Sample: 55c336693e66b5d6a799b6b4f8eb5f1a.
Tools: pdfid.py, pdf-parser.py
Blog post: Analyzing a Phishing PDF with /ObjStm
Sample: 55c336693e66b5d6a799b6b4f8eb5f1a.
Tools: pdfid.py, pdf-parser.py
Blog post: Analyzing a Phishing PDF with /ObjStm
Sample: 8598361ecbbffb35900d0720b0316a56.
Tools: oledump.py
ISC Diary entry: Video: Finding Property Values in Office Documents
Sample: 8598361ecbbffb35900d0720b0316a56.
Tools: oledump.py, base64dump.py, zipdump.py
ISC Diary entry: Video: Maldoc Analysis of the Weekend
Tools: msoffcrypto-crack.py, oledump.py
ISC Diary entry: Video: Analyzing Encrypted Malicious Office Documents
Sample: 2d0d0094b25f0116dbdfa85a2a3b69d2
Tools: numbers-to-string.py
ISC Diary entry: Video: De-DOSfuscation Example
Sample: 1f27e4d035c8ec71264c9fb1c8915f0b
Tools: rtfdump.py, oledump.py, format-bytes.py, scdbg.exe
ISC Diary entry: Dissecting a CVE-2017-11882 Exploit
Sample: 7ea8e50ce884dab89a13803ccebea26e
Tools: CyberChef
ISC Diary entry: CyberChef: BASE64/XOR Recipe
Sample: dfff3a02e6e6a4d079c12f83dcc2f7a5
Tools: re-search.py, sets.py, python-per-line.py
ISC Diary entry: When DOSfuscation Helps…