Hi folks,
I developed a tool which might be of interest for you/us reversers. It's capable of creating histograms for the spreading of byte-codes for a whole file as well as section-wise regarding PE-files. This will make the detection of crypted and/or packed data much easier. The tool (a
windows and a linux version) and a decent description is available under our CERT-homepage:
http://cert.at/downloads/software/bytehist_en.html
Plz let me know if you encounter any problems or have any questions. Comments are also appreciated.
Cheers,
chrisu






