-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathclearTimeStamp.py
More file actions
49 lines (41 loc) · 1.69 KB
/
Copy pathclearTimeStamp.py
File metadata and controls
49 lines (41 loc) · 1.69 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
import struct
import os
def main():
print("Clean COFF Header Timestamp")
pathToFile = input("Path to file: ").strip()
try:
with open(pathToFile, "rb+") as f:
# Check Size first
if(os.path.getsize(pathToFile) > 64):
print(f"File {pathToFile} biggest than 64 bits. Start.")
# Check DOS Header Signature ('MZ')
if f.read(2) != b"MZ":
print("Error: Not a valid DOS/PE executable.")
return
# Go to offset 0x3C to read e_lfanew (PE Header Offset)
f.seek(0x3C)
lfanew_bytes = f.read(4)
if len(lfanew_bytes) < 4:
print("Error: Corrupted DOS header.")
return
pe_offset = struct.unpack('<I', lfanew_bytes)[0]
# Verify PE Signature ("PE\0\0")
f.seek(pe_offset)
pe_sig = f.read(4)
if pe_sig != b'PE\x00\x00':
print("Error: Invalid PE header signature.")
return
# COFF Header starts right after PE Signature (+4 bytes)
# TimeDateStamp is located at offset +4 inside COFF Header
# Total offset: pe_offset + 4 (PE Sig) + 4 (Machine + Sections) = pe_offset + 8
timestamp_offset = pe_offset + 8
# Seek to TimeDateStamp and overwrite with 0x00000000
f.seek(timestamp_offset)
f.write(struct.pack("<I", 0))
print("[+] TimeDateStamp successfully stripped (set to 0x00000000)!")
except FileNotFoundError:
print("Error: File not found. Try another path.")
except IOError as e:
print(f"I/O Error: {e}")
if __name__ == "__main__":
main()