恶意PDF分析工具

原名:analyzing-malicious-pdf-with-peepdf

使用 peepdf 和 pdfid 对恶意 PDF 文档进行静态分析。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-18
TRACE 评分
3.2 / 5

内容概览

- When triaging suspicious PDF attachments from phishing emails - During malware analysis of PDF-based exploit documents - When extracting embedded JavaScript, shellcode, or executables from PDFs - For forensic examination of weaponized document artifacts - When building detection signatures for PDF-based threats - Python 3.8+ with peepdf-3 installed (pip install peepdf-3) - pdfid.py and pdf-parser.py from Didier Stevens suite - Isolated analysis environment (VM or sandbox) - Optional: PyV8 for JavaScript emulation within peepdf - Optional: Pylibemu for shellcode analysis 1. Triage with pdfid : Scan PDF for suspicious keywords (/JS, /JavaScript, /OpenAction, /Launch, /EmbeddedFile). 2. Interactive Analysis : Open PDF in peepdf interactive mode to explore object structure. 3. Identify Suspicious Objects : Locate objects containing JavaScript, streams, or encoded data. 4. Extract Content :…

查看 SKILL 详情