首页
社区
课程
招聘
[转帖]Malicious VBA Macro’s: Trials and Tribulations
2021-1-22 06:46 1821

[转帖]Malicious VBA Macro’s: Trials and Tribulations

2021-1-22 06:46
1821

Malicious VBA Macro’s: Trials and Tribulations

Introduction

Over this past winter break, I wanted to go back to learning more about malicious Word/Excel Macros and what the potential is there. I made a blog post over a year ago where I talked about a technique I haven’t seen used very often involving linking a remote VBA template to a word doc, which was then downloaded and ran only when the document is open. In that same blog post, I also added a self-deletion technique, making it harder for the blue team to run forensics on the malicious doc. In this post, I’ll be talking about other techniques I’ve learned, including calling Windows API functions, and I’ll be discussing my (somewhat) failed attempt to write VBA that dumps the LSASS process, but also my successful attempt at writing a reverse shell completely in VBA (no shellcode injection or dropping exe’s).

https://john-woodman.com/research/malicious-vba-macros-trials-tribulations/



[培训]《安卓高级研修班(网课)》月薪三万计划,掌 握调试、分析还原ollvm、vmp的方法,定制art虚拟机自动化脱壳的方法

收藏
点赞4
打赏
分享
最新回复 (2)
雪    币: 2013
活跃值: (8365)
能力值: ( LV2,RANK:15 )
在线值:
发帖
回帖
粉丝
2DCoXrq 2021-1-22 18:30
2
0

网页本地存档

上传的附件:
雪    币: 85485
活跃值: (198795)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2021-1-22 18:32
3
0
FleTime 网页本地存档
游客
登录 | 注册 方可回帖
返回