|i|dZdZddlZddlZddlZddlmZddlmZddl m Z ddl Z dZ e d kr e dSdS) a pyxswf.py pyxswf is a script to detect, extract and analyze Flash objects (SWF) that may be embedded in files such as MS Office documents (e.g. Word, Excel), which is especially useful for malware analysis. pyxswf is an extension to xxxswf.py published by Alexander Hanel on http://hooked-on-mnemonics.blogspot.nl/2011/12/xxxswfpy.html Compared to xxxswf, it can extract streams from MS Office documents by parsing their OLE structure properly (-o option), which is necessary when streams are fragmented. Stream fragmentation is a known obfuscation technique, as explained on http://www.breakingpointsystems.com/resources/blog/evasion-with-ole2-fragmentation/ It can also extract Flash objects from RTF documents, by parsing embedded objects encoded in hexadecimal format (-f option). pyxswf project website: http://www.decalage.info/python/pyxswf pyxswf is part of the python-oletools package: http://www.decalage.info/python/oletools z0.54N)rtfobj)BytesIO)xxxswfctdtztdtdd}tjtdz|z}|ddd d d |d dd dd |ddd dd |ddd dd |ddd dd |dddd d!"|d#d$d d%d& |d'd(d d)d* |d+d,d d-d. |\}}t|d/kr|dS|j r|D]}tj |}|j D]}||j tjkr||j|j}|}d0|vsd1|vr?td2t'|jzt+j||j|||dS|jru|D]p}t3j|D]Y\} } }d0|vsd1|vrKtd3t|| fzt7|}d4| z} t+j|| |ZqdSt+jdS)5Nz0pyxswf %s - http://decalage.info/python/oletoolszGPlease report any issue at https://github.com/decalage2/oletools/issuesz!usage: %prog [options]  )usagez-xz --extract store_trueextractziExtracts the embedded SWF(s), names it MD5HASH.swf & saves it in the working dir. No addition args needed)actiondesthelpz-yz--yarayarazdScans the SWF(s) with yara. If the SWF(s) is compressed it will be deflated. No addition args neededz-sz --md5scanmd5scanzgScans the SWF(s) for MD5 signatures. Please see func checkMD5 to define hashes. No addition args neededz-Hz--headerheaderz6Displays the SWFs file header. No addition args neededz-dz --decompress decompresszDeflates compressed SWFS(s)z-rz--recdirPATHstringzZWill recursively scan a directory for files that contain SWFs. Must provide path in quotes)rtyperz-cz --compresscompresszCompresses the SWF using Zlibz-oz--oleolezCParse an OLE file (e.g. Word, Excel) to look for SWF in each streamz-fz--rtfrtfz9Parse an RTF file to look for SWF in each embedded objectrsFWSsCWSzOLE stream: %sz)RTF embedded object size %d at index %08XzRTF_embedded_object_%08X)print __version__optparse OptionParser__doc__ add_option parse_argslen print_helprolefile OleFileIO direntries entry_type STGTY_STREAM_open isectStartsizegetvaluereprnamer disneylandcloserrrtf_iter_objectsrmain) r parseroptionsargsfilenamerdirentryfdataindexorig_lenr-s =C:\PYTHON\_runtimes\venv\Lib\site-packages\oletools/pyxswf.pyr1r1Ws = KLLL TUUU 2JJJ 0E  "4%)? @ @ @F dK 9T@@@ dH\Ntuuu dK 9T}~~~ dJ|(RJKKK dN>Vt^^ETTYHZZ[[[ A5=D%aw777  8 8 8  __main__)rrrsysosrriorthirdparty.xxxswfrr#r1__name__r<r;rDsx %%%%%% >>>@ zDFFFFFr<