GetPDF

GetPDF is a blue team lab that falls under the Malware Analysis category and will cover the following subjects: de4js, pdfid, pdfparser, peepdf, PDFStreamDumper, Wireshark, tshark, scdbg, NetworkMiner, Initial Access, Execution, Command and Control.

Learning Objectives

Reconstruct a multi-stage PDF malware attack by analyzing network traffic, dissecting PDF objects, deobfuscating JavaScript, and emulating shellcode to identify payloads and exploited CVEs.

Categories: Malware Analysis.

MITRE ATT&CK Tactics: Initial Access, Execution, Command and Control.

Tools: de4js, pdfid, pdfparser, peepdf, PDFStreamDumper, Wireshark, tshark, scdbg, NetworkMiner.

Difficulty: medium.