This new version of oledump.py adds a new variable for option -E: %MOFULEINFO%
This variable need to be used together with option -i: it contains the size of the compiled VBA code and the compressed VBA code. For example: 123+65.
There’s a new option (-s) for plugin plugin_http_heuristics: with this option, the plugin ignores space characters (useful for hexadecimal bytes separated by a space character, for example).
And there is a new plugin: plugin_msg_summary. This is a new type of plugin, a plugin that operates on the complete document. Before, plugins could only operate on individual streams, and were instantiated for each stream.
This plugin produces a summary of a .msg file (something we needed for our “Epic Manchego” research).
Here is an example:
This plugin has a couple of options, for example to produce JSON output or to add header or body information:
1 post – 1 participant