Quantcast
Channel: Malware – Didier Stevens
Viewing all articles
Browse latest Browse all 102

Analysis Of An Office Maldoc With Encrypted Payload (Slow And Clean)

$
0
0

In my previous post we used VBA and Excel to decode the URL and the PE file.

In this  post we will use Python. I translated the VBA decoding function IpkfHKQ2Sd to Python:

20151105-223017

Now we can decode the URL using Python:

20151105-223901

And also decode the downloaded file with my translate program and the IpkfHKQ2Sd function:

20151105-224328

20151105-224636

 



Viewing all articles
Browse latest Browse all 102

Trending Articles