Tools: pdfid.py and pdf-parser.py, QPDF and Poppler.
ISC diary entries: “Encrypted Sextortion PDFs”
Sample: 294592cd85ddf80ad1a092f955f1ae25
Tools: pdfid.py and pdf-parser.py, QPDF and Poppler.
ISC diary entries: “Encrypted Sextortion PDFs”
Sample: 294592cd85ddf80ad1a092f955f1ae25
Tools: search-for-compression.py
ISC diary entries: “Malicious .DAA Attachments” and “The DAA File Format”
Sample: 6e8947a82c97c26728dc590ed797ee23