Analyzing UDF Files with Python
Yesterday, Xavier wrote a diary entry about malicious UDF files.

I wrote about the analysis of .ISO files before, and it turns out the same techniques work for UDF files too.
Python module isoparser can also parse UDF files:

We can retrieve the content:

And calculate the hash of the contained EXE:

Didier Stevens
Senior handler
Microsoft MVP
blog.DidierStevens.com DidierStevensLabs.com
×
Diary Archives

Comments