Sample: 82c12e7fe6cabf5edc0bdaa760b4b8c8
ISC Diary Entry: Zloader Maldoc Analysis With xlm-deobfuscator
Sample: 82c12e7fe6cabf5edc0bdaa760b4b8c8
ISC Diary Entry: Zloader Maldoc Analysis With xlm-deobfuscator
Tools: zipdump.py
Blog post: Analyzing Malformed ZIP Files
Sample: c36e0ef657bc2137d4ee13a97528e7a12d2ffe7b8dc2b54c92f123b3f61845a6
ISC Diary Entry: Obfuscated with a Simple 0x0A
Tools: format-bytes.py, pecheck.py, file-magic.py, cut-bytes.py.
Blog post: Steganography and Malware
Sample: DB043392816146BBE6E9F3FE669459FEA52A82A77A033C86FD5BC2F4569839C9
ISC Diary Entry: Video: Stego & Cryptominers
Tools: oledump.py, cut-bytes.py.
Blog post: Analyzing .DWG Files With Embedded VBA Macros
ISC Diary entry: Malicious .DWG Files?
Tools: pdfid.py and pdf-parser.py, QPDF and Poppler.
ISC diary entries: “Encrypted Sextortion PDFs”
Sample: 294592cd85ddf80ad1a092f955f1ae25
Tools: search-for-compression.py
ISC diary entries: “Malicious .DAA Attachments” and “The DAA File Format”
Sample: 6e8947a82c97c26728dc590ed797ee23
Tools: oledump.py, base64dump.py, translate.py
ISC diary entry: Analyzing Compressed PowerShell Scripts
Sample: 1d5794e6b276db06f6f70d5fae6d718e
Sample: 7df15be35bd8fd1a98adc24e6be7bfcd..
Tools: oledump.py
ISC Diary entry: Maldoc: Excel 4.0 Macro