Forensic Blogs

An aggregator for digital forensics blogs

April 12, 2015 by Didier Stevens

Update: oledump.py Version 0.0.14

A new version of oledump (small bugfix and updated plugins).

oledump_V0_0_14.zip (https)
MD5: 5ECD8BC3BD1F6C59F57E7C74DACCF017
SHA256: 7EEF509D84F7185C299A17882D3BD71481B7B1E41654F463F58492455FBDBD11


Read the original at: Didier StevensFiled Under: Digital Forensics Tagged With: My Software, Update

April 8, 2015 by Didier Stevens

Quickpost: Maldocs: VBA And Pastebin

Since a day or two I’m seeing yet another trick used by malware authors in their VBA macros.

The sample I’m looking at is 26B857A0A57B89166584CBB7167CAA19.

The VBA macro downloads base64 encoded scripts from Pastebin:

20150408-220943

20150408-221046

The scripts are delimited by HTML-like tags like . Tags that start with stext are scripts for Windows XP systems, and tags that start with text are for Windows Vista and later. This difference is for Powershell: on XP, VBS scripts are executed, and on more recent systems, Powershell scripts are executed.

The URL of the payload comes from another Pastebin entry:

20150408-221533

Correct: that trojan is hosted on Dropbox.

Quickpost info


Read the original at: Didier StevensFiled Under: Digital Forensics Tagged With: Malware

March 31, 2015 by Didier Stevens

pdf-parser And YARA

I’m teaching a PDF class at HITB Amsterdam in May. This is one of the many subjects covered in the class.

For about half a year now, I’ve been adding YARA support to several of my analysis tools. Like pdf-parser.

I’ll write some blogposts covering each tool with YARA support. I’ll start with a video for pdf-parser:


Read the original at: Didier StevensFiled Under: Digital Forensics Tagged With: My Software, PDF

  • « Previous Page
  • 1
  • …
  • 222
  • 223
  • 224
  • 225
  • 226
  • …
  • 234
  • Next Page »

About

This site aggregates posts from various digital forensics blogs. Feel free to take a look around, and make sure to visit the original sites.

  • Contact
  • Aggregated Sites

Suggest a Site

Know of a site we should add? Enter it below

Sending

Jump to Category

All content is copyright the respective author(s)