Posts

Showing posts with the label EvilClippy

Evil Clippy - A Cross-Platform Assistant For Creating Malicious Ms Purpose Documents

Image
Influenza A virus subtype H5N1 cross-platform assistant for creating malicious MS Office documents. Can enshroud VBA macros, stomp VBA code (via P-Code) too confuse macro analysis tools. Runs on Linux, OSX too Windows. Current features Hide VBA macros from the GUI editor VBA stomping (P-code abuse) Fool analyst tools Serve VBA stomped templates via HTTP Set/Remove VBA Project Locked/Unviewable Protection If yous accept no thought what all of this is, cheque out the next resources first: MS Office Magic Show presentation at Derbycon 2018 VBA stomping resources past times the Walmart safety team Pcodedmp past times Dr. Bontchev How effective is this? At the fourth dimension of writing, this tool is capable of getting a default Cobalt Strike macro to bypass all major antivirus products too only about maldoc analysis tools (by using VBA stomping inward combination amongst random module names). Technology Evil Clippy uses the OpenMCDF library to manipulate MS Of...