Open decalage2 opened 4 years ago
See this sample: https://labs.inquest.net/dfi/sha256/9404cbeacd30e170fe03bfdeb54663cb1439ccf73309e172e11349aa64fdbd00
Potential keywords (can be obfuscated):
Another post: https://codewhitesec.blogspot.com/2019/07/heap-based-amsi-bypass-in-vba.html
Also this one: https://depthsecurity.com/blog/obfuscating-malicious-macro-enabled-word-docs
See this sample: https://labs.inquest.net/dfi/sha256/9404cbeacd30e170fe03bfdeb54663cb1439ccf73309e172e11349aa64fdbd00
Potential keywords (can be obfuscated):