Practical Maldoc Analysis Workshop: The Unusual Suspects
In last year’s workshop, “Practical Maldoc Analysis Workshop”, Didier focused on the usual suspects: PDF, Office and RTF.
In this follow-up workshop, we will focus on “The Unusual Suspects”: document file formats that you don’t encounter frequently when analyzing malicious documents.
Like last year, we go top-down. We don’t start with the fundamentals (they will come later during the exercises when necessary), but we start directly with exercise files that we first have to identify, and then decide how to proceed with the analysis.
Non-exhaustive list of unusual suspects that will be covered in this workshop:
• PowerPoint
• Excel 4 Macros
• “Obscure” Word formats like MIME
• One Note
• AutoCAD
• MS Access
• Images: JPEG, PNG, SVG, …
• …
All analysis will be done with free/open-source tools, many developed by Didier.
Didier Stevens (SANS ISC Senior Handler) is a Senior Analyst working at NVISO. Didier has developed and published more than 100 open-source tools mostly for malware analysis, several of them popular in the security community. You can find his open source security tools on his IT security related blog https://blog.DidierStevens.com