This change @DidierStevens talks about starts with a file discussed on twitter:
This started with a pentest Excel4 macro file by @spamv noticed by @malwrhunterteam:
🔗virustotal.com/gui/file/ccef6…
🧐
I analyzed the file and submitted a #Yara rule to @cyb3rops signature repo:
github.com/Neo23x0/signat…
I ran a @virustotal retrohunt before submitting the rules to test them. I started looking through the results:
🔗gist.github.com/JohnLaTwC/9f64…
Heavily using @decalage2's olevba and @DidierStevens's BIFF record parser for oledump to examine samples:
Some of the files are not parsed properly. Time to improve the tools! Submit changes back to @decalage2 @DidierStevens
👍github.com/DidierStevens/…
Sounds like fun right?🥳 A lot of time looking at screens like this: (👁️>👁️)💤
So that's the difference one malware file discussed on twitter can make!
Thx to @malwrhunterteam @spamv @DissectMalware @decalage2 @cyb3rops and the Excel4 posts by @StanHacked and @domchell:
1⃣outflank.nl/blog/2018/10/0…
2⃣github.com/mdsecactivebre…
Share this Scrolly Tale with your friends.
A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.