Logo white

Peter M. Groen / oletools

Sign in
  • Sign in
  • Project
  • Files
  • Commits
  • Network
  • Graphs
  • Milestones
  • Issues 0
  • Merge Requests 0
  • Labels
  • Wiki
  • Commits 1,521
  • Compare
  • Branches 1
  • Tags 0
  • oletools
30 Jan, 2020
4 commits
  • Fixed merge error.
    50851a0a
    kirk-sayre-work authored
    2020-01-30 15:50:26 -0600  
    Browse Code »
  • Added reading GroupName text to consume_MorphDataControl(). ...
    6f190114
    This may help prevent unread data being left in the OLE stream when the GroupName text size is > 0.
    kirk-sayre-work authored
    2020-01-30 14:44:12 -0600  
    Browse Code »
  • Revert to original olevba.py.
    240f9a25
    kirk-sayre-work authored
    2020-01-30 14:43:20 -0600  
    Browse Code »
  • Merge remote-tracking branch 'upstream/master' into merge2master
    e91694c5
    kirk-sayre-work authored
    2020-01-30 14:42:36 -0600  
    Browse Code »

27 Jan, 2020
4 commits
  • mraptor: added detection of the "_OnConnecting" trigger (as in #528)
    05532922
    decalage2 authored
    2020-01-27 22:02:36 +0100  
    Browse Code »
  • readme: added link to IntelOwl
    8dbe9228
    decalage2 authored
    2020-01-27 21:58:32 +0100  
    Browse Code »
  • Merge pull request #528 from mlodic/master ...
    82dd352f
    added new Autorun method OnConnecting
    Philippe Lagadec authored
    2020-01-27 21:52:30 +0100  
    Browse Code »
  • added new Autorun method OnConnecting
    991de023
    Matteo Lodi authored
    2020-01-27 16:13:31 +0100  
    Browse Code »

21 Jan, 2020
2 commits
  • Stop reading extra 2 bytes between name field and tag field.
    bf1324d5
    kirk-sayre-work authored
    2020-01-21 12:54:37 -0600  
    Browse Code »
  • Now reads in Caption and GroupName from MorphDataExtraDataBlock .
    a3f1362c
    kirk-sayre-work authored
    2020-01-21 11:57:36 -0600  
    Browse Code »

17 Dec, 2019
1 commit
  • rtfobj: fixed process_file to detect Equation class, fixes #525
    2aa07c12
    decalage2 authored
    2019-12-17 22:06:16 +0100  
    Browse Code »

16 Dec, 2019
1 commit
  • rtfobj: removed "\rtf" from the list of destination control words, fixes #522
    2f7ee0f4
    decalage2 authored
    2019-12-16 14:01:10 +0100  
    Browse Code »

11 Dec, 2019
1 commit
  • Fixed bug in detecting MHT files.
    0b9f0d5b
    kirk-sayre-work authored
    2019-12-11 12:53:35 -0600  
    Browse Code »

10 Dec, 2019
1 commit
  • Added files to get setup.py to work.
    c2732388
    kirk-sayre-work authored
    2019-12-10 09:16:42 -0600  
    Browse Code »

04 Dec, 2019
6 commits
  • olevba: quick hack to avoid pcodedmp errors to appear on the console
    888bf456
    decalage2 authored
    2019-12-04 13:48:14 +0100  
    Browse Code »
  • olevba: disabled VBA stomping detection for files in memory, because it is not y… ...
    2fa61161
    …et supported by pcodedmp (see issue #519)
    decalage2 authored
    2019-12-04 13:35:59 +0100  
    Browse Code »
  • olevba: slight bugfix for VBA stomping detection, bumped to 0.55.1
    45db7680
    decalage2 authored
    2019-12-04 01:04:39 +0100  
    Browse Code »
  • olevba, doc: updated the list of supported formats
    35786cc7
    decalage2 authored
    2019-12-04 00:31:25 +0100  
    Browse Code »
  • updated doc for v0.55
    ae22ba64
    decalage2 authored
    2019-12-04 00:15:36 +0100  
    Browse Code »
  • updated readme and changelog for v0.55
    cd4b73d9
    decalage2 authored
    2019-12-04 00:13:26 +0100  
    Browse Code »

03 Dec, 2019
4 commits
  • bumped version to 0.55
    631a172e
    decalage2 authored
    2019-12-03 23:45:58 +0100  
    Browse Code »
  • olevba: added support for SLK files and XLM macros in SLK
    52fec143
    decalage2 authored
    2019-12-03 23:41:38 +0100  
    Browse Code »
  • crypto: replaced log.warning by log.info for error messages that trigger on all non OLE files
    6eb1efaa
    decalage2 authored
    2019-12-03 20:30:16 +0100  
    Browse Code »
  • olevba: improved error message when attempting to analyse an RTF file.
    9331696e
    decalage2 authored
    2019-12-03 15:57:16 +0100  
    Browse Code »

29 Nov, 2019
2 commits
  • merge PR #483 ...
    15aad960
    # Conflicts:
    #	oletools/ooxml.py
    decalage2 authored
    2019-11-29 22:24:04 +0100  
    Browse Code »
  • tests: temporarily disabled some msodde tests that trigger antivirus alerts (tem… ...
    b4edcc89
    …porary workaround for #398), corresponding test files are now zipped with password 'infected-test' (for #215)
    decalage2 authored
    2019-11-29 21:36:15 +0100  
    Browse Code »

28 Nov, 2019
3 commits
  • msodde: added comment
    3e636fc5
    decalage2 authored
    2019-11-28 23:00:00 +0100  
    Browse Code »
  • Merge pull request #514 from enkelli/fix-bytes2str-olevba ...
    f6c9d403
    Use given encoding in bytes2str (olevba).
    Philippe Lagadec authored
    2019-11-28 12:15:56 +0100  
    Browse Code »
  • Use given encoding in bytes2str (olevba). ...
    7012c3e2
    encoding parameter is passed to bytes2str and it's also mentioned in its
    description but method actually always used UTF-8.
    Pavol Plaskoň authored
    2019-11-28 11:18:51 +0100  
    Browse Code »

19 Nov, 2019
1 commit
  • oleobj: corrected local import, fixes #508
    f97e9227
    decalage2 authored
    2019-11-19 21:57:51 +0100  
    Browse Code »

10 Nov, 2019
1 commit
  • setup.py, requirements.txt: changed pyparsing from >=2.2.0 to >=2.1.0, fixes #481
    c46fc950
    decalage2 authored
    2019-11-10 21:53:01 +0100  
    Browse Code »

06 Nov, 2019
3 commits
  • mraptor: added SetTimer
    203c40af
    decalage2 authored
    2019-11-06 21:13:22 +0100  
    Browse Code »
  • olevba: added SUSPICIOUS_KEYWORDS_REGEX to detect keywords using regex, added 'k… ...
    02057ccf
    …ernel32' to base64 whitelist
    decalage2 authored
    2019-11-06 21:09:50 +0100  
    Browse Code »
  • olevba: added suspicious keywords SetTimer and .Variables
    bb9bf948
    decalage2 authored
    2019-11-06 20:54:59 +0100  
    Browse Code »

05 Nov, 2019
1 commit
  • tests: fixed exception in test_encoding_handler.py
    a85860db
    decalage2 authored
    2019-11-05 22:34:24 +0100  
    Browse Code »

02 Nov, 2019
1 commit
  • olevba: added AUTOEXEC_KEYWORDS_REGEX and improved detect_autoexec to support re… ...
    1ac0bf80
    …gex in keywords, added autoexec keywords from mraptor, fixes #499
    decalage2 authored
    2019-11-02 21:05:36 +0100  
    Browse Code »

01 Nov, 2019
1 commit
  • Merge remote-tracking branch 'origin/master'
    bd81d785
    decalage2 authored
    2019-11-01 18:05:18 +0100  
    Browse Code »

31 Oct, 2019
2 commits
  • tests: small fix in test_encoding_handler.py
    6b7a773f
    decalage2 authored
    2019-10-31 14:36:12 +0100  
    Browse Code »
  • msodde: added comments
    830f098b
    decalage2 authored
    2019-10-31 14:31:28 +0100  
    Browse Code »

18 Oct, 2019
1 commit
  • Merge pull request #217 from samiraguiar/compress-test-data ...
    180a24ba
    test-cases: add support for encrypted corpus
    Philippe Lagadec authored
    2019-10-18 20:59:11 +0200  
    Browse Code »