March 29, 2023, 7:51 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

In this update, I add option -W to write items to disk.


Option -W takes a value. Possible values are: vir, hash, hashvir and idvir.


This value determines the filename for each item written to disk.


vir: filename is item name + extension vir
hash: filename is sha256 hash
hashvir: filename is sha256 hash + extension vir
idvir: filename is item id + extension vir


For an example, take a look at my SANS ISC diary entry “Extracting Multiple …

article didier didier stevens disk entry extension filename files filter hash http isc link malware analysis md5 name ole sans sans isc sha256 update value version zip

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Officer Hospital Laguna Beach

@ Allied Universal | Laguna Beach, CA, United States

Sr. Cloud DevSecOps Engineer

@ Oracle | NOIDA, UTTAR PRADESH, India

Cloud Operations Security Engineer

@ Elekta | Crawley - Cornerstone

Cybersecurity – Senior Information System Security Manager (ISSM)

@ Boeing | USA - Seal Beach, CA

Engineering -- Tech Risk -- Security Architecture -- VP -- Dallas

@ Goldman Sachs | Dallas, Texas, United States