Aug. 29, 2023, 10:31 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

This update to emldump.py adds a new feature to fix (-F) some obfuscations.


For the moment, only one obfuscation method is fixed (many are already ignored with option -f –filter), used in polyglot PDF/Word files.


emldump_V0_0_12.zip (http)
MD5: 3847B92460C0485E1238C47C29EF9DE1
SHA256: AFDFB8E78AE7DE56F50EA73D69705B6DACB425FFBD40D6997D64C7C75E3D8A0D


Article Link: Update: emldump.py Version 0.0.12 | Didier Stevens


1 post - 1 participant


Read full topic

article didier didier stevens feature files filter fix http link malware analysis md5 obfuscation pdf polyglot topic update version word zip

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)