Does OLE in windows have anything to do with overlays?
@jstrosch2 ай бұрын
Not directly, no. I suppose an OLE object could be stored in an overlay, since they are just arbitrary content beyond the end of a "normal" PE file.
@amnaaldh99118 ай бұрын
Weirdly, the overlay cannot be extracted but great contents
@jstrosch7 ай бұрын
Depends on what you are using to analyze the PE file. I don't recall exactly what I said in this video so perhaps you're referring to a comment, but some tools make it easy to extract while others require a bit more work :)
@ciaobello1261 Жыл бұрын
As always, an informative video
@jstrosch Жыл бұрын
Glad you think so!
@paveekazhagana3106 Жыл бұрын
Very Useful
@jstrosch Жыл бұрын
Glad you found it helpful!
@christiangualteros36 Жыл бұрын
Thank you
@jstrosch Жыл бұрын
You're welcome!
@blueteams5495 Жыл бұрын
Thanks Josh for another informative video, Can you pls provide sample hash in description if possible.
@jstrosch Жыл бұрын
Added - thanks for the reminder! You can find most, if not all, of the samples I use on the Malware Bazaar by AbuseCH.
@blueteams5495 Жыл бұрын
@@jstrosch Thanks of reply. I have question regarding overlays. If pe file contains valid digitalSiganture and if we try to add overlay to it, Will it be still valid digitalsignature or invalid?
@jstrosch Жыл бұрын
@@blueteams5495 Hm, interesting question. I'm not sure off-hand, I would think that if there is a signature and you added an overlay, disregarding that sig, you would simply overwrite it. It looks like you can locate the digital signature and it's size via the Data Directory structures in the image_optional_header structure, so my thoughts are that you could append additional overlay data beyond that (xstackoverflow.com/questions/47646135/where-is-the-digital-signature-stored-when-code-signing-a-exe-file-in-windows). But, I haven't had a chance to try it out... so just a working theory at this point :)
@davidvamei218 Жыл бұрын
Nice can you please analyze XLL add-in
@jstrosch Жыл бұрын
I’ll take a look and add it to my content schedule :)
@zebulonsaloum9935 Жыл бұрын
Excellent content!!! You could get the engagement you deserve with *Promosm*!!