06.03.2017 Views

Philippe Lagadec – decalage.info - @decalage2

esi4ybW

esi4ybW

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

MacroRaptor - mraptor<br />

Observations:<br />

• Malicious macros need to start automatically.<br />

• AutoOpen, Document_Open, Document_Close, etc<br />

• They need to drop a payload as a file, or inject code into a process.<br />

• They need to execute the payload.<br />

• Most of these actions cannot be obfuscated in VBA.<br />

• Most non-malicious macros do not use these features.<br />

=> It is possible to detect most malicious macros using a small<br />

number of keywords.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!