Author: Didier Stevens
Maldoc Analysis With xlm-deobfuscator
Sample: 82c12e7fe6cabf5edc0bdaa760b4b8c8
ISC Diary Entry: Zloader Maldoc Analysis With xlm-deobfuscator
ZIP(EICAR File), Memorized
And here I memorized all the bytes (and their meaning) of a ZIP file containing a single file: an uncompressed EICAR file.
It’s another party trick … for a hacker party 😉 .
EICAR File, Memorized
I memorized the EICAR standard antivirus test file and show that in this video.
It’s a party trick … for a hacker party 😉 .
zipdump.py: Malformed .docm File
Tools: zipdump.py
Blog post: Analyzing Malformed ZIP Files
Sample: c36e0ef657bc2137d4ee13a97528e7a12d2ffe7b8dc2b54c92f123b3f61845a6
ISC Diary Entry: Obfuscated with a Simple 0x0A
GNU Radio Companion: .WAV File
Tools: GNU Radio Companion.
GNU Radio Companion: Simple Filters
Tools: GNU Radio Companion.