Yesterday, Xavier wrote a diary entry about malicious UDF files. I wrote about the analysis of .ISO files before, and it turns out the same techniques work for UDF files too. Python module isoparser can also parse UDF files: We can retrieve the content: And calculate the hash of the contained EXE:
Didier Stevens |
DidierStevens 647 Posts ISC Handler Apr 19th 2019 |
Thread locked Subscribe |
Apr 19th 2019 3 years ago |
Sign Up for Free or Log In to start participating in the conversation!