00
|
|
|
misp_file = FileObject(filepath=filepath, pseudofile=pseudofile, filename=filename,
|
2017-12-20 14:27:31 +01:00
|
|
|
standalone=standalone, default_attributes_parameters=default_attributes_parameters)
|
2019-10-30 14:23:37 +01:00
|
|
|
if HAS_LIEF and (filepath or (pseudofile and filename)):
|
2017-08-25 17:41:58 +02:00
|
|
|
try:
|
2017-12-09 13:12:04 +01:00
|
|
|
if filepath:
|
|
|
|
lief_parsed = lief.parse(filepath=filepath)
|
2020-01-23 10:27:40 +01:00
|
|
|
elif pseudofile and filename:
|
2019-02-06 11:31:05 +01:00
|
|
|
if sys.version_info < (3, 0):
|
2017-12-09 13:35:44 +01:00
|
|
|
logger.critical('Pseudofile is not supported in python2. Just update.')
|
|
|
|
lief_parsed = None
|
|
|
|
else:
|
|
|
|
lief_parsed = lief.parse(raw=pseudofile.getvalue(), name=filename)
|
2020-01-23 10:27:40 +01:00
|
|
|
else:
|
|
|
|
logger.critical('You need either a filepath, or a pseudofile and a filename.')
|
|
|
|
lief_parsed = None
|
2017-08-25 17:41:58 +02:00
|
|
|
if isinstance(lief_parsed, lief.PE.Binary):
|
2017-12-20 14:27:31 +01:00
|
|
|
return make_pe_objects(lief_parsed, misp_file, standalone, default_attributes_parameters)
|
2017-08-25 17:41:58 +02:00
|
|
|
elif isinstance(lief_parsed, lief.ELF.Binary):
|
2017-12-20 14:27:31 +01:00
|
|
|
return make_elf_objects(lief_parsed, misp_file, standalone, default_attributes_parameters)
|
2017-08-25 17:41:58 +02:00
|
|
|
elif isinstance(lief_parsed, lief.MachO.Binary):
|
2017-12-20 14:27:31 +01:00
|
|
|
return make_macho_objects(lief_parsed, misp_file, standalone, default_attributes_parameters)
|
2017-08-25 17:41:58 +02:00
|
|
|
except lief.bad_format as e:
|
2017-11-08 03:10:04 +01:00
|
|
|
logger.warning('Bad format: {}'.format(e))
|
2017-08-25 17:41:58 +02:00
|
|
|
except lief.bad_file as e:
|
2017-11-08 03:10:04 +01:00
|
|
|
logger.warning('Bad file: {}'.format(e))
|
2017-12-04 17:52:13 +01:00
|
|
|
except lief.conversion_error as e:
|
|
|
|
logger.warning('Conversion file: {}'.format(e))
|
|
|
|
except lief.builder_error as e:
|
|
|
|
logger.warning('Builder file: {}'.format(e))
|
2017-08-25 17:41:58 +02:00
|
|
|
except lief.parser_error as e:
|
2017-11-08 03:10:04 +01:00
|
|
|
logger.warning('Parser error: {}'.format(e))
|
2017-12-04 17:52:13 +01:00
|
|
|
except lief.integrity_error as e:
|
|
|
|
logger.warning('Integrity error: {}'.format(e))
|
|
|
|
except lief.pe_error as e:
|
|
|
|
logger.warning('PE error: {}'.format(e))
|
|
|
|
except lief.type_error as e:
|
|
|
|
logger.warning('Type error: {}'.format(e))
|
|
|
|
except lief.exception as e:
|
|
|
|
logger.warning('Lief exception: {}'.format(e))
|
2017-12-09 13:35:44 +01:00
|
|
|
except FileTypeNotImplemented as e:
|
2017-11-08 03:10:04 +01:00
|
|
|
logger.warning(e)
|
2017-09-20 12:44:55 +02:00
|
|
|
if not HAS_LIEF:
|
2017-11-08 03:10:04 +01:00
|
|
|
logger.warning('Please install lief, documentation here: https://github.com/lief-project/LIEF')
|
2019-08-08 14:35:51 +02:00
|
|
|
return misp_file, None, []
|