Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Analyzing UDF Files with Python SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Analyzing UDF Files with Python

Yesterday, Xavier wrote a diary entry about malicious UDF files.

I wrote about the analysis of .ISO files before, and it turns out the same techniques work for UDF files too.

Python module isoparser can also parse UDF files:

We can retrieve the content:

And calculate the hash of the contained EXE:


Didier Stevens
Senior handler
Microsoft MVP


597 Posts
ISC Handler
Apr 19th 2019

Sign Up for Free or Log In to start participating in the conversation!