Quick Howto: Extract URLs from RTF files, (Mon, Feb 9th)
ID: 21d9bf18-2af1-5169-b603-7de089d8499e
STIX ID: report--21d9bf18-2af1-5169-b603-7de089d8499e
Feed Name: SANS ISC Diary
Threat Score
Malicious RTF documents exploiting CVE-2026-21509 and attributed to APT28 are examined; the author demonstrates extracting embedded URLs and IOCs from RTF objects using rtfdump.py → strings.py → re-search.py, and highlights discovered domains, private IPs, and unusual UNC/WebDAV notations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
