logo

Quick Howto: Extract URLs from RTF files, (Mon, Feb 9th)

ID: 21d9bf18-2af1-5169-b603-7de089d8499e

STIX ID: report--21d9bf18-2af1-5169-b603-7de089d8499e

Feed Name: SANS ISC Diary

Threat Score
85/100

Date Published: 2026-02-09

Date Updated: 2026-04-19

...
...

Malicious RTF documents exploiting CVE-2026-21509 and attributed to APT28 are examined; the author demonstrates extracting embedded URLs and IOCs from RTF objects using rtfdump.py → strings.py → re-search.py, and highlights discovered domains, private IPs, and unusual UNC/WebDAV notations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.