Tools: oledump.py
Twitter: @JohnLaTwC
Sample: 1bf30ae0d9fb2b9fcf16575e40f26110
Tools: rtfdump.py
ISC Diary entry: Dealing with obfuscated RTF files
Sample: a3d89108e4a13900c299d7c5f6d687e0
Payload: InfiniteControl
Tools: oledump.py, zipdump.py, base64dump.py, pecheck.py, Metasploit
Tools: oledump.py, base64dump.py
Sample: 9c4c3234f20b6102569216675b48c70a
ISC Diary Entry: It’s Not An Invoice …
Tools: xor-kpa.py