When you have a complete mystery file and want to figure out what it is, it helps to first try to “categorize” the file. Some things to think about:

  • Where did it come from?

    • An embedded system that someone dumped firmware off?
      • Get as much info as you can on the system. SoC/CPU datasheets will be very useful.
    • A DLL that lost its extension?
    • A word doc that someone renamed with .exe because they thought it would be funny?
    • If you didn’t make this file yourself, interrogate the person you got it from.
  • What’s in the file?

    Open, NOT run!

    Note that I said “open” the file, NOT “run” the file! Especially if it’s executable code, never run untrusted code, especially something that your friend just gave you and said “hey, what’s this??”

    • Does it match known file signatures? See (BELOW).

Content recognition

  • file
    • Standard “what is that file?” analyzer. Can very quickly identify many file formats, like various executable formats, documents, plaintext, compressed archives, and more.
  • binwalk:
    • Advanced “what is that file?” analyzer. Capable of recognizing single files which contain multiple sections; especially useful for firmware dumps (can carve out app sections, data sections, compressed archives, etc)
    • sudo emerge -a app-misc/binwalk on Gentoo; run as binwalk3 once installed
    • Typical usage:
      • binwalk3 -av <file> for a quick “what’s in here”
      • binwalk3 -avM <file> to recursively scan embedded files (if there’s zip data, for example, unpack and scan it)
      • binwalk -ae <file> to actually carve the offsets into their own files
  • Veles:
    • Visualize di- and tri-gram bytes in 2d and 3d plots. Takes advantage of human pattern recognition to spot what’s in the file.

sre