John Lambert Profile picture
Corporate Vice President, Security Fellow, Microsoft Security Research, johnla(AT)https://t.co/3dGtq71Nby

Mar 28, 2020, 8 tweets

This change @DidierStevens talks about starts with a file discussed on twitter:

This started with a pentest Excel4 macro file by @spamv noticed by @malwrhunterteam:
🔗virustotal.com/gui/file/ccef6…
🧐

I analyzed the file and submitted a #Yara rule to @cyb3rops signature repo:
github.com/Neo23x0/signat…

I ran a @virustotal retrohunt before submitting the rules to test them. I started looking through the results:
🔗gist.github.com/JohnLaTwC/9f64…

Heavily using @decalage2's olevba and @DidierStevens's BIFF record parser for oledump to examine samples:

Some of the files are not parsed properly. Time to improve the tools! Submit changes back to @decalage2 @DidierStevens
👍github.com/DidierStevens/…

Sounds like fun right?🥳 A lot of time looking at screens like this: (👁️>👁️)💤

So that's the difference one malware file discussed on twitter can make!

Thx to @malwrhunterteam @spamv @DissectMalware @decalage2 @cyb3rops and the Excel4 posts by @StanHacked and @domchell:
1⃣outflank.nl/blog/2018/10/0…
2⃣github.com/mdsecactivebre…

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling