Open wichmannpas opened 3 years ago
Started analyzing with commit 6509f418feb7684c46b76eefb28b82baccbef286
Automatic (Malicious) Macro detection implemented with quicksand in commit 3254923e12367a4b4d82db7b03d805e4cefcee68. However, Macro removal still has to be implemented.
Added multiple YARA rules for detecting Office Documents with Macros.
A few selected rules: