PDF恶意文件分析
原名:analyzing-pdf-malware-with-pdfid
使用 PDFiD、pdf-parser 和 peepdf 工具分析恶意 PDF 文件,检测潜在威胁和可疑内容。
- 分类
- 开发提效
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-19
- TRACE 评分
- 3.2 / 5
内容概览
- A suspicious PDF attachment has been flagged by email security or reported by a user - You need to determine if a PDF contains embedded JavaScript, shellcode, or exploit code - Triaging PDF documents before opening them in a sandbox or analysis environment - Extracting embedded executables, scripts, or URLs from malicious PDF objects - Analyzing PDF exploit kits targeting Adobe Reader or other PDF viewer vulnerabilities Do not use for analyzing the rendered visual content of a PDF; this is for structural analysis of the PDF file format for malicious objects. - Python 3.8+ with Didier Stevens' PDF tools installed (pip install pdfid pdf-parser) - peepdf installed for interactive PDF analysis (pip install peepdf) - pdftotext from poppler-utils for extracting text content safely - YARA with PDF-specific rules for malware family identification - Isolated analysis VM without a PDF reader ins…