decalage2 / ViperMonkey

A VBA parser and emulation engine to analyze malicious macros.
1.04k stars 185 forks source link

documentation: mention password of artifacts zip #110

Open decalage2 opened 3 years ago

decalage2 commented 3 years ago

When vmonkey extracts artifact files, they are stored in a zip file <File>_artifacts.zip, with password "infected".

kirk-sayre-work commented 2 years ago

Added to my Python 3 fork.