首页
社区
课程
招聘
[转帖]Malicious VBA Macro’s: Trials and Tribulations
2021-1-22 06:46 1805

[转帖]Malicious VBA Macro’s: Trials and Tribulations

2021-1-22 06:46
1805

Malicious VBA Macro’s: Trials and Tribulations

Introduction

Over this past winter break, I wanted to go back to learning more about malicious Word/Excel Macros and what the potential is there. I made a blog post over a year ago where I talked about a technique I haven’t seen used very often involving linking a remote VBA template to a word doc, which was then downloaded and ran only when the document is open. In that same blog post, I also added a self-deletion technique, making it harder for the blue team to run forensics on the malicious doc. In this post, I’ll be talking about other techniques I’ve learned, including calling Windows API functions, and I’ll be discussing my (somewhat) failed attempt to write VBA that dumps the LSASS process, but also my successful attempt at writing a reverse shell completely in VBA (no shellcode injection or dropping exe’s).

https://john-woodman.com/research/malicious-vba-macros-trials-tribulations/



[培训]二进制漏洞攻防(第3期);满10人开班;模糊测试与工具使用二次开发;网络协议漏洞挖掘;Linux内核漏洞挖掘与利用;AOSP漏洞挖掘与利用;代码审计。

收藏
点赞4
打赏
分享
最新回复 (2)
雪    币: 2011
活跃值: (8355)
能力值: ( LV2,RANK:15 )
在线值:
发帖
回帖
粉丝
2DCoXrq 2021-1-22 18:30
2
0

网页本地存档

上传的附件:
雪    币: 85263
活跃值: (198560)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2021-1-22 18:32
3
0
FleTime 网页本地存档
游客
登录 | 注册 方可回帖
返回