Blog post: Bash Bunny PDF Dropper
Tools: make-pdf tools
Tools: oledump.py.
Tools: cut-bytes.py.
ISC Diary entry: Another example of maldoc string obfuscation, with extra bonus: UAC bypass
Tools: oledump.py, re-search.py and sets.py.
Sample: 7dff363557f711a92216da9e9af3bb1f
Blog post: New Tool: sets.py
ISC Diary entry: Sleeping VBS Really Wants To Sleep
Tools: oledump.py
Sample: 7EAB96D2BC04CA155DE035815B88EE00