{"id":13844658,"url":"https://github.com/zed-0xff/pedump","last_synced_at":"2025-05-14T13:06:15.006Z","repository":{"id":2002357,"uuid":"2935891","full_name":"zed-0xff/pedump","owner":"zed-0xff","description":"dump windows PE files using ruby","archived":false,"fork":false,"pushed_at":"2025-05-06T13:56:02.000Z","size":5303,"stargazers_count":314,"open_issues_count":1,"forks_count":70,"subscribers_count":28,"default_branch":"master","last_synced_at":"2025-05-06T15:04:36.601Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"http://pedump.me","language":"Ruby","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/zed-0xff.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE.txt","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null},"funding":{"ko_fi":"zed_0xff"}},"created_at":"2011-12-07T21:39:28.000Z","updated_at":"2025-05-06T13:56:06.000Z","dependencies_parsed_at":"2024-01-15T00:22:56.322Z","dependency_job_id":"70887801-ef5c-4bca-8e6b-4308c54639de","html_url":"https://github.com/zed-0xff/pedump","commit_stats":{"total_commits":373,"total_committers":6,"mean_commits":"62.166666666666664","dds":0.09115281501340478,"last_synced_commit":"fa1b8bd0af8e90a4a10759f237efea00c1c94dbd"},"previous_names":[],"tags_count":43,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zed-0xff%2Fpedump","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zed-0xff%2Fpedump/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zed-0xff%2Fpedump/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zed-0xff%2Fpedump/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/zed-0xff","download_url":"https://codeload.github.com/zed-0xff/pedump/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":254149950,"owners_count":22022851,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:02:50.604Z","updated_at":"2025-05-14T13:06:14.983Z","avatar_url":"https://github.com/zed-0xff.png","language":"Ruby","funding_links":["https://ko-fi.com/zed_0xff","https://ko-fi.com/K3K81Z3W5"],"categories":["Ruby (88)","Ruby"],"sub_categories":[],"readme":"pedump    [![Build Status](https://travis-ci.org/zed-0xff/pedump.png?branch=master)](https://travis-ci.org/zed-0xff/pedump) [![ko-fi](https://www.ko-fi.com/img/githubbutton_sm.svg)](https://ko-fi.com/K3K81Z3W5)\n======\n\nNews\n----\n```\n2025.03.16 - added .NET CLR parsing\n2024.04.20 - cli: add --set-dll-char to patch dll characteristics\n             pe: imphash calculation\n             cli: added --imphash option\n2024.01.15 - add \"--set-os-version VER\" cmdline option for patching OS version in PE header\n2023.12.04 - workaround IO.pread() not available on windows\n2021.02.18 - updated gems; changed open-uri to URI.open; enabled SSL on https://pedump.me/\n2020.08.09 - CLI: added resource extracting with --extract ID\n2020.07.28 - 0.6.1; better RICH HDR parsing/output\n2020.07.27 - 0.6.0\n2020.07.26 - now travis autotests run on ARM and OSX too!\n2020.07.25 - added EFI TE parsing; removed 'progressbar' gem dependency\n```\n\nDescription\n-----------\nA pure ruby implementation of win32 PE binary files dumper.\n\nSupported formats:\n\n * DOS MZ EXE\n * win16 NE\n * win32 PE\n * win64 PE\n * EFI TE\n\nCan dump:\n\n * MZ/NE/PE Header\n * DOS stub\n * ['Rich' Header](http://ntcore.com/files/richsign.htm)\n * Data Directory\n * Sections\n * Resources\n * Strings\n * Imports \u0026 Exports\n * VS_VERSIONINFO parsing\n * PE Packer/Compiler detection\n * a convenient way to upload your PE's to https://pedump.me for a nice HTML tables with image previews, candies \u0026 stuff\n\nInstallation\n------------\n    gem install pedump\n\nUsage\n-----\n\n    # pedump -h\n\n    Usage: pedump [options]\n            --version                    Print version information and exit\n        -v, --verbose                    Run verbosely\n                                         (can be used multiple times)\n        -q, --quiet                      Silent any warnings\n                                         (can be used multiple times)\n        -F, --force                      Try to dump by all means\n                                         (can cause exceptions \u0026 heavy wounds)\n        -f, --format FORMAT              Output format: bin,c,dump,hex,inspect,json,table,yaml\n                                         (default: table)\n    \n            --clr                        a shortcut for --clr_header, --clr_readytorun, --clr_metadata, --clr_streams, --clr_strings, --clr_tables\n            --clr-header                 clr_header\n            --clr-metadata               clr_metadata\n            --clr-readytorun             clr_readytorun\n            --clr-streams                clr_streams\n            --clr-strings                clr_strings\n            --clr-tables [TABLES]        clr_tables\n            --data-directory             data_directory\n            --dos-stub                   dos_stub\n        -E, --exports                    exports\n            --imphash                    imphash\n        -I, --imports                    imports\n            --mz                         mz\n            --ne                         ne\n            --packer                     packer\n            --pe                         pe\n            --resource-directory         resource_directory\n        -R, --resources                  resources\n            --rich                       rich\n        -S, --sections                   sections\n            --security                   security\n        -s, --strings                    strings\n            --tail                       tail\n            --te                         te\n            --tls                        tls\n        -V, --version-info               version_info\n    \n            --tokens                     Show CLR tokens\n            --deep                       packer deep scan, significantly slower\n        -P, --packer-only                packer/compiler detect only,\n                                         mimics 'file' command output\n        -r, --recursive                  recurse dirs in packer detect\n            --all                        Dump all but resource-directory (default)\n    \n            --extract ID                 Extract a resource/section/data_dir\n                                         ID: datadir:EXPORT     - datadir by type\n                                         ID: resource:0x98478   - resource by offset\n                                         ID: resource:ICON/#1   - resource by type \u0026 name\n                                         ID: section:.text      - section by name\n                                         ID: section:rva/0x1000 - section by RVA\n                                         ID: section:raw/0x400  - section by RAW_PTR\n                                         ID: tail               - file tail\n                                         ID: tail:c00           - file tail + 0xc00 offset\n            --va2file VA                 Convert RVA to file offset\n            --set-os-version VER         Patch OS version in PE header\n            --set-dll-char X             Patch IMAGE_OPTIONAL_HEADER32.DllCharacteristics\n    \n        -W, --web                        Uploads files to a https://pedump.me\n                                         for a nice HTML tables with image previews,\n                                         candies \u0026 stuff\n        -C, --console                    opens IRB console with specified file loaded\n\n### MZ Header\n\n    # pedump --mz calc.exe\n\n    === MZ Header ===\n    \n                         signature:                     \"MZ\"\n               bytes_in_last_block:        144            90\n                    blocks_in_file:                        3\n                        num_relocs:                        0\n                 header_paragraphs:                        4\n              min_extra_paragraphs:                        0\n              max_extra_paragraphs:      65535          ffff\n                                ss:                        0\n                                sp:        184            b8\n                          checksum:                        0\n                                ip:                        0\n                                cs:                        0\n                reloc_table_offset:         64            40\n                    overlay_number:                        0\n                         reserved0:                        0\n                            oem_id:                        0\n                          oem_info:                        0\n                         reserved2:                        0\n                         reserved3:                        0\n                         reserved4:                        0\n                         reserved5:                        0\n                         reserved6:                        0\n                            lfanew:        232            e8\n\n### DOS stub\n\n    # pedump --dos-stub calc.exe\n\n    === DOS STUB ===\n    \n    00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |.... ...!..L.!Th|\n    00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|\n    00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |\n    00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$       |\n\n### 'Rich' Header\n\n    # pedump --rich calc.exe\n\n    === RICH Header ===\n    \n       ID   VER         COUNT  DESCRIPTION\n       95  521e             9  [ASM] VS2008 build 21022\n        1     0           367  [---] Unmarked objects\n       93  521e            29  [IMP] VS2008 build 21022\n       84  521e           129  [C++] VS2008 build 21022\n       83  521e            25  [ C ] VS2008 build 21022\n       94  521e             1  [RES] VS2008 build 21022\n       91  521e             1  [LNK] VS2008 build 21022\n\n### PE Header\n\n    # pedump --pe calc.exe\n\n    === PE Header ===\n    \n                         signature:             \"PE\\x00\\x00\"\n    \n    # IMAGE_FILE_HEADER:\n                           Machine:        332           14c  x86\n                  NumberOfSections:                        4\n                     TimeDateStamp:    \"2008-09-14 07:28:52\"\n              PointerToSymbolTable:                        0\n                   NumberOfSymbols:                        0\n              SizeOfOptionalHeader:        224            e0\n                   Characteristics:        258           102  EXECUTABLE_IMAGE, 32BIT_MACHINE\n    \n    # IMAGE_OPTIONAL_HEADER32:\n                             Magic:        267           10b  32-bit executable\n                     LinkerVersion:                      9.0\n                        SizeOfCode:     305664         4aa00\n             SizeOfInitializedData:     340480         53200\n           SizeOfUninitializedData:                        0\n               AddressOfEntryPoint:     230155         3830b\n                        BaseOfCode:       4096          1000\n                        BaseOfData:     311296         4c000\n                         ImageBase:   16777216       1000000\n                  SectionAlignment:       4096          1000\n                     FileAlignment:        512           200\n            OperatingSystemVersion:                      5.1\n                      ImageVersion:                    5.256\n                  SubsystemVersion:                      5.1\n                         Reserved1:                        0\n                       SizeOfImage:     659456         a1000\n                     SizeOfHeaders:       1024           400\n                          CheckSum:     690555         a897b\n                         Subsystem:                        2  WINDOWS_GUI\n                DllCharacteristics:      33088          8140  DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE\n                SizeOfStackReserve:     262144         40000\n                 SizeOfStackCommit:       8192          2000\n                 SizeOfHeapReserve:    1048576        100000\n                  SizeOfHeapCommit:       4096          1000\n                       LoaderFlags:                        0\n               NumberOfRvaAndSizes:         16            10\n\n### Data Directory\n\n    # pedump --data-directory calc.exe\n\n    === DATA DIRECTORY ===\n    \n      EXPORT        rva:0x       0   size:0x        0\n      IMPORT        rva:0x   49c1c   size:0x      12c\n      RESOURCE      rva:0x   51000   size:0x    4ab07\n      EXCEPTION     rva:0x       0   size:0x        0\n      SECURITY      rva:0x       0   size:0x        0\n      BASERELOC     rva:0x   9c000   size:0x     3588\n      DEBUG         rva:0x    1610   size:0x       1c\n      ARCHITECTURE  rva:0x       0   size:0x        0\n      GLOBALPTR     rva:0x       0   size:0x        0\n      TLS           rva:0x       0   size:0x        0\n      LOAD_CONFIG   rva:0x    3d78   size:0x       40\n      Bound_IAT     rva:0x     280   size:0x      12c\n      IAT           rva:0x    1000   size:0x      594\n      Delay_IAT     rva:0x   49bac   size:0x       40\n      CLR_Header    rva:0x       0   size:0x        0\n                    rva:0x       0   size:0x        0\n\n### Sections\n\n    # pedump --sections calc.exe\n\n    === SECTIONS ===\n    \n      NAME          RVA      VSZ   RAW_SZ  RAW_PTR  nREL  REL_PTR nLINE LINE_PTR     FLAGS\n      .text        1000    4a99a    4aa00      400     0        0     0        0  60000020  R-X CODE\n      .data       4c000     431c     3000    4ae00     0        0     0        0  c0000040  RW- IDATA\n      .rsrc       51000    4ab07    4ac00    4de00     0        0     0        0  40000040  R-- IDATA\n      .reloc      9c000     41f6     4200    98a00     0        0     0        0  42000040  R-- IDATA DISCARDABLE\n\n### Resources\n\n    # pedump --resources calc.exe\n\n    === RESOURCES ===\n    \n    FILE_OFFSET    CP  LANG     SIZE  TYPE          NAME\n        0x4ec84     0 0x409     7465  IMAGE         #157\n        0x509b0     0 0x409     4086  IMAGE         #165\n        0x519a8     0 0x409     4234  IMAGE         #170\n        0x52a34     0 0x409     4625  IMAGE         #175\n        0x53c48     0 0x409     4873  IMAGE         #180\n        0x54f54     0 0x409     3048  IMAGE         #204\n        0x55b3c     0 0x409     3052  IMAGE         #208\n        0x56728     0 0x409     3217  IMAGE         #212\n        0x573bc     0 0x409     3338  IMAGE         #216\n        0x580c8     0 0x409     4191  IMAGE         #217\n        0x59128     0 0x409     4229  IMAGE         #218\n        0x5a1b0     0 0x409     4110  IMAGE         #219\n        0x5b1c0     0 0x409     4065  IMAGE         #220\n        0x5c1a4     0 0x409     3235  IMAGE         #961\n        0x5ce48     0 0x409      470  IMAGE         #981\n        0x5d020     0 0x409      587  IMAGE         #982\n        0x5d26c     0 0x409      518  IMAGE         #983\n        0x5d474     0 0x409     5344  IMAGE         #3000\n        0x5e954     0 0x409     4154  IMAGE         #3015\n        0x5f990     0 0x409     4815  IMAGE         #3045\n        0x60c60     0 0x409     6038  IMAGE         #3051\n        0x623f8     0 0x409     4290  IMAGE         #3060\n    ...\n\n### Strings\n\n    # pedump --strings calc.exe.mui\n\n    === STRINGS ===\n    \n       ID    ID  LANG  STRING\n        0     0   409  \"+/-\"\n        1     1   409  \"C\"\n        2     2   409  \"CE\"\n        3     3   409  \"Backspace\"\n        4     4   409  \".\"\n        6     6   409  \"And\"\n        7     7   409  \"Or\"\n        8     8   409  \"Xor\"\n        9     9   409  \"Lsh\"\n       10     a   409  \"Rsh\"\n       11     b   409  \"/\"\n       12     c   409  \"*\"\n       13     d   409  \"+\"\n       14     e   409  \"-\"\n       15     f   409  \"Mod\"\n       16    10   409  \"R\"\n       17    11   409  \"^\"\n       18    12   409  \"Int\"\n       19    13   409  \"RoL\"\n       20    14   409  \"RoR\"\n       21    15   409  \"Not\"\n       22    16   409  \"sin\"\n    ...\n\n### Imports\n\n    # pedump --imports zlib.dll\n\n    === IMPORTS ===\n    \n    MODULE_NAME      HINT   ORD  FUNCTION_NAME\n    KERNEL32.dll       e1        GetLastError\n    KERNEL32.dll      153        HeapAlloc\n    KERNEL32.dll      159        HeapFree\n    KERNEL32.dll       9f        GetCommandLineA\n    KERNEL32.dll      103        GetProcAddress\n    KERNEL32.dll       eb        GetModuleHandleA\n    KERNEL32.dll      137        GetVersion\n    KERNEL32.dll      164        InitializeCriticalSection\n    KERNEL32.dll       44        DeleteCriticalSection\n    KERNEL32.dll       4f        EnterCriticalSection\n    KERNEL32.dll      177        LeaveCriticalSection\n    KERNEL32.dll      1fa        SetHandleCount\n    KERNEL32.dll       dc        GetFileType\n    KERNEL32.dll      116        GetStdHandle\n    KERNEL32.dll      114        GetStartupInfoA\n    KERNEL32.dll      155        HeapCreate\n    KERNEL32.dll      157        HeapDestroy\n    KERNEL32.dll       c7        GetCurrentThreadId\n    KERNEL32.dll      222        TlsSetValue\n    KERNEL32.dll      21f        TlsAlloc\n    KERNEL32.dll      220        TlsFree\n    KERNEL32.dll      1fd        SetLastError\n    KERNEL32.dll      221        TlsGetValue\n    KERNEL32.dll       62        ExitProcess\n    KERNEL32.dll      1b8        ReadFile\n    KERNEL32.dll       16        CloseHandle\n    KERNEL32.dll      24f        WriteFile\n    KERNEL32.dll       83        FlushFileBuffers\n    KERNEL32.dll       e9        GetModuleFileNameA\n    KERNEL32.dll       98        GetCPInfo\n    KERNEL32.dll       92        GetACP\n    KERNEL32.dll       f6        GetOEMCP\n    KERNEL32.dll       8b        FreeEnvironmentStringsA\n    KERNEL32.dll       d0        GetEnvironmentStrings\n    KERNEL32.dll       8c        FreeEnvironmentStringsW\n    KERNEL32.dll       d2        GetEnvironmentStringsW\n    KERNEL32.dll      242        WideCharToMultiByte\n    KERNEL32.dll       2b        CreateFileA\n    KERNEL32.dll      1f8        SetFilePointer\n    KERNEL32.dll      206        SetStdHandle\n    KERNEL32.dll      178        LoadLibraryA\n    KERNEL32.dll      1ef        SetEndOfFile\n\n### Exports\n\n    # pedump --exports zlib.dll\n\n    === EXPORTS ===\n    \n    # module \"zlib.dll\"\n    # flags=0x0  ts=\"1996-05-07 08:46:46\"  version=0.0  ord_base=1\n    # nFuncs=27  nNames=27\n    \n      ORD ENTRY_VA  NAME\n        1     76d0  adler32\n        2     2db0  compress\n        3     4aa0  crc32\n        4     3c90  deflate\n        5     4060  deflateCopy\n        6     3fd0  deflateEnd\n        7     37f0  deflateInit2_\n        8     37c0  deflateInit_\n        9     3bc0  deflateParams\n        a     3b40  deflateReset\n        b     3a40  deflateSetDictionary\n        c     7510  gzclose\n        d     6f00  gzdopen\n        e     75a0  gzerror\n        f     73f0  gzflush\n       10     6c50  gzopen\n       11     7190  gzread\n       12     7350  gzwrite\n       13     4e50  inflate\n       14     4cc0  inflateEnd\n       15     4d20  inflateInit2_\n       16     4e30  inflateInit_\n       17     4c70  inflateReset\n       18     5260  inflateSetDictionary\n       19     52f0  inflateSync\n       1a     4bd0  uncompress\n       1b     e340  zlib_version\n\n### VS_VERSIONINFO parsing\n\n    # pedump --version-info calc.exe\n\n    === VERSION INFO ===\n    \n    # VS_FIXEDFILEINFO:\n      FileVersion         :  6.1.6801.0\n      ProductVersion      :  6.1.6801.0\n      StrucVersion        :  0x10000\n      FileFlagsMask       :  0x3f\n      FileFlags           :  0\n      FileOS              :  0x40004\n      FileType            :  1\n      FileSubtype         :  0\n    \n    # StringTable 040904B0:\n      CompanyName         :  \"Microsoft Corporation\"\n      FileDescription     :  \"Windows Calculator\"\n      FileVersion         :  \"6.1.6801.0 (winmain_win7m3.080913-2030)\"\n      InternalName        :  \"CALC\"\n      LegalCopyright      :  \"© Microsoft Corporation. All rights reserved.\"\n      OriginalFilename    :  \"CALC.EXE\"\n      ProductName         :  \"Microsoft® Windows® Operating System\"\n      ProductVersion      :  \"6.1.6801.0\"\n    \n      VarFileInfo         :  [ 0x409, 0x4b0 ]\n\n### Packer / Compiler detection\n\n    # pedump --packer zlib.dll\n\n    === Packer / Compiler ===\n    \n      MS Visual C v2.0\n\n#### pedump can mimic 'file' command output:\n\n    #pedump --packer-only -qqq samples/*\n    \n    samples/StringLoader.dll:                 Microsoft Visual C++ 6.0 DLL (Debug)\n    samples/control.exe:                      ASPack v2.12\n    samples/gms_v1_0_3.exe:                   UPX 2.90 [LZMA] (Markus Oberhumer, Laszlo Molnar \u0026 John Reiser)\n    samples/unpackme.exe:                     ASProtect 1.33 - 2.1 Registered (Alexey Solodovnikov)\n    samples/zlib.dll:                         Microsoft Visual C v2.0\n\n### Extracting\n\n#### Resources\n\nby name:\n\n    # pedump calc.exe --extract resource:VERSION/#1 | hexdump -C | head\n\n    00000000  78 03 34 00 00 00 56 00  53 00 5f 00 56 00 45 00  |x.4...V.S._.V.E.|\n    00000010  52 00 53 00 49 00 4f 00  4e 00 5f 00 49 00 4e 00  |R.S.I.O.N._.I.N.|\n    00000020  46 00 4f 00 00 00 00 00  bd 04 ef fe 00 00 01 00  |F.O.............|\n    00000030  01 00 06 00 00 00 91 1a  01 00 06 00 00 00 91 1a  |................|\n    00000040  3f 00 00 00 00 00 00 00  04 00 04 00 01 00 00 00  |?...............|\n    00000050  00 00 00 00 00 00 00 00  00 00 00 00 d6 02 00 00  |................|\n    00000060  01 00 53 00 74 00 72 00  69 00 6e 00 67 00 46 00  |..S.t.r.i.n.g.F.|\n    00000070  69 00 6c 00 65 00 49 00  6e 00 66 00 6f 00 00 00  |i.l.e.I.n.f.o...|\n    00000080  b2 02 00 00 01 00 30 00  34 00 30 00 39 00 30 00  |......0.4.0.9.0.|\n    00000090  34 00 42 00 30 00 00 00  4c 00 16 00 01 00 43 00  |4.B.0...L.....C.|\n\nby offset:\n\n    # pedump calc.exe --extract resource:0x98478 | head\n\n    \u003c?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"yes\"?\u003e\r\n    \u003c!-- Copyright (c) Microsoft Corporation --\u003e\r\n    \u003cassembly xmlns=\"urn:schemas-microsoft-com:asm.v1\" manifestVersion=\"1.0\"\u003e\r\n    \u003cassemblyIdentity\r\n        name=\"Microsoft.Windows.Shell.calc\"\r\n        processorArchitecture=\"x86\"\r\n        version=\"5.1.0.0\"\r\n        type=\"win32\"/\u003e\r\n    \u003cdescription\u003eWindows Shell\u003c/description\u003e\r\n    \u003cdependency\u003e\n\n#### Sections\n\nby name:\n\n    # pedump calc.exe --extract section:.text | hexdump -C | head -4\n\n    00000000  0b aa cb 77 f7 c4 cc 77  a4 c4 cc 77 c4 c4 cc 77  |...w...w...w...w|\n    00000010  3e d7 ca 77 ec b4 cb 77  69 9c f0 77 dc c4 cc 77  |\u003e..w...wi..w...w|\n    00000020  12 9c cb 77 4d af cb 77  b4 c4 cc 77 6e a8 ee 77  |...wM..w...wn..w|\n    00000030  14 fc f0 77 00 00 00 00  2c 92 04 76 09 62 04 76  |...w....,..v.b.v|\n\nby RVA:\n\n    # pedump calc.exe --extract section:rva/0x1000 | hexdump -C | head -4\n\n    00000000  0b aa cb 77 f7 c4 cc 77  a4 c4 cc 77 c4 c4 cc 77  |...w...w...w...w|\n    00000010  3e d7 ca 77 ec b4 cb 77  69 9c f0 77 dc c4 cc 77  |\u003e..w...wi..w...w|\n    00000020  12 9c cb 77 4d af cb 77  b4 c4 cc 77 6e a8 ee 77  |...wM..w...wn..w|\n    00000030  14 fc f0 77 00 00 00 00  2c 92 04 76 09 62 04 76  |...w....,..v.b.v|\n\nby RAW_PTR (file offset):\n\n    # pedump calc.exe --extract section:raw/0x400 | hexdump -C | head -4\n\n    00000000  0b aa cb 77 f7 c4 cc 77  a4 c4 cc 77 c4 c4 cc 77  |...w...w...w...w|\n    00000010  3e d7 ca 77 ec b4 cb 77  69 9c f0 77 dc c4 cc 77  |\u003e..w...wi..w...w|\n    00000020  12 9c cb 77 4d af cb 77  b4 c4 cc 77 6e a8 ee 77  |...wM..w...wn..w|\n    00000030  14 fc f0 77 00 00 00 00  2c 92 04 76 09 62 04 76  |...w....,..v.b.v|\n\n#### Data Directory\n\n    # pedump calc.exe --extract datadir:IMPORT | hexdump -C | head -4\n\n    00000000  90 9f 04 00 ff ff ff ff  ff ff ff ff dc a2 04 00  |................|\n    00000010  48 12 00 00 f4 a0 04 00  ff ff ff ff ff ff ff ff  |H...............|\n    00000020  10 a5 04 00 ac 13 00 00  48 9d 04 00 ff ff ff ff  |........H.......|\n    00000030  ff ff ff ff f6 a5 04 00  00 10 00 00 5c 9f 04 00  |............\\...|\n\nLicense\n-------\nReleased under the MIT License.  See the [LICENSE](https://github.com/zed-0xff/pedump/blob/master/LICENSE.txt) file for further details.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzed-0xff%2Fpedump","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fzed-0xff%2Fpedump","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzed-0xff%2Fpedump/lists"}