decalage2 / oletools

oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.
http://www.decalage.info/python/oletools
Other
2.81k stars 560 forks source link

clsid/ftguess: add ZED container format #834

Open decalage2 opened 7 months ago

decalage2 commented 7 months ago

Add CLSID 00000FE0-8804-4CA8-8868-36F59DEFD14D Also ZED containers always have a stream named "5haaaaqaIekzeecnWj31zxh0Nc", which could be checked in ftguess for better identification. Source: https://filext.com/file-extension/ZED - https://www.zedencrypt.com ZED containers are encrypted.