
Analyzing Phishing Documents by 0xdf - HTB Village at H@cktivityCon 2021
Source: YouTube · Hack The Box · published Sep 18, 2021 · 42:42
This presentation provides an introduction to analyzing phishing documents 0:00, covering the importance of this skill in cybersecurity and demonstrating tools and techniques for analysis 1:27. The speaker explains that phishing documents are a common attack vector that constantly evolves 1:46 and can be analyzed with relatively basic technical skills 2:37.
Key Takeaways:
• Phishing documents use legitimate features to execute malicious code, such as DDE fields in Excel or VBA macros in Office documents 9:34
• Office documents come in two formats: older binary formats (.doc, .xls) and newer XML-based formats (.docx, .xlsx) which can be extracted as zip files 13:00
• Tools like olevba, pdfid, and ole_dump are essential for analyzing different document formats 19:56
• De-obfuscation techniques include using native editors, CyberChef, and removing useless code to understand malicious payloads 23:17
• Practice resources include VirusTotal for real malware samples, malware-traffic-analysis.net, and CTF challenges on platforms like Hack The Box 25:00
The presentation concludes with practical demonstrations of analyzing malicious documents, emphasizing that understanding how documents gain execution is the key first step in analysis 7:19.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
hi welcome to phishing uh analyzing phishing documents 101 uh for hacktivitycon let's go ahead and get started um so who am i what are my names and groups here my name is david forsythe i go by oxdf on the internet and i am a training architect at hack the box and that means i do all sorts of things for the platform i develop machine and challenge content i also develop automations and stuff behind the scene to help support the platform and the processes that involve getting everything out for people every week and um actually for the last few months i've been leading our efforts on getting our weekly vulnerable machine out to the pub tested and available and out to the public so i wear a lot of different hats there um before coming to hack the box earlier this year i have 15 years of expe…