Quantcast
Viewing all articles
Browse latest Browse all 9687

.PUB Analysis, (Sat, Sep 24th)

Xavier reported a maldoc campaign using Microsoft Publisher files. These files can be analyzed just like malicious Word files.

oledump.py reveals VBA macros in this sample:

Image may be NSFW.
Clik here to view.

The VBA macro contains calls to the chr function. This could encode a URL or some other payload:

Image may be NSFW.
Clik here to view.

Image may be NSFW.
Clik here to view.

If you want more details, I made this video.

Didier Stevens
Microsoft MVP Consumer Security
blog.DidierStevens.com DidierStevensLabs.com

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Viewing all articles
Browse latest Browse all 9687

Trending Articles