Skip to content

Didier Stevens Videos

  • Home
  • About
  • count.py

Didier Stevens Videos RSS

  • RSS - Posts

Recent Posts

  • Reversing A Network Protocol
  • Extracting Information From “logfmt” Files With CyberChef
  • PNG + mimikatz.exe
  • PNG Analysis
  • Analysis of a Malicious HTML File (QBot)

Recent Comments

Mike Michalko's avatarMike Michalko on James Webb JPEG With Malw…
isodump.py | Didier… on The Security Toolsmith (NVISO…
Overview of Content… on Maldoc Analysis With Cybe…
ZIP(EICAR File), Mem… on EICAR File, Memorized
Overview of Content… on AutoCAD & VBA

Archives

  • May 2024
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • April 2022
  • March 2022
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • September 2019
  • July 2019
  • May 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • December 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • December 2016
  • November 2016
  • October 2016
  • July 2016
  • May 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • May 2015
  • April 2015
  • March 2015
  • February 2015
  • January 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • July 2014

Categories

  • howto
  • malware
  • my software
  • Networking
  • Science
  • technology
  • Uncategorized
  • video

Meta

  • Create account
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.com

malware

CVE-2021-40444 Maldocs: Extracting URLs

Samples: ed2b9e22aef3e545814519151528b2d11a5e73d1b2119c067e672b653ab6855a and 679bbe0c50754853978a3a583505ebb99bce720cf26a6aaf8be06cd879701ff1

Tools: zipdump.py, re-search.py and xmldump.py

ISC diary entry: Simple Analysis Of A CVE-2021-40444 .docx Document

Comment
October 4, 2021 Didier Stevens

Strings Analysis: VBA & Excel4 Maldoc

Tools: CyberChef

Sample: 2013496fe5524988c28357245d684cdca787b47c0b3b16cae20b3222977d769b

ISC Diary Entry: Strings Analysis: VBA & Excel4 Maldoc

Comment
October 2, 2021 Didier Stevens

Simple Analysis Of A CVE-2021-40444 .docx Document

Samples: ed2b9e22aef3e545814519151528b2d11a5e73d1b2119c067e672b653ab6855a and 679bbe0c50754853978a3a583505ebb99bce720cf26a6aaf8be06cd879701ff1

Tools: zipdump.py, re-search.py and xmldump.py

ISC diary entry: Simple Analysis Of A CVE-2021-40444 .docx Document

Comment
September 19, 2021 Didier Stevens

CyberChef: BASE85 Decoding

Tools: CyberChef

CyberChef recipe: pastebin

ISC diary entry: Video: CyberChef BASE85 Decoding

Comment
July 18, 2021 Didier Stevens

Adding BASE85 To base64dump.py

Tool: base64dump.py

ISC Diary entry: BASE85 Decoding With base64dump.py

Comment
July 18, 2021 Didier Stevens

Cobalt Strike & DNS – Part 1

Tools: cs-dns-stager.py, base64dump.py and 1768.py

Capture file: https://www.malware-traffic-analysis.net/2021/05/21/index2.html

ISC diary entry: Video: Cobalt Strike & DNS – Part 1

Comment
May 30, 2021 Didier Stevens

Making Sense Of Encrypted Cobalt Strike Traffic

Tools: 1768.py.

Brad’s post with pcap file: 2021-05-13 (THURSDAY) – HANCITOR WITH FICKER STEALER AND COBALT STRIKE

Comment
May 22, 2021May 26, 2021 Didier Stevens

Decoding Cobalt Strike Traffic

Tools: parse-cs-http-traffic.py, 1768.py, pecheck.py and pybeacon.

ISC diary entry: Decoding Cobalt Strike Traffic

Comment
April 18, 2021April 18, 2021 Didier Stevens

Finding Metasploit & Cobalt Strike URLs

Tools: metatool.py.

ISC diary entry: Finding Metasploit & Cobalt Strike URLs

Comment
March 21, 2021 Didier Stevens

oledump and YARA DDE Rules

Tools: oledump.py, YARA.

NVISO blog post: Detecting DDE in MS Office documents

ISC diary entry: DDE and oledump

Comment
February 21, 2021 Didier Stevens

Posts navigation

← Older posts
Newer posts →
Blog at WordPress.com.
Didier Stevens Videos
Blog at WordPress.com.
  • Subscribe Subscribed
    • Didier Stevens Videos
    • Already have a WordPress.com account? Log in now.
    • Didier Stevens Videos
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...