Analyzing Malicious Documents Cheat Sheet
Analyzing Malicious Documents Cheat Sheet
COM/)
(https://twitt
(http
Analzing Malicious
Documents Cheat Sheet
MOR ON
Information Securit
(https://zeltser.com/information-
securit)
Malicious Software
(https://zeltser.com/malicious-
This cheat sheet outlines tips and tools for analzing malicious docu- software)
ments, such as Microsoft O ce, RTF and Adoe Acroat (PDF) les. To
print it, use the one-page PDF (/media/docs/analzing-malicious-docu-
ment- les.pdf) version; ou can also edit the Word (/media/docs/analz-
ing-malicious-document- les.docx) version to customize it for ou own The SANS malware analsis course
pcodedmp.p Disassemle
(https://githu.com/ontchev/pcodedmp) -d le.doc p-code macro
code from
le.doc.
Post-Scriptum
Special thanks for feedack to Pedro ueno
(http://handlers.dshield.org/pueno/) and Didier Stevens (http://log.di-
dierstevens.com/). If ou have suggestions for improving this cheat
sheet, please let me know (/contact/). Creative Commons v3 “Attriu-
tion” License (http://creativecommons.org/licenses//3.0/) for this cheat
sheet version 3.0.