Quick Howto: ZIP Files Inside RTF, (Mon, Mar 2nd)
ID: 4e44c1c3-08f0-571b-a582-c3c49ad7006c
STIX ID: report--4e44c1c3-08f0-571b-a582-c3c49ad7006c
Feed Name: SANS ISC Diary
Didier Stevens provides a concise technical walkthrough for extracting URLs from RTF files by inspecting embedded OLE objects and DOCX (ZIP) containers. He shows using oledump.py to enumerate OLE streams, identifying abused CLSIDs and URL-containing streams, then using zipdump.py and searching for the ZIP magic header (50 4B 03 04) to locate and extract URLs from compressed files embedded inside RTF documents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
