spender-sandbox / cuckoo-modified

Modified edition of cuckoo
394 stars 178 forks source link

ole embeds in docs? #339

Open mallorybobalice opened 7 years ago

mallorybobalice commented 7 years ago

http://payload-security.blogspot.com.au/2016/10/on-dridex-and-new-zero-day-distribution_27.html?m=1

Haven't tried myself but what's peoples experience with these?

mallorybobalice commented 7 years ago

just tested on our test box (4m behind) for me neither ole from docs (e.g. embedded docs) nor docs out of msg files get extracted directly or into dropped :( @spender-sandbox help? /options/fixed in newer commits?