Parsing Google Docs HTML
ID: 608dca87-46bc-5ee7-9c63-d85ecb00ade0
STIX ID: report--608dca87-46bc-5ee7-9c63-d85ecb00ade0
Feed Name: KMsec blog
Threat Score
This analysis demonstrates a method to extract document metadata, text, embedded links, and images from Google Docs HTML script tags, and applies it to a corpus of 25,000+ public docs to uncover a phishing campaign targeting financial brands (e.g., American Express) with observable malicious links; the author provides a parsing tool and searchable corpus to hunt related documents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
