ProPDF

ProPDF is a blue team lab that falls under the Malware Analysis category and will cover the following subjects: CyberChef, Ghidra, VsCode, HexEditor, PDFwalker, Execution, Privilege Escalation, Defense Evasion, Command and Control.

Learning Objectives

Reconstruct a malicious PDF attack chain by analyzing embedded JavaScript, extracting the PE payload, identifying Windows API calls, and uncovering the C2 server and downloaded file.

Categories: Malware Analysis.

MITRE ATT&CK Tactics: Execution, Privilege Escalation, Defense Evasion, Command and Control.

Tools: PDFwalker, VsCode, HexEditor, CyberChef, Ghidra.

Difficulty: hard.