Open decalage2 opened 4 years ago
It may be interesting to detect VBA Purging (when VBA P-Code has been removed and only compressed VBA source code is left), as explained in this article: https://blog.nviso.eu/2020/02/25/evidence-of-vba-purging-found-in-malicious-documents/ More VBA Purging links:
See also OfficePurge to generate samples:
It may be interesting to detect VBA Purging (when VBA P-Code has been removed and only compressed VBA source code is left), as explained in this article: https://blog.nviso.eu/2020/02/25/evidence-of-vba-purging-found-in-malicious-documents/ More VBA Purging links: