Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center InfoSec Handlers Diary Blog

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Video: Malformed .docm File

Published: 2020-04-26
Last Updated: 2020-04-26 08:27:47 UTC
by Didier Stevens (Version: 1)
0 comment(s)

In diary entry "Obfuscated with a Simple 0x0A", Xavier discovers that a .docm file is a malformed ZIP file.

In the following video, I show how this file is malformed:

Didier Stevens
Senior handler
Microsoft MVP

Keywords: maldoc malformed zip
0 comment(s)
Diary Archives