Skip to content

.xls malicious sample not processed with doc_info analyzer #3908

Description

@ManaswibRane

What happened

Tried analyzing this sample .xls
https://bazaar.abuse.ch/sample/49b9c15adfd52643c9e980a92af5ea642e3d21efaa0022632cbafca87daeb0b0/ with doc_info and file_info
It is caused due to the categorization of files used (libmagic)

We might want to add more tools for analysis like oledump. Thats how I extracted and found a word doc embeaded in the xls.
Also maybe improve the doc_info analyzer

Environment

  1. OS: Linux
  2. IntelOwl version: v 6.6.1

What did you expect to happen

How to reproduce your issue

use the sample in the analyzer

Error messages and logs

Image

XLMMacroDeobfuscator

Image

Exiftool

Image

the embeaded doc

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions