Blog post: Malicious Documents: The Matryoshka Edition
Tools: pdf tools, oledump.py, re-search.py
Sample: 98a727a32fee7115d9599b4df9b6b433
Blog post: Malicious Documents: The Matryoshka Edition
Tools: pdf tools, oledump.py, re-search.py
Sample: 98a727a32fee7115d9599b4df9b6b433
Tools: oledump.py.
Tools: cut-bytes.py.
ISC Diary entry: Another example of maldoc string obfuscation, with extra bonus: UAC bypass
Tools: oledump.py, re-search.py and sets.py.
Sample: 7dff363557f711a92216da9e9af3bb1f
Blog post: New Tool: sets.py