Skip to content

MZ.exe · .dll · .sys

PE Parser

Headers, sections, imports, resources, Rich header, Authenticode, .NET metadata, strings and hashes of Windows executables — with plain-language indicators. Static parsing in your browser with WebAssembly: the file is never uploaded and never run.

FIG. 0awaiting specimen

Drop .exe, .dll or .sys files here

One file or a whole batch: folders and ZIP collections (Velociraptor, a zipped folder) work as-is. Files are recognised by their MZ header, so renamed payloads are found too. Nothing is executed — the bytes are only read.

Four synthetic, harmless PE files from a fictional intrusion (their code is a single `ret`). Tip: compare the two m64.exe builds, then open the signed DLL.

100% client-side and static: files are parsed by WebAssembly in your browser, never uploaded, never executed.

How to get the files

Full collection guide

Take the suspicious binaries off the machine without running them, keeping their folder so each one stays attributed, then drop the files, the folder or a ZIP here. Nothing needs to be installed.

  1. Copy the binaries (never run them)
  2. Drop the files, folder or ZIP here
  3. Parsed in your browser, never uploaded

Already have the file? Drag it straight onto this page: it is read, not executed.

To sweep a live machine, paste this into Windows PowerShell run as administrator. It copies executables (.exe, .dll, .sys, .scr, .cpl, .ocx) written in the last 14 days under ProgramData, Users and Windows\Temp, keeping their paths. Adjust the roots and the number of days to your case.

PowerShell · Admin
$dst = 'C:\triage\pe'
$roots = 'C:\ProgramData', 'C:\Users', 'C:\Windows\Temp'
Get-ChildItem -Path $roots -Recurse -Force -File -Include *.exe, *.dll, *.sys, *.scr, *.cpl, *.ocx -ErrorAction SilentlyContinue |
  Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-14) -and $_.Length -lt 200MB } |
  ForEach-Object {
    $to = Join-Path $dst $_.FullName.Substring(3)
    New-Item -ItemType Directory -Force -Path (Split-Path $to) | Out-Null
    Copy-Item -LiteralPath $_.FullName -Destination $to -Force
  }

Result: C:\triage\pe\ProgramData\…, C:\triage\pe\Users\<user>\… Drop the C:\triage\pe folder here (drag it, or use Choose a folder).

Analysing on another machine? Pack it into one ZIP with the tar.exe built into Windows 10 1803 and later. Antivirus may quarantine files while you copy them: add an exclusion for C:\triage or collect from an image.

PowerShell / cmd
tar -a -c -f C:\triage\pe.zip -C C:\triage pe

Gotchas

  • Antivirus can delete or quarantine samples during collection. Exclude the destination folder or work from an image.
  • Password-protected ZIPs (the usual "infected" archives) can't be opened in the browser: extract them first, then drop the folder.
  • Files over 512 MB are skipped: the browser reads each file whole into memory.

What is a PE file?

PE (Portable Executable) is the file format of Windows programs: .exe, .dll, .sys drivers, .scr, .cpl, .ocx and EFI binaries. It starts with an MS-DOS header ("MZ"), then a PE signature, a COFF file header, an optional header with 16 data directories, and a section table that maps the file into memory.

Static analysis reads that structure without running anything: what the file imports, when and with what it was built, whether it is signed, what it carries in its resources and overlay. It is the first, safe step of malware triage.

What this tool reads

  • Headers: DOS, COFF and optional header (PE32 and PE32+), data directories, section table with raw/virtual sizes, flags and entropy per section, checksum recomputed.
  • Imports (ordinals of ws2_32, wsock32 and oleaut32 named), delay-load and bound imports, exports and forwarders, imphash.
  • Resources: version information, manifest, icons, string tables, dialogs, embedded files; overlay detection.
  • Rich header decoded to Visual Studio releases, debug directory (PDB path, GUID, age), TLS callbacks, load configuration (CFG, SafeSEH), relocations.
  • Authenticode: signer, certificates, timestamp, file hash versus signed digest and RSA signature check. .NET: CLR header, metadata streams, assembly, references, P/Invoke, types.
  • Strings (ASCII and UTF-16LE) with categories, MD5 / SHA-1 / SHA-256 / TLSH, packer and compiler heuristics, and a batch table to spot families.

Why it matters in an investigation

  • Hashes and imphash let you search threat intelligence and group variants of the same tool; TLSH measures how close two files are.
  • Compile, debug and signing times date a tool — and disagreements between them reveal tampering.
  • Imports and strings show capabilities (network, injection, persistence) and indicators (URLs, IPs, paths, registry keys).
  • Version information, PDB paths and the Rich header point to the author's environment; a signature says who vouched for the file.

Limitations

  • Static only: packed or encrypted code has to be unpacked elsewhere before its real imports and strings appear.
  • Certificate chains are not validated (no trust store, no revocation): the tool checks integrity, not trust.
  • Packer detection relies on a small set of heuristics, not on a signature database such as Detect It Easy's.
  • No disassembly or emulation; no ssdeep (no permissively licensed implementation).

How to get the files

  • Pivot from execution artefacts (Prefetch, Amcache, services, tasks) to the exact paths, then copy those files without running them.
  • On a live system, sweep user-writable folders with PowerShell or collect running binaries with Velociraptor's Windows.Triage.Targets (_Live).
  • Keep folder structure and hash everything before analysis.

FAQ

Is the file uploaded or executed?

Neither. The analyzer is Rust compiled to WebAssembly and runs in a Web Worker in your browser. It only reads bytes: no emulation, no sandbox, no upload endpoint.

Can it tell me if a file is malware?

No tool can from static data alone. It shows facts (imports, signature, packer, timestamps) and plain-language indicators worth a look. Combine them with context, threat intelligence and, if needed, dynamic analysis in a sandbox.

Does it verify signatures like Windows does?

Partly. It recomputes the Authenticode hash and checks it against the signed digest, then verifies the signer's RSA signature with the embedded certificate. It does not check whether the chain ends at a trusted root or whether a certificate was revoked — that needs a trust store and online data.

How is the imphash computed?

Exactly like pefile: lower-case "dll.function" pairs (the .dll, .ocx or .sys extension dropped, ordinals of ws2_32, wsock32 and oleaut32 named from pefile's tables, others as ordN), joined with commas, then MD5. Delay-load imports are not included.

How is this different from pestudio, PE-bear or Detect It Easy?

It brings the views analysts use most from those tools into one page with no install, handles a batch of files at once (hashes, imphash families, time range, comparison) and never needs the sample on an analysis VM. Those tools go deeper in their specialities: disassembly, signature databases, editing.

Step-by-step static triage of Windows executables with the free PE Parser: load files or a ZIP, read indicators, compare builds and export results.
Find and copy suspicious EXE, DLL and SYS files from a Windows host or image without running them: PowerShell, Velociraptor, disk images and pitfalls.
Static signs that a Windows executable is packed or protected — section names, entropy, W+X sections, entry point, imports, overlay — and their pitfalls.