Analysis of Malicious Documents2


I can’t complete this task. I’m using the tools provided in the course, but I can’t find the answers. I think the MD5 is correct, but I’m not sure why it’s wrong. VirusTotal confused me, and I couldn’t find the answer.

there may be a problem with the lab. I think the hash you found belongs to html file, not the pdf. You can perhaps follow along from the explanation section in the lab.

2 Likes

TASK - Office Macro Lab

I couldn’t complete the tasks “Investigate the stream 9 and find the name specified in the VB_Name attribute?” and “When did the adversary create the ‘Macros’ stream?” Which program should we use?

oledump is deprecated, was it supposed to be done with that tool?

TASK - PDF Lab

The PDF task can’t be done because it’s a HTML file.

TAKS - PDF Lab
The PDF task can’t be done because it’s a Html file. ??

1 Like

Right. It’s not a Word file, but an HTML file.

Ekran görüntüsü 2025-01-01 140516
Is there anyone who can help with the Office Macro Lab?

use oletools please GitHub - decalage2/oletools: oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.

1 Like

I did use oletools. olevba , olemeta and oleid dint help. I cant use oledump.py. Dont work.

1 Like

Oledump finally worked. I found the answer to the last question. How can we find the answer to the next question? I can’t find a date.

Only exiftool click_me.doc gives me date but its not working. Is date format right? What is the format?

You’re very close, my friend. Read about what you can do with oletools on GitHub. Check the description. Hint (oletimes) :))

2 Likes

Thank you, Its done. I think pdf part is need a update tho.

2 Likes

Updated. Check again please

nasıl çalıştırdınız oledump toolunu

chatgpt github linkin çalışmıyor yeni link bul dedim.

olebrowse ile manuel aradım bitti
:skull:

Requirements da

sudo -H pip install -U oletools

yeterli diyor ama bende olmamıştı sanırım.

yok yok bende de olmadı ama nasıl kurduğumu bilmiyorum bazıları geldi bazıları gelmedi çünkü olebrowse dan manuel aradım denedim tek tek :smiling_face_with_tear:

oledump için githubtan DidierStevens/DidierStevensSuite burada oledump mevcut. oletools içinde oledump gelmiyor arkadaşlar.son soruda yardımcı olacaktır.

1 Like

Merhaba ilk sorunun cevabını bulabildiniz mi? Bu bir doc dosyası değil mi ?