PDF malware analysis
In this section, we’ll have a look at PDF malware forensics and analysis. PDFs are possibly the most common form of document when sharing information as many people would rather open a PDF than an Office document, such as one in .docx
or .xls
format, as they are more likely to contain macros and even viruses. While PDFs are more trusted document types, it is still common to come across some that have been infected with malware or contain hidden information.
Although we won’t be analyzing malicious PDFs as it may result in your system becoming infected or experiencing some adverse effects, I will still introduce you to a tool called pdf-parser
, which can be used to inspect elements of a PDF document and pinpoint malicious code and other suspect elements.
This may be considered an advanced tool as people with programming experience typically use it to identify shellcode, streams, and filters. However, even beginners will be able to analyze the...