Malwrologist

Results 50 comments of Malwrologist

60H (96) is an array ![image](https://user-images.githubusercontent.com/9646319/105150782-2e850180-5ad3-11eb-9efa-58a35c7dc304.png) rgVal (data) starts at index 11 ![image](https://user-images.githubusercontent.com/9646319/105150962-62f8bd80-5ad3-11eb-9d15-c6ef63340c83.png) can be double or unicode string ![image](https://user-images.githubusercontent.com/9646319/105151048-7c9a0500-5ad3-11eb-8027-44869212d086.png) ![image](https://user-images.githubusercontent.com/9646319/105151181-a6532c00-5ad3-11eb-9526-cdea3eb9f347.png) ![image](https://user-images.githubusercontent.com/9646319/105152680-7dcc3180-5ad5-11eb-9574-33cc9e37fb46.png)

Code: https://github.com/DissectMalware/xlrd2/blob/1900ebd5f99d113648ac3f42a3ea5495faf0d1c9/xlrd2/formula.py#L1546

Can you please share the sample files so I can also check?

I am thinking about [xlrd2](https://github.com/DissectMalware/xlrd2) as well. It also shows relative cell addressing in r1c1 notation.... if we change here, I also need to change there

Sorry for the late response. @diyarbagis @bek01 @Hadiqa-khan @Aphetoros please share the sample or its hash so I can investigate.

Sorry for such a late response. I totally missed this issue. I will take a look into this and will address the issue.

Can you share the sample? or if it is on VirusTotal, share the SHA256? Without having the sample it is very hard to debug. Most probably the .one file contains...

Can you share the file with me? without the file I am not able to debug and see what the problem is. If it is on VT or any other...

Make sense as I have not covered all filenode types. If the program cannot parse a filenode, it might result in jumping to a location in file that does not...

Thank you for sharing the sample, will check soon