
machofile은 Mach-O 바이너리 파일을 파싱하기 위한 모듈입니다.
machofile은 Mach-O 바이너리 파일을 파싱하기 위한 모듈로, 악성코드 분석과 리버스 엔지니어링에 중점을 둡니다.
Ero Carrera의 pefile에서 영감을 얻은 이 모듈은 Mach-O 바이너리에 대해 유사한 기능을 제공하는 것을 목표로 합니다. 파일 형식 지식, 기본 구조 및 상수를 얻는 데 사용된 참고 자료와 문서는 아래 나열된 리소스에서 가져왔습니다.
machofile은 자체 포함되어 있습니다. 이 모듈은 의존성이 없으며, 엔디안 독립적이고 macOS, Windows, Linux에서 작동합니다.
다른 Mach-O 파싱 모듈도 있지만, 이 모듈을 개발하게 된 동기는 다음과 같습니다:
사용해 보시거나 버그를 발견하시면 알려주세요. 하지만 너그럽게 봐주세요 ;) 코드는 최적화되고 더 많은 기능이 추가될 예정입니다.
현재 기능:
참고: 현재까지 이 모듈은 x86, x86_64, arm64, arm64e Mach-O 샘플을 대상으로 초기 테스트되었습니다.
구현 예정 기능(순서 무작위):
명령줄에서 사용하거나 Python 코드에서 모듈로 임포트하여 관심 있는 구조만 파싱하도록 각 함수를 개별적으로 호출할 수 있습니다. pip로 직접 설치한 후 프로그래밍 방식으로 또는 명령줄에서 사용하거나, 독립 실행 스크립트로 사용할 수도 있습니다.
pip install machofile
이 모듈은 파싱할 파일 경로 또는 데이터 버퍼를 입력으로 받습니다.
import machofile
macho = machofile.UniversalMachO(file_path='/path/to/machobinary')
macho.parse()
이미 데이터 버퍼가 준비되어 있다면 다음과 같이 직접 전달할 수 있습니다:
import machofile
with open(file_path, 'rb') as f:
data = f.read()
macho = machofile.UniversalMachO(data=data)
macho.parse()
API에 대한 자세한 사용법은 전용 API 문서 페이지를 참조하세요.
pip로 설치했다면 machofile을 CLI 도구로 직접 사용할 수 있으며, python3 machofile.py 형태의 독립 실행 도구로도 사용할 수 있습니다. 모듈에서 제공되는 모든 기능을 명령줄 도구에서도 동일하게 사용할 수 있습니다.
% machofile -h
usage: machofile [-h] -f FILE [-j] [--raw] [-a] [-d] [-e] [-ep] [-g]
[-hdr] [-i] [-l] [-seg] [-sig] [-sim] [-u] [-v]
[--arch ARCH] [--dump-dir DUMP_DIR]
Parse Mach-O binary structures. (version 2026.02.04)
options:
-h, --help show this help message and exit
required arguments:
-f, --file FILE Path to the file to be parsed
output format options:
-j, --json Output data in JSON format
--raw Output raw values in JSON format (use with -j/--json)
data extraction options:
-a, --all Print all info about the file
-d, --dylib Print Dylib Command Table and Dylib list
-e, --exports Print exported symbols
-ep, --entry-point Print entry point information
-g, --general_info Print general info about the file
-hdr, --header Print Mach-O header info
-i, --imports Print imported symbols
-l, --load_cmd_t Print Load Command Table and Command list
-seg, --segments Print File Segments info
-sig, --signature Print code signature and entitlements information
-sim, --similarity Print similarity hashes
-u, --uuid Print UUID
-v, --version Print version information
filter options:
--arch ARCH Show info for specific architecture only (for Universal binaries)
dump options:
--dump-dir DUMP_DIR Dump individual Mach-O slices from a FAT/Universal binary
to the specified directory
예제 출력:
% machofile -a -f b4f68a58658ceceb368520dafc35b270272ac27b8890d5b3ff0b968170471e2b
[General File Info]
Filename: b4f68a58658ceceb368520dafc35b270272ac27b8890d5b3ff0b968170471e2b
Filesize: 54240
MD5: 20ffe440e4f557b9e03855b5da2b3c9c
SHA1: 1bf61ecad8568a774f9fba726a254a9603d09f33
SHA256: b4f68a58658ceceb368520dafc35b270272ac27b8890d5b3ff0b968170471e2b
[Mach-O Header]
magic: MH_MAGIC (32-bit), 0xFEEDFACE
cputype: Intel i386
cpusubtype: X86_ALL
filetype: EXECUTE
ncmds: 13
sizeofcmds: 1180
flags: NOUNDEFS, DYLDLINK, TWOLEVEL
[Load Cmd table]
{'cmd': 'LC_SEGMENT', 'cmdsize': 56}
{'cmd': 'LC_SEGMENT', 'cmdsize': 192}
{'cmd': 'LC_SEGMENT', 'cmdsize': 328}
{'cmd': 'LC_SEGMENT', 'cmdsize': 192}
{'cmd': 'LC_SEGMENT', 'cmdsize': 56}
{'cmd': 'LC_SYMTAB', 'cmdsize': 24}
{'cmd': 'LC_DYSYMTAB', 'cmdsize': 80}
{'cmd': 'LC_LOAD_DYLINKER', 'cmdsize': 28}
{'cmd': 'LC_UUID', 'cmdsize': 24}
{'cmd': 'LC_UNIXTHREAD', 'cmdsize': 80}
{'cmd': 'LC_LOAD_DYLIB', 'cmdsize': 52}
{'cmd': 'LC_LOAD_DYLIB', 'cmdsize': 52}
{'cmd': 'LC_CODE_SIGNATURE', 'cmdsize': 16}
[Load Commands]
LC_CODE_SIGNATURE
LC_DYSYMTAB
LC_LOAD_DYLIB
LC_LOAD_DYLINKER
LC_SEGMENT
LC_SYMTAB
LC_UNIXTHREAD
LC_UUID
[File Segments]
SEGNAME VADDR VSIZE OFFSET SIZE MAX_VM_PROTECTION INITIAL_VM_PROTECTION NSECTS FLAGS ENTROPY
------------------------------------------------------------------------------------------------------------
__PAGEZERO 0 4096 0 0 0 0 0 0 0.0
__TEXT 4096 28672 0 28672 7 5 2 0 5.080680410706916
__DATA 32768 4096 28672 4096 7 3 4 0 0.1261649636134924
__IMPORT 36864 4096 32768 4096 7 7 2 0 0.21493796627555234
__LINKEDIT 40960 20480 36864 17376 7 1 0 0 6.637864516225949
[Dylib Commands]
DYLIB_NAME_OFFSET DYLIB_TIMESTAMP DYLIB_CURRENT_VERSION DYLIB_COMPAT_VERSION DYLIB_NAME
----------------------------------------------------------------------------------------------------------
24 2 65536 65536 b'/usr/lib/libgcc_s.1.dylib'
24 2 7274759 65536 b'/usr/lib/libSystem.B.dylib'
[Dylib Names]
b'/usr/lib/libgcc_s.1.dylib'
b'/usr/lib/libSystem.B.dylib'
[UUID]
d691c242-da49-1081-50d5-4f8991924b06
[Entry Point]
type: LC_UNIXTHREAD
entry_address: 9200
thread_data_size: 72
[Version Information]
No version information found
[Code Signature]
signed: True
signing_status: Apple signed
certificates_info:
count: 3
certificates:
index: 0
size: 4815
subject: Contains: Developer ID Certification Authority
issuer: Unable to parse
is_apple_cert: True
type: Developer ID Certification Authority
index: 1
size: 1215
subject: Contains: Apple Root CA
issuer: Unable to parse
is_apple_cert: True
type: Apple Root CA