When you have a complete mystery file and want to figure out what it is, it helps to first try to “categorize” the file. Some things to think about:
-
Where did it come from?
- An embedded system that someone dumped firmware off?
- Get as much info as you can on the system. SoC/CPU datasheets will be very useful.
- A DLL that lost its extension?
- A word doc that someone renamed with
.exebecause they thought it would be funny? - If you didn’t make this file yourself, interrogate the person you got it from.
- An embedded system that someone dumped firmware off?
-
What’s in the file?
-
Open it. Is it full of text? Neat. Read it. See Raw file viewing and editing if it’s binary.
Open, NOT run!
Note that I said “open” the file, NOT “run” the file! Especially if it’s executable code, never run untrusted code, especially something that your friend just gave you and said “hey, what’s this??”
- Does it match known file signatures? See (BELOW).
-
Content recognition
file- Standard “what is that file?” analyzer. Can very quickly identify many file formats, like various executable formats, documents, plaintext, compressed archives, and more.
binwalk:- Advanced “what is that file?” analyzer. Capable of recognizing single files which contain multiple sections; especially useful for firmware dumps (can carve out app sections, data sections, compressed archives, etc)
sudo emerge -a app-misc/binwalkon Gentoo; run asbinwalk3once installed- Typical usage:
binwalk3 -av <file>for a quick “what’s in here”binwalk3 -avM <file>to recursively scan embedded files (if there’s zip data, for example, unpack and scan it)binwalk -ae <file>to actually carve the offsets into their own files
- Veles:
- Visualize di- and tri-gram bytes in 2d and 3d plots. Takes advantage of human pattern recognition to spot what’s in the file.