You are on page 1of 14

Malware Analysis Fundamentals - Files | Tools

March 26, 2020


Marc Ochsenmeier
@ochsenmeier
www.winitor.com
Malware Analysis Fundamentals - Files > Tools 2

Handling an unknown | generic File

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 3

Handling an email File

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 4

Handling a MS Office 97-2003 File

applies to following files: doc, xls, ppt, msg

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 5

Handling a protected MS Office 97-2003 File

applies to following files: doc, xls, ppt, msg

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 6

Handling a MS Office 2007+ File

applies to following files: docx, xlsx, xlsb, xlsm, pptx

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 7

Handling a protected MS Office 2007+ File

applies to following files: docx, xlsx, xlsb, xlsm, pptx

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 8

Handling an RTF File

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 9

Handling an LNK File

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 10

Handling an MSI File

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 11

Handling a PDF file

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 12

Handling an Executable File

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 13

Handling a Certificate File

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020


Malware Analysis Fundamentals - Files > Tools 14

More Information
• python-oletools
https://github.com/decalage2/oletools
• Didier Stevens
https://blog.didierstevens.com/didier-stevens-suite/
• Analyzing Malicious Documents Cheat Sheet
https://zeltser.com/media/docs/analyzing-malicious-document-files.pdf

Marc Ochsenmeier | @ochsenmeier | www.winitor.com March 26, 2020

You might also like