Tools: oledump.py, zipdump.py
ISC diary entries: Simple YARA Rules for Office Maldocs, YARA Rule for OOXML Maldocs: Less False Positives
Tools: oledump.py, zipdump.py
ISC diary entries: Simple YARA Rules for Office Maldocs, YARA Rule for OOXML Maldocs: Less False Positives
Sample: a9490d94cf547e27dcc0d52dc72e74e7
Tools: oledump.py, zipdump.py, xmldump.py, translate.py, base64dump.py
ISC Diary entry: Obfuscated Maldoc: Reversed BASE64