«   2025/05   »
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Tags
more
Archives
Today
Total
관리 메뉴

www.ManiaLab.com

analysis suspicious PDF 본문

1.Sec_Etc

analysis suspicious PDF

HaiDong 2009. 12. 16. 16:48

# analysis suspicious pdf(file name is pdf.pdf that is downloaded at gowlave.cn)

# HaiDong, 091215
 

# uncompress pdf stream by pdftk



# decode str variable section by malzla


  

# analysis IyLrgiy variable

 


# copy upper decoded data & paste by hex at Hex view Tab
 




# exe.php is malware as below


Comments