Skip to content

Instantly share code, notes, and snippets.

@decalage2
decalage2 / extract_iocs.py
Last active Dec 7, 2019
Script to extract unusual URLs, IPs, etc from OpenXML files using olevba
View extract_iocs.py
import sys, zipfile
from oletools.olevba import detect_patterns
# samples: https://github.com/StrangerealIntel/CyberThreatIntel/blob/master/Indian/APT/Donot/17-09-19/Malware%20analysis.md
fname = sys.argv[1]
print(f'Opening {fname}')
if zipfile.is_zipfile(fname):
print('filetype: OpenXML or Zip')
z = zipfile.ZipFile(fname)
for f in z.infolist():
@decalage2
decalage2 / olevba_extract.py
Last active Jan 30, 2019
Quick example showing how to extract VBA macros to files using olevba (Python 2 or 3)
View olevba_extract.py
# Quick example showing how to extract VBA macros to files using olevba
# works with python 2 or 3
# ref: https://github.com/decalage2/oletools/wiki/olevba#extract-vba-macro-source-code
import sys
if sys.version_info[0] <= 2:
# Python 2.x
from oletools.olevba import VBA_Parser
else:
@decalage2
decalage2 / Extensions.java
Created Apr 19, 2017
CommonCrawlDocumentDownload - How to add RTF files
View Extensions.java
package org.dstadler.commoncrawl;
/**
* Which extensions we are interested in.
*
* @author dominik.stadler
*/
public class Extensions {
private static final String[] EXTENSIONS = new String[] {
@decalage2
decalage2 / vbaproject.py
Created Nov 16, 2016
olevba - how to access VBA project/dir and module streams
View vbaproject.py
# sample code to demonstrate how to access VBA project/dir and module streams using olevba
from oletools.olevba import VBA_Parser, decompress_stream
from oletools.ezhexviewer import hexdump3
import sys
def dump_vba_projects(vbaparser):
vba_projects = vbaparser.find_vba_projects()
for vba_root, project_path, dir_path in vba_projects:
You can’t perform that action at this time.