Commit 781e2ad28cdea2fb6039a125526e5d5696fed6ae

Authored by decalage2
1 parent eb2b93eb

oledir: added more CLSIDs

Showing 1 changed file with 16 additions and 1 deletions
oletools/oledir.py
@@ -120,9 +120,24 @@ STATUS_COLORS = { @@ -120,9 +120,24 @@ STATUS_COLORS = {
120 } 120 }
121 121
122 KNOWN_CLSIDS = { 122 KNOWN_CLSIDS = {
123 - '00020906-0000-0000-C000-000000000046': 'MS Word', 123 + # MS Office files
  124 + '00020906-0000-0000-C000-000000000046': 'Microsoft Word 97-2003 Document',
  125 + # OLE Objects
124 '0002CE02-0000-0000-C000-000000000046': 'MS Equation Editor (may trigger CVE-2017-11882)', 126 '0002CE02-0000-0000-C000-000000000046': 'MS Equation Editor (may trigger CVE-2017-11882)',
  127 + # OLE Links
125 '00000300-0000-0000-C000-000000000046': 'StdOleLink (embedded OLE object)', 128 '00000300-0000-0000-C000-000000000046': 'StdOleLink (embedded OLE object)',
  129 + # Monikers
  130 + '00000303-0000-0000-C000-000000000046': 'File Moniker',
  131 + '00000304-0000-0000-C000-000000000046': 'Item Moniker',
  132 + '00000305-0000-0000-C000-000000000046': 'Anti Moniker',
  133 + '00000306-0000-0000-C000-000000000046': 'Pointer Moniker',
  134 + '00000308-0000-0000-C000-000000000046': 'Packager Moniker',
  135 + '00000309-0000-0000-C000-000000000046': 'Composite Moniker',
  136 + '0000031a-0000-0000-C000-000000000046': 'Class Moniker',
  137 + '0002034c-0000-0000-C000-000000000046': 'OutlookAttachMoniker',
  138 + '0002034e-0000-0000-C000-000000000046': 'OutlookMessageMoniker',
  139 + '79EAC9E0-BAF9-11CE-8C82-00AA004BA90B': 'URL Moniker',
  140 + 'ECABB0C7-7F19-11D2-978E-0000F8757E2A': 'SOAP Moniker',
126 } 141 }
127 142
128 143