Wednesday 28 December 2016

Update: pdf-parser Version 0.6.7

I added option -k to search for keys in dictionaries. A usage example can be found in blog post “PDF Analysis: Back To Basics“.

Friday 16 December 2016

Hancitor Maldoc Videos

I produced 4 videos covering the process hollowing maldoc “Maldoc With Process Hollowing Shellcode“.


Wednesday 14 December 2016

Update: pecheck.py Version 0.6.0 – Overview Of Resources

This new version can produce a compact overview of all the resources in a PE file using option o: -o r.  Here is the overview of resources in an exe (malware) created with iexpress:


It contains a cab file with 2 executables, which are executed after extraction (no surprise):


Monday 12 December 2016

Update: oledump.py Version 0.0.26

Just a small change in this version: an indicator (O) for streams containing OLE 1.0 embedded data:


And plugin_http_heuristics also detects XOR-encoding starting with the second character of the key.

Friday 9 December 2016

Update: pecheck.py Version 0.5.2

This new version displays information about the signature (provided pyasn1 is installed), and adds option -g to extract data (pefile.get_data) from the pefile like resources.

Options -x, -a, -D and -S can be used to dump data (hex, ascii, binary and strings).

Tuesday 6 December 2016

Overview of Content Published In November

Here is an overview of content I published in November:

