You are on page 1of 6

Description

Extensions
Header Offset Footer Default size
Flags
*** Pictures
JPEG
JPG;jpeg;jpe
\xFF+\xD8\xFF[\xC4\xDB\xE0-\xE3\xE8\xEB\xED\xEE\xFE]
0
~1
PNG
png
\x89PNG\x0D\x0A\x1A\x0A 0
\x49\x45\x4E\x44\xAE\x42\x60\x82
GIF
gif
GIF8[79]a
0
~3
TIFF/NEF/CR2/DNG
TIF;tiff;nef;cr2;dng
(\x49\x49\x2A\x00)|(\x4D\x4D\x00
\x2A) 0
~5
MSO Document Image
mdi
EP\*\x00
0
PaperPort scanned
max
ViG..\x1A
0
MS Windows Journal
jnt;jtp NB\x2A\x00
0
Bitmap bmp;dib BM.....\x00.\x00....[\x0C\x28\x40\x6C\x7C]\x00\x00\x00 0
~4
AOL ART art
\x4A\x47[\x03\x04]\x0E\x00\x00\x00
0
PC Paintbrush pcx
\x0A\x05\x01\x08
0
Paint Shop Pro psp;PsPImage
(Paint Shop Pro I)|(~BK\x00)
0
High Dynamic Range
hdr
\#\?RADIANCE
0
Canon Raw
crw
HEAPCCDR
6
Fuji Raw
raf
FUJIFILMCCD-RAW 0
Minolta Dimage RAW image
mrw
\x00MRM 0
Adobe Photoshop psd
8BPS\x00\x01\x00\x00\x00\x00\x00\x00
0
Icon
ico
\x00\x00\x01\x00[\x01-\x12]\x00(\x10\x10|\x20\x20|\x30\x30|\x40\
x40).\x00[\x00\x01]
0
~7
24000
Graphics Metafile
wmf
\xD7\xCD\xC6\x9A\x00\x00
0
~40
Windows 3 Metafile
wmf
\x01\x00\x09\x00\0x00\x03
0
~40
Enhanced Metafile
emf
EMF\x00\x00\x01\x00
40
~18
thumbcache
db
CMMM[\x14\x15]\x00\x00\x00
0
~38
Artwork cache itc2
\x00\x00\x01\x1Citch
0
Corel Photopaint
cpt
CPT[789]?FILE 0
Corel Draw
cdr
RIFF....CDR
0
~33
Corel Binary Metafile cmx
CMX1
8
~33
Calamus Vector Graphic cvg
CALAMUSCVG
0
MacDraw drawing drw
dDocD2 0
Freehand (MX) Project fh10;fh11
\x1C\x01\x00\x00\x02\x00\x04\x1C\x01\x14
\x00\x02\x00\x14\x1C\x01\x16\x00\x02\x00
0
Freehand drawing (v3) fh3
FH31
0
Freehand drawing
fh9;fh8;fh7;fh5;;
AGD[1-4]
0
Google SketchUp skp
\xFF\xFE\xFF\x0E\x53\x00\x6B\x00\x65\x00\x74\x00\x63\x00
\x68\x00\x55\x00\x70\x00
0
CAD
dwg
AC10
0
Encapsulated PostScript eps;ai \xC5\xD0\xD3\xC6
0
~70
*** Documents
Rich Text Format
rtf
\{\\rtf 0
~20
G
Unicode UTF-16LE
txt
\xFF\xFE[\x09\x0A\x0D\x20-\x3B\x40-\x7E\xC0-\xDC
]\x00[^\x00]\x00
0
~48
G
Text UTF-8
txt
\xEF\xBB\xBF[\x09\x0A\x0D\x20-\x3B\x40-\x7E\xC0-\xDC]
0
~57
G
MS Office/OLE2 ole2;doc;xls;dot;ppt;xla;ppa;pps;pot;msi;sdw;db;vsd;msg \xD0\xCF
\x11\xE0\xA1\xB1\x1A\xE1
0
~16
MS Office 2007 docx;xlsx;pptx _Types\]\.xml 38
~14
MS Access
mdb;mda;mde;mdt;fdb;psa \x00\x01\x00\x00Standard Jet
0
~71
MS Access 2007 accdb;accde
\x00\x01\x00\x00Standard ACE DB 0
MS Money
mny
\x00\x01\x00\x00MSISAM 0
FileMaker Pro database fp5;fp3 \x00\x01\x00\x00\x00\x02\x00\x01\x00\x05\x00\x02
\x00\x02\xC0
0
FileMaker Pro 7 fp7
\x00\x01\x00\x00\x00\x02\x00\x01\x00\x05\x00\x02\x00\x02
\xC0HBAM7
0
KWord kwd
KOffice application/x-kword
10
~14
RagTime Document
rtd
\x43\x23\x2B\x44\xA4\x43\x4D\xA5\x48\x64\x72

0
WordPerfect
wpd;wp;wp5;wp6;wpp
\xFFWPC 0
MS Word 6.0
doc
\x12\x34\x56\x78\x90\xFF
0
MS Word (MacBinary)
doc
BNMSWD...\x00 67
MS Write
wri
\x31\xBE\x00\x00\x00\xAB\x00\x00\x00\x00\x00\x00
0
MS Write
wri
\x32\xBE\x00\x00\x00\xAB\x00\x00\x00\x00\x00\x00
0
MS OneNote
one
\xE4\x52\x5C\x7B\x8C\xD8\xA7\x4D\xAE\xB1\x53\x78\xD0\x29
\x96\xD3
0
OpenOffice Writer
sxw;sxg sun\.xml\.writer
54
~14
OpenOffice Calc sxc;stc sun\.xml\.calc 54
~14
OpenOffice Math sxm
sun\.xml\.math 54
~14
OpenOffice Impress
sxi
sun\.xml\.impress
54
~14
OpenOffice Draw sxd;std sun\.xml\.draw 54
~14
OpenOffice 2 Writer
ott
document\.text-templ
64
~14
OpenOffice 2 Writer
odt
document\.text 64
~14
OpenOffice 2 Calc
ots
document\.spreadsheet-templ
64
~14
OpenOffice 2 Calc
ods
document\.spreads
64
~14
OpenOffice 2 Base
odb
vnd\.sun\.xml\.base
50
~14
OpenOffice 2 Draw
odg
document\.graphic
64
~14
OpenOffice 2 Math
odf
document\.formula
64
~14
OpenOffice 2 Impress
odp
document\.present
64
~14
Quattro Pro Notebook 6.0
wb2
\x00\x00\x02\x00\x02\x10\xC9\x00\x02\x00
\x00\x06
0
PostScript/Adobe
ps;eps;ai
%!PS-Adobe
0
~56
Adobe Acrobat pdf
%PDF\x2D1\x2E 0
~17
Adobe FrameMaker
fm
<MakerFile
0
Macintosh plaintext (MacBinary) txt
TEXT.....\x00 65
Quicken qdf
\xAC\x9E\xBD\x8F
0
Quicken qsd
QW Ver\.
0
QuickBooks Backup
qbb
\x45\x86\x00\x00\x06\x00
0
Sage
sly;srt;slt
\x53\x52\x01\x00
0
Lotus WordPro v9
lwp
WordPro 0
Lotus Ami Pro ami;sam \[ver\] 0
Lotus 123 v9
123
\x00\x00\x1A\x00\x05\x10\x04
0
Lotus 123 v3-5 wk3;wk4;wk5
\x00\x00\x1A\x00[\x00\x02]\x10\x04\x00 0
Lotus 123 v1
wk1
\x20\x00\x60\x40\x60
0
Lotus Notes
nsf;ntf \x1A\x00\x00[\x03\x04]\x00\x00 0
Microsoft Project
mpx
MPX[, ] 0
IBM DisplayWrite
rft;dds DDS \x7c\x00\x00\x00
0
Blindwrite
bwt
BLINDWRITE TOC FILE
0
Claris Works document cwk
\x00BOBO
3
Claris Works word processor (MacBinary) cwk
WORDBOBO
65
Claris Works text (MacBinary) cwk
CWWPBOBO
65
*** E-mail
AOL PFC pfc;org AOLVM100
0
~22
Mailbox mbox;mbs
From\x20
0
~43
E-mail eml;mht (From|Return-Path|Delivered-To|Received):\x20 0
~43
Outlook pst;ost;fdb
!BDN
0
~24
Outlook AutoComplete
nk2
\x0D\xF0\xAD\xBA
0
Exchange DB
edb
\xEF\xCD\xAB\x89[\x20\x23]\x06\x00\x00[\x00\x01]\x00\x00
\x00
4
~54
20971520
Outlook Express dbx
\xCF\xAD\x12\xFE
0
~25
OS X Tiger E-mail
emlx
#{3,7}\x0D?\x0A(Delivered-To|Status|Return-Path|
From|To|Date|Message-Id):\x20 0
</plist>\x0A
100000 F
Outlook 2011 Mac
olk14MsgSource MSrc
0
OE addr. book wab
\x9C\xCB\xCB\x8D\x13\x75\xD2\x11\x91\x58\x00\xC0\x4F\x79
\x56\xA4
0
OE addr. book (Win95) wab
\x81\x32\x84\xC1\x85\x05\xD0\x11\xB2\x90\x00\xAA

\x00\x3C\xF6\x76
0
vCard vcf
BEGIN:VCARD
0
END:VCARD
1000
Virtual Calendar
vcs;ics BEGIN:[vV]C[aA][lL][eE][nN][dD][aA][rR] 0
END:VCALENDAR
*** Internet
HTML/XML
HTML;htm;phtml;shtml;xml;xsd;msc
([\x0D\x0A\x09\x20]{0,21
}((<[hH][tT][mM][lL])|(<![dD][oO][cC][tT][yY][pP])|(<!--)|(<\?xml)|(<xs:schema))
)|(\xEF\xBB\xBF\x3C)|(\xFF\xFE\x3C\x00) 0
~15
Gt
PHP
php;php3;php4 <\?php[^\x00] 0
~56
Internet Explorer cache INDEX.DAT;dat Client UrlCache
0
~34
SQLite 2.x database
SQLITE2;sqlite;;
\*\* This file contains an SQLit
e 2\.# 0
t
SQLite 3.x database
SQLITEDB;sqlite;kexi;db;;
SQLite format 3\x00
0
~59
t
Mime Html
mht
MIME-Version:\x201\.0\x0D\x0A 0
\x00
f
Nokia text
vmg
BEGIN:VMSG
0
END:VMSG
1024
Dialup dun
\[Phone\]\x0D\x0A
0
~56
3000
Google cookie COOKIE;txt
(__utma|PREF)\x0A
0
\x0A\x2A\x0A\x00
3000
Chrome cache
chrome \xC3\xCA\x04\xC1[\x00\x03]\x00[\x01\x02]\x00
0
~63
Chrome session snss
SNSS\x01\x00\x00\x00
0
Facebook
json
for \(;;\);\{\x22
0
~56
Opera Hotlist (v2.0) / bookmark adr
(\xEF\xBB\xBF)?Opera Hotlist version #\.
0
0
Firefox sessionrestore \(?\{\x22?windows\x22?:\[\{
0
~56
96000
Flash Cookie
sol
\x00\xBF....TCSO
0
~52
Safari Cookies binarycookie
cook\x00
0
~68
*** Archives
Zip Archive
zip;jar;xps;apk (PK\x03\x04)|(PK00)|(PK\x05\x06)
0
~14
g
Jar Archive
jar
\x5F\x27\xA8\x89
0
RAR Archive
rar
Rar!\x1a\x07\x00
0
~29
Tar/PAX Archive tar;pax ustar 257
~31
G
KGB Archive
kgb
KGB_arch 0
GZip Archive
gz;tgz \x1F\x8B\x08[\x00\x08]....[\x00\x02\x04][\x00-\x12\xFF]
0
~32
BZip Archive
bz2
BZ[0h]#\x31\x41\x59\x26 0
ARJ Archive
arj
\x60\xEA......\x10\x00\x02
0
7-Zip Archive 7z
7z\xBC\xAF\x27 0
~39
Stuffit SFX Archive
sea
APPLaust!
65
Stuffit Archive sitx
StuffIt!
0
Stuffit v5 Archive
sit
StuffIt 0
ACE Archive
ace
\*\*ACE\*\*
7
BinHex 4.0
hqx
must be converted with BinHex 11
*** OS Artifacts
Win9x Registry Hive
registry
CREG
0
WinNT Registry Hive
registry
regf
0
~28
t
Windows Password
pwl
\xE3\x82\x85\x96
0
Windows Event Log
evt
\x30\x00\x00\x00LfLe
0
~44
Windows Event Log
evtx
ElfFile 0
~42
setup info
setupinfo;;
DRBKLBSM
24
Online Metadata Cache spp
\x1F\x44\xFA\xA0\x8E\xF6\xCC\x4D\x9D\x91\x2C\x2E
\xBE\xC0\xBB\x63
0
EFS Private Key file
EFS;; \x02\x00\x00\x00\x00\x00\x00\x00[^\x00]\x00\x00\
x00.\x00\x00\x00..\x00\x00..\x00\x00..\x00\x00\x14\x00 0
1000
EFS Master Key file
EFS;; \x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
[0-9a-f]\x00[0-9a-f]\x00
0
1000
Printer Spool 9x
shd
\x4B\x49\x00\x00..\x00\x00..\x00\x00..\x00\x00

0
1000
Printer Spool NT
shd
\x66\x49\x00\x00......\x00\x00.\x00\x00\x00
0
1000
Printer Spool W2K/XP
shd
\x67\x49\x00\x00.\x00\x00\x00......\x00\x00.\x00
\x00\x00
0
4000
Printer Spool 2003
shd
\x68\x49\x00\x00.\x00\x00\x00......\x00\x00.\x00
\x00\x00
0
4000
Printer Spool NT/2K/XP spl
\x00\x00\x01\x00..\x00\x00\x10\x00\x00\x00..\x00
\x00
0
~19
Certificate 1 cer;cat \x30\x82..[\x06\x0A\x30]
0
~53
Certificate 2 cat
\x30\x83[^\x00]..\x06\x09
0
~53
Certificate 3 pem
-----BEGIN\x20 0
~56
setupapi Vista log
\[Device Install Log\]\x0D\x0A 0
~56
setupapi XP
log
\[SetupAPI Log\]\x0D\x0A
0
~56
Shadow copy
VSC;; \x6B\x87\x08\x38\x76\xC1\x48\x4E\xB7\xAE\x04\x04\x6E\x6C
\xC7\x52\x01\x00\x00\x00\x04
0
~46
Windows Pagedump
dmp
PAGEDUMP
0
~51
Windows Pagedump
dmp
PAGEDU64
0
Heap dump file hdmp
MDMP
0
NTFS $LogFile $LOGFILE;;
RSTR\x1E\x00\x09\x00
0
~60
67108864
Event Trace Log etl
\x00[\x00\x04\x0C\x10\x20\x40\x80][\x00\x01\x02]\x00\x06
[\x00\x01]\x01[\x04\x05]..\x00\x00[\x01-\x04\x08]\x00\x00\x00.{7}[\x00\x01](aa|Z
b)\x02\x00
104
Snapshot Prop SnapProp
\x1F\x44\xFA\xA0\x8E\xF6\xCC\x4D\x9D\x91\x2C\x2E
\xBE\xC0\xBB\x63
0
32768
Windows Prefetch
pf
[\x11\x17]\x00\x00\x00SCCA
0
~23
Task Scheduler job
((\x47\x04)|(\x01\x05))\x01\x00................\x46\x00
0
1000
$I Recycler
recycler
\x01\x00{7}.....\x00\x00\x00.{7}\x01[C-Z]\x00:\x
00
0
1000
Windows Shortcut
lnk
\x4C\x00\x00\x00\x01\x14\x02\x00\x00\x00\x00\x00
\xC0\x00\x00\x00\x00\x00\x00\x46
0
~49
3000
bG
Internet Shortcut
url;ulk \[InternetShortcut\]
0
\x00
1000
f
Internet Shortcut
url
(\[DEFAULT\]\x0D\x0ABASEURL|\[\{000214A0-0000-00
00-C000-000000000046) 0
~56
Apple download cache
waf
\.WAF 0
Change Log
clog;log
\x00\x00\x00\x00\x12\xEF\xCD\xAB
4
65536
Ubuntu Trash
trashinfo
\[Trash Info\]\x0A
0
\x00
1000
f
KDE cache
kdecache
7\x0Ahttp://
0
PList (XML)
plist <!DOCTYPE plist 39
</plist>\x0A
PList (binary) BPLIST;plist
bplist00
0
~58
OS X Keychain keychain
kych\x00\x01
0
~64
Virtual HD
vhd
conectix
0
VMware 4 Virtual Disk vmdk
KDMV
0
Macintosh Disk Image
dmf;dmg \x78\x01\x73\x0D\x62\x62\x60\x60
0
Windows Imaging wim;swm MSWIM\x00\x00\x00
0
~66
iPhone Backup index
mbdx
mbdx\x02\x00
0
iPhone Backup db
mbdb
mbdb\x05\x00
0
AppleDouble
_ad
\x00\x05\x16\x07\x00\x02\x00\x00
0
*** Music/Video
Wave
wav
WAVEfmt
8
~33
MP3 ID3 v2/3/4 mp3
ID3[\x02-\x04]\x00[\x00\x80]\x00
0
5242880
MP3 general
mp3
\xFF[\xE2\xE3\xF2\xF3\xFA\xFB][\x10-\x1B\x20-\x2B\x30-\x
3B\x40-\x4B\x50-\x5B\x60-\x6B\x70-\x7B\x80-\x8B\x90-\x9B\xA0-\xAB\xB0-\xBB\xC0-\
xCB\xD0-\xDB\xE0-\xEB] 0
~21
cG
OGG Vorbis
ogg;ogv;ogm;oga;ogx
OggS\x00
0
~45
5242880

G
Audacity
au
dns\.\x5c
0
AVI
avi
AVI LIST
8
~33
10000000
4X Movie
4xm
4XMVLIST
8
Windows Media asf;wmv;wma;dvr-ms
\x30\x26\xB2\x75\x8E\x66\xCF\x11\xA6\xD9
\x00\xAA\x00\x62\xCE\x6C
0
~26
10000000
Windows Television
wtv
\xB7\xD8\x00\x20\x37\x49\xDA\x11\xA6\x4E\x00\x07
\xE9\x5E\xAD\x8D
0
MediaPlayer Playlist
wpl
<\?wpl version= 0
</smil>\x0D\x0A
M3U playlist
m3u
\#EXTM3U
0
~56
Real Audio
ram;ra \.ra 0
Real Media
rm;rmvb;rv
\.RMF 0
10000000
MPEG
mpg;mpeg
\x00\x00\x01\xBA
0
~41
20971520
G
QuickTime Movie mov
(moov|pnot)
4
~27
10000000
QuickTime MOV mov
ftypqt
4
~27
QuickTime 3GP 3gp
ftypisom
4
~27
QuickTime 3GP 3gp;3ga ftyp3gp 4
~27
QuickTime 3GP 3gp
ftypmmp4
4
~27
QuickTime 3G2 3g2
ftyp3g2a
4
~27
QuickTime M4A m4a;m4p ftypM4A\x20
4
~27
QuickTime M4V m4v
ftypM4V\x20
4
~27
QuickTime MP4 mp4
ftypmp41
4
~27
QuickTime MP4 mp4;m4b ftypmp42
4
~27
AVCHD mts
\x00\x00\x00\x00\x47\x40
Matroska
mkv;mka matroska
8
Flash Video
flv
FLV\x01[\x01\x05]
0
~36
10000000
Flash MP4 video fv4
ftypf4v\x20
4
~27
Director - Shockwave movie
dcr
XFIR...\x00MDGF 0
MIDI
mid
MThd
0
250000
Sony Compressed voice dvf
MS_VOICE\x00
0
Compact Disc Digital Audio (CD-DA) file cda
RIFF....CDDAfmt 0
~33
*** Programs
Compiled Html chm;chi ITSF\x03\x00\x00\x00
0
~47
Windows Help
hlp;gid (\x3F\x5F\x03\x00)|(\x4C\x4E\x02\x00) 0
MS Help 2.0
its;lit ITOLITLS
0
Windows Exec. exe;dll;drv;vxd;sys;ocx;vbx;com;fon
MZ.[\x00-\x02].[\x00-\x0
2]
0
~30
ELF Object
o;ko
\x7FELF\x01\x01\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\
x01
0
ELF Executable elf
\x7FELF\x01\x01\x01\x00.......\x00\x02 0
~73
ELF Shared Object
so
\x7FELF\x01\x01\x01\x00\x00\x00\x00\x00\x00\x00\
x00\x00\x03
0
~73
Mac executable macho \xCA\xFE\xBA\xBE\x00\x00\x00[\x01\x02\x03]
0
~67
*** Application Data
Acronis True Image file tib
\xB4\x6E\x68\x44
0
Nero CD Compilation
nri;nrb \x0E\x4E\x65\x72\x6F\x49\x53\x4F\x30
0
\x00LFDU[^\x00]*
Alcohol 120% CD Image mdf
\x00\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\x00
\x00\x02\x00\x01
0
Ghost Image
gho;ghs \xFE\xEF\x01[\x00-\x03]....[\x00\x01][\x00\x01] 0
eMule Collection
emulecollection ed2k://\|file\| 0
PGP pubring
pkr;gpg \x99\x01\xA2\x04
0
PGP secring
skr
\x95\x01\xCF\x04
0
Steganos Safe sle
ACL[2-5]\x00
0
PGP Safe
pgd
PGPdMAIN\x60\x01\x00
0
Skype chat dat dat
sCdB
0
Skype localization data mls
MLSW...skypePM \x00
0
Skype user data dbb
l33l..\x00\x00 0
~50
G

MS/MSN MARC archive


mar
MARC\x03
0
Auto completion jsonp window\.google\.ac\.h\(\[
0
\]\]\) 1000
MapSource GPS Waypoint Database gdb
MsRcf 0
SeeYou Waypoint ndb
! ILEC 0
Artwork cache itc2
\x00\x01\x1Citch
0
Flash swf;swc [CF]WS[\x03-\x0B]
0
~37
*** Special Interest
TCP Packet
tcp
\x08\x00\x45\x00.....\x00[\x01-\x80]\x06
12
~61
1500
b
UDP Packet
udp
\x08\x00\x45\x00[\x00-\x05].....[\x01-\x80]\x11 12
~61
1500
b
VISA/Mastercard ccn
[^0-9\-A-Za-z_\.][45]###[- ]####[- ]####[- ]####[^0-9\-A
-Za-z_\[&]
0
~65
25
b
Gigatribe 2.x state file
state \x40\x02\x00\x00\x5C\x5C[a-zA-Z]
0
1000
Gigatribe 3.x state file
state \x00\x00\x00\x01\x00\x00[\x00\x01].\x00[
\\a-zA-Z]\x00[\\:a-zA-Z]\x00
0
\x12\x34\x56\x78
Gigatribe 2.x chat file GIGA,bin
\x30\x41\x48\x43...\x00 0
Gigatribe 3.x chat file GIGA,dat
\x63\x68\x00\x00\x00\x0A
0

You might also like