Skip to content

.xls malicious sample not processed with doc_info analyzer #3908

Description

@ManaswibRane

What happened

Tried analyzing this sample .xls
https://bazaar.abuse.ch/sample/49b9c15adfd52643c9e980a92af5ea642e3d21efaa0022632cbafca87daeb0b0/ with doc_info and file_info
It is caused due to the categorization of files used (libmagic)

We might want to add more tools for analysis like oledump. Thats how I extracted and found a word doc embeaded in the xls.
Also maybe improve the doc_info analyzer

Environment

  1. OS: Linux
  2. IntelOwl version: v 6.6.1

What did you expect to happen

How to reproduce your issue

use the sample in the analyzer

Error messages and logs

Image

XLMMacroDeobfuscator

Image

Exiftool

Image

the embeaded doc

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions