decalage2 / oletools

oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.
http://www.decalage.info/python/oletools
Other
2.81k stars 560 forks source link

oleobj/oleid: distinguish legitimate hyperlinks from suspicious ones #847

Open decalage2 opened 3 months ago

decalage2 commented 3 months ago

for now, oleobj reports all hyperlinks the same way, and oleid reports them as high risk, even if those are legitimate hyperlinks in Excel or Word documents. It would at least be possible to flag some kinds of URLs as suspicious, for example: