March 29, 2023, 7:51 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

In this update, I add option -W to write items to disk.


Option -W takes a value. Possible values are: vir, hash, hashvir and idvir.


This value determines the filename for each item written to disk.


vir: filename is item name + extension vir
hash: filename is sha256 hash
hashvir: filename is sha256 hash + extension vir
idvir: filename is item id + extension vir


For an example, take a look at my SANS ISC diary entry “Extracting Multiple …

article didier didier stevens disk entry extension filename files filter hash http isc link malware analysis md5 name ole sans sans isc sha256 update value version zip

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)