18
Malware Analysis Fundamentals - Files | Tools May 26, 2020 Marc Ochsenmeier @ochsenmeier www.winitor.com

Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

  • Upload
    others

  • View
    13

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | ToolsMay 26, 2020

Marc Ochsenmeier

@ochsenmeier

www.winitor.com

Page 2: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

2

Handling generic|unknown File

Page 3: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

3

Handling email File

Page 4: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

4

Handling RTF File

Page 5: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

5

Handling PDF file

Page 6: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

6

Handling LNK File

Page 7: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

7

Handling MS Office 97-2003 File

doc, xls, xlsm, xlsb, ppt, msg files

(I) xls, xlsm, xlsb files

Page 8: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

8

Handling protected MS Office 97-2003 File

doc, xls, xlsm, xlsb, ppt, msg files

(I) xls, xlsm, xlsb files

Page 9: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

9

Handling MS Office 2007+ File

docx, xlsx, xlsb, xlsm, pptx files

(I) xls, xlsm, xlsb files

Page 10: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

10

Handling protected MS Office 2007+ File

docx, xlsx, xlsb, xlsm, pptx files

(I) xls, xlsm, xlsb files

Page 11: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

11

Handling MSI File

Page 12: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

12

Handling Executable File

Page 13: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

13

Handling AutoIt Executable File

Page 14: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

14

Handling Certificate File

Page 15: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

15

Handling Cab File

Page 16: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

16

Handling Microsoft Office Files

Page 17: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

17

Handling miscellaneous Files

Page 18: Malware Analysis Fundamentals - Files | Tools€¦ · Malware Analysis Fundamentals - Files | Tools @ochsenmeier | Marc Ochsenmeier | May 26, 2020 8 Handling protected MS Office 97-2003

Malware Analysis Fundamentals - Files | Tools

@ochsenmeier | Marc Ochsenmeier | www.winitor.com May 26, 2020

18

• Oletoolshttps://github.com/decalage2/oletools

• Didier Stevenshttps://blog.didierstevens.com/didier-stevens-suite/

• Analyzing Malicious Documents Cheat Sheethttps://zeltser.com/media/docs/analyzing-malicious-document-files.pdf

• Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros) https://github.com/DissectMalware/XLMMacroDeobfuscator

• AutoIT Extractorhttps://gitlab.com/x0r19x91/autoit-extractor

• uncompyle2https://github.com/wibiti/uncompyle2

• LECmdhttps://f001.backblazeb2.com/file/EricZimmermanTools/LECmd.zip

More Information