Extracting Files Embedded Inside Word Documents, (Tue, Dec 3rd)
ID: 12d5583d-a07f-55ed-9fd8-845e7505524d
STIX ID: report--12d5583d-a07f-55ed-9fd8-845e7505524d
Feed Name: SANS ISC Diary
Threat Score
This report demonstrates analysis of a malicious OOXML Word document that embeds an executable. It shows how to inspect the ZIP container, locate the OLE object, extract the embedded executable with oledump, and provides the embedded file's hash and VirusTotal link; the author notes the payload does not auto-execute and requires social engineering to run.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
