Update: oledump.py Version 0.0.55
2020-11-15 22:49:38 Author: blog.didierstevens.com(查看原文) 阅读量:311 收藏

Update: oledump.py Version 0.0.55

This new version of oledump.py brings extra JSON support and a new indicator.

Existing option -j (–jsonoutput) produces JSON output: a JSON object with the content of each individual stream (BASE64 encoded).

This option (-j) can now be used together with option -v (–vbadecompress) to produce a JSON object with the VBA code (BASE64 encoded) of each VBA module stream.

And there is a new indicator (!) :

This indicator is used for VBA module streams for which oledump is not able to recognize “normal” VBA source code (e.g. starting with something else than attributes). Here is an example of a sample that would cause this ! indicator to appear: AV Cleaned Maldoc.

oledump_V0_0_55.zip (https)
MD5: 499B66DC3BAF86BDA4BC0370E3C18A1A
SHA256: ABEABFF0F1F5AA2239AFCDE73A676D4E8D9BA2F82C03B8663FFAB6F8D3A360E7

No comments yet.


文章来源: https://blog.didierstevens.com/2020/11/15/update-oledump-py-version-0-0-55/
如有侵权请联系:admin#unsafe.sh