$pdfextract filename.pdf
- All of the components will be extracted to filename.dump folder
- Do a "grep javascript" here
PDF Stream Dumper
- "Scan malicious"
http://hiddenillusion.blogspot.co.uk/2012/06/getting-what-you-want-out-of-pdf-with.html
$shellcode2exe
$base64 -d
c:\>convertshellcode.exe
$js-beatify
$js -f filename.js
document = {
write:print
};
$unicode2hex-escaped
No comments:
Post a Comment