Evil Clippy Makes Malicious Office Docs that Dodge Detection
#1
Quote:Security researchers brought to life and released a wicked variant of Clippy, the recently resurfaced assistant in Microsoft Office that we all loved so much to hate, that makes it more difficult to detect a malicious macro in documents.

Dubbed Evil Clippy, the tool modifies Office documents at file format level to spew out malicious versions that get by the static analysis of antivirus engines and even utilities for manual inspection of macro scripts.

To do this, it takes advantage of undocumented features, unclear specifications, and deviations from intended implementations.

Macros are snippets of VBA (Visual Basic for Applications) code that automate tasks in Microsoft Office applications. They are constantly used to deliver malware when the user opens a document.

SOURCE
[-] The following 2 users say Thank You to Mohammad.Poorya for this post:
  â€˘ harlan4096, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes 19.1.6
25.4.0 All TODO...Kool — 16:06
YouTube updates Shorts view count metho...
This is a smart and ...Kiran78 — 11:41
Microsoft Edge 135.0.3179.73
Version 135.0.3179...harlan4096 — 06:08
AnyDesk 9.5.1 for Windows
AnyDesk 9.5.1 for ...harlan4096 — 06:07
Messengers 101: safety and privacy advic...
A dozen short and ...harlan4096 — 06:05

[-]
Birthdays
Today's Birthdays
avatar (37)urumahiz
Upcoming Birthdays
avatar (44)wapedDow
avatar (48)oapedDow
avatar (41)Sanchowogy
avatar (45)MeighGoask
avatar (43)techlignub
avatar (42)Stevenmam
avatar (49)onlinbah
avatar (49)fuspeukChark
avatar (43)werriewWaiNg
avatar (37)Freemanleo
avatar (42)cdoubapKit
avatar (37)lystraPonia
avatar (30)smith8395john
avatar (50)steakelask
avatar (44)Termoplenka
avatar (42)bycoPaist
avatar (48)pieloKat
avatar (42)ilyagNeexy
avatar (50)donitascene
avatar (50)Toligo
avatar (45)Rodneykak
avatar (48)tradeSmode
avatar (37)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>