Malicious Word Document: This Time The Maldoc Is A MIME File, (Sat, May 9th)

Bart Blaze Tweeted me a malicious Word document sample (MD5 23a2d596d927ceab01918cc1dfd5db68) that can not be analyzed with my oledump tool. It turns out to be a MIME file that contains a MSO file, that in turn contains an OLE file. Weve seen MSO files containing OLE files when we talked about XML Office documents. Ive updated my oledump tool (V0.0.15) to handle MSO files directly.

Bart has a blogpost explaining several methods to analyze this file.

If you want to use oledump, first you extract the MSO file from the MIME file, and then you use oledump. If you don” />

Didier Stevens
Microsoft MVP Consumer Security

(c) SANS Internet Storm Center. Creative Commons Attribution-Noncommercial 3.0 United States License.

Reposted from SANS. View original.