Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: Malicious Word Document: This Time The Maldoc Is A MIME File - SANS Internet Storm Center SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Malicious Word Document: This Time The Maldoc Is A MIME File

Bart Blaze Tweeted me a malicious Word document sample (MD5 23a2d596d927ceab01918cc1dfd5db68) that can not be analyzed with my oledump tool. It turns out to be a MIME file that contains a MSO file, that in turn contains an OLE file. We've seen MSO files containing OLE files when we talked about XML Office documents. I've updated my oledump tool (V0.0.15) to handle MSO files directly.

Bart has a blogpost explaining several methods to analyze this file.

If you want to use oledump, first you extract the MSO file from the MIME file, and then you use oledump. If you don't have a tool to handle MIME files, I have one: emldump.py.

Here you can see emldump and oledump piped together to analyze the maldoc:

Didier Stevens
Microsoft MVP Consumer Security
blog.DidierStevens.com DidierStevensLabs.com

Tags: maldoc, MIME, MSO, OLE, word
DidierStevens

100 Posts
ISC Handler

Sign Up for Free or Log In to start participating in the conversation!