Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: Analyzing Office Maldocs With Decoder.xls SANS ISC InfoSec Forums

Special Webcast: What you need to know about the crypt32.dll vulnerability. Register Now

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Analyzing Office Maldocs With Decoder.xls

In my last diary entry, I show how to decode VBA maldoc strings with Excel. A similar technique can be used to decode a payload (like shellcode).

I explain this method in this video.

Didier Stevens
Microsoft MVP Consumer Security
blog.DidierStevens.com DidierStevensLabs.com

DidierStevens

411 Posts
ISC Handler

Sign Up for Free or Log In to start participating in the conversation!