Didier Stevens

Wednesday 19 July 2017

Update:zipdump.py Version 0.0.11

Filed under: My Software,Update — Didier Stevens @ 22:20

Sometimes I just need to search for a string in the files of a ZIP container, and for that I need to create a small YARA rule.

With this new version, I can let zipdump generate the rule, I just need to provide the string. The value provided to option -y needs to start with #s# (s stands for string). Here is an example where I search for string HUBBLE:

zipdump_v0_0_11.zip (https)
MD5: E97E0191757230D2C7F9109B91636BF7
SHA256: 6640F971F61F7915D89388D3072854C00C81C47476A96CAC7BE6740DA348467B

5 Comments »

  1. […] I did with zipdump, this oledump version now also supports YARA rules provided via the command-line (# and […]

    Pingback by Update: oledump.py Version 0.0.28 | Didier Stevens — Thursday 20 July 2017 @ 18:45

  2. […] He updated zipdump to version 0.0.11, adding the ability to auto-generated a YARA rule based off a string, and then search a zip file. Update:zipdump.py Version 0.0.11 […]

    Pingback by Week 29 – 2017 – This Week In 4n6 — Sunday 23 July 2017 @ 11:09

  3. […] Update:zipdump.py Version 0.0.11 […]

    Pingback by Overview of Content Published In July | Didier Stevens — Tuesday 1 August 2017 @ 21:52

  4. […] oledump.py, zipdump.py, base64dump.py, […]

    Pingback by Emotet Maldoc & ViperMonkey – Didier Stevens Videos — Thursday 10 August 2017 @ 20:03

  5. […] oledump.py, zipdump.py, base64dump.py, pecheck.py, […]

    Pingback by Metasploit’s msf.docm Analysis – Didier Stevens Videos — Monday 21 August 2017 @ 20:39


RSS feed for comments on this post. TrackBack URI

Leave a Reply (comments are moderated)

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

Blog at WordPress.com.

%d bloggers like this: