Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le mars 23, 2017, 21:00:44

Titre: [MMPC]Malicious macro using a sneaky new trick
Posté par: igor51 le mars 23, 2017, 21:00:44
Malicious macro using a sneaky new trick

We recently came across a file (ORDER-549-6303896-2172940.docm, SHA1: 952d788f0759835553708dbe323fd08b5a33ec66) containing a VBA project that scripts a malicious macro (SHA1: 73c4c3869304a10ec598a50791b7de1e7da58f36). We added it under the detection TrojanDownloader:O97M/Donoff – a large family of Office-targeting macro-based malware that has been active for several years (see our blog category on macro-based malware for more blogs). However, there wasn’t...
Source: Malicious macro using a sneaky new trick (https://blogs.technet.microsoft.com/mmpc/2016/05/17/malicious-macro-using-a-sneaky-new-trick/)