Hashes & Entropy¶
File Information in the GUI, and --hashes in the CLI, compute everything below in one pass. The work runs in parallel across the available CPUs.
| Hash | Type | Use it for |
|---|---|---|
| CRC32 | Checksum | Quick integrity checks |
| MD5 / SHA-1 / SHA-256 | Cryptographic | Exact identity; threat-intel and IOC lookups |
| ImpHash | Import-table MD5 | Clustering samples built from the same code |
| Authentihash | SHA-256 of the image as Authenticode hashes it | Identity that ignores the signature and overlay |
| SSDEEP | Fuzzy (piecewise) | Similarity score 0–100 between files |
| TLSH | Locality-sensitive | Distance between files (lower = more similar) |
| Entropy | Shannon, 0–8 | Packing and encryption detection |
File Information for WannaCry ([email protected]; SHA-256 ED01EBFB…, the value threat-intel feeds list). The whole-file entropy of 7.99547 is close to the maximum of 8, and the navigator strip shows why: after a thin strip of code, the file is one resource with a flat skyline at the top (entropy near 8) and the yellow wave of a payload. It is the password-protected archive that the small loader in front of it extracts.
ImpHash¶
The MD5 of the normalized, ordered list of dll.function imports. Two samples with different bytes but the same ImpHash usually come from the same source. It's weak for .NET files, which all import mscoree.dll!_CorExeMain.
Authentihash¶
Hashes the PE the way Authenticode does: it skips CheckSum, the Security directory entry and the certificate table. Use it to recognize the same binary re-signed, or to compare with the embedded digest in the signature, where a mismatch means the file was modified after signing.
The file is hashed contiguously, in file order, exactly as signtool and WinVerifyTrust do, so any gap between the headers and the first section is included. Older builds hashed headers and sections separately and reported some intact Microsoft signatures (files with a 4 KB file alignment, such as XP's msvbvm60.dll) as modified; that is fixed.
SSDEEP and TLSH¶
Fuzzy hashes that survive small changes. PPEE uses them in the similarity engine. Thresholds are set in Settings → Clustering.
SSDEEP digests use the standard blocksize:signature1:signature2 text format, so they can be compared with digests from other tools that use it. PPEE computes them with its own implementation, written from the published algorithm description.
Entropy¶
| Entropy | Typical content |
|---|---|
| < 1 | Padding, zeros |
| 4.5 – 6.5 | Normal code and data |
| > 7.2 | Compressed or encrypted: packed sections, embedded archives, encrypted payloads |
Whole-file entropy is in fileInfo.entropy. Per-region entropy is drawn by the navigator strip, and each resource has its own entropy value.
ppee-cli --json --hashes f.exe | jq '{sha256: .fileInfo.sha256, imphash: .fileInfo.impHash, entropy: .fileInfo.entropy}'
MCP: get_hashes
References¶
- SSDEEP fuzzy hashing project: the context-triggered piecewise hash used for SSDEEP.
- TLSH (Trend Micro Locality Sensitive Hash), on GitHub: the locality-sensitive hash used for TLSH.
- FIPS 180-4, Secure Hash Standard (NIST): the SHA-1 and SHA-2 hash functions.
- RFC 1321, the MD5 message-digest algorithm: the MD5 hash.
