I've written a diary entry about malicious MS Office documents stored as MIME files. A few days ago a reader contacted me for a problem he had analyzing such a maldoc MIME file. When he used emldump to analyze his sample (f67aa5a3ede3d31c5a68494c0678e2ee), it was not a multipart:
But when I looked at the content of the file, I saw that the first line was just gibberish:
You can make emldump skip this first line with option -H:
Now you see that the third part is an MSO file, and you can extract this and pipe it into oledump, like I explained in my diary entry. Should you find MIME files starting with more than one line of gibberish, you can use the tail command to remove this, like this (example to skip 2 lines):
Didier Stevens |
DidierStevens 647 Posts ISC Handler Jan 2nd 2016 |
Thread locked Subscribe |
Jan 2nd 2016 6 years ago |
Sign Up for Free or Log In to start participating in the conversation!