ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

Macro Office Exploit


  • Please log in to reply
Macro Office Exploit

#1

pruned_62471256
pruned_62471256
    Offline
    2
    Rep
    76
    Likes

    Veteran

  • PipPipPipPipPipPipPip
Posts: 537
Threads: 28
Joined: May 07, 2015
Credits: 0
Eight years registered
#1

Here is example of Macro Office exploit, The detection rate is 7/35 and if you work on it it will be 0/35

 

crimeware-640x505.jpg

Hidden Content
You'll be able to see the hidden content once you reply to this topic or

Please Login or Register to see this Hidden Content

.


  • 15

#2

pruned_82626945
pruned_82626945
    Offline
    0
    Rep
    0
    Likes

    Lurker

  • Pip
Posts: 3
Threads: 0
Joined: Aug 06, 2015
Credits: 0
Eight years registered
#2

Thank you this will be very handy! any advice on 0/35?


  • 0

#3

kiko0735
kiko0735
    Offline
    2
    Rep
    0
    Likes

    Member

Posts: 53
Threads: 0
Joined: Jan 23, 2015
Credits: 0
Eight years registered
#3

lol, seen this alot of times, but i guess we have 2 obfuscate it?


  • 0

#4

Rivaldo00
Rivaldo00
    Offline
    2
    Rep
    -9
    Likes

    Junkie

Posts: 356
Threads: 0
Joined: May 14, 2015
Credits: 0
Eight years registered
#4

ty


  • 0

#5

elisha13
elisha13
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 74
Threads: 0
Joined: Jul 25, 2015
Credits: 0
Eight years registered
#5

Thanks a Loot!!! 


  • 0

#6

Kaname
Kaname
    Offline
    2
    Rep
    1
    Likes

    Member

Posts: 52
Threads: 2
Joined: Jul 08, 2015
Credits: 0
Eight years registered
#6

thank you ..Great share (Y)


  • 0

#7

pruned_58744019
pruned_58744019
    Offline
    2
    Rep
    5
    Likes

    Junkie

  • PipPipPipPipPipPip
Posts: 372
Threads: 1
Joined: May 11, 2015
Credits: 0
Eight years registered
#7

How about the refud procedure bro?


  • 0

#8

pruned_54198522
pruned_54198522
    Offline
    0
    Rep
    10
    Likes

    Advanced Member

  • PipPipPipPip
Posts: 99
Threads: 2
Joined: Jul 31, 2015
Credits: 0
Eight years registered
#8

How about the refud procedure bro?

 

Few things you can try to reFUD it.

 

First of all you need some basic coding knowledge otherways you shouldn't be reFUDing.

 

 

1. Remove parts of the macro untill it's FUD on the scanner. Then try to do the following things with the code you had to remove to make it FUD.

2. Change variable names.

3. Change the order of the code.

4. Try to change or use an encryption, if it hasn't already one on it, on parts of the code where it's possible.

5. Recode certain parts if you really can't get it FUD without changing that certain part.


  • 0

#9

SpheXii
SpheXii
    Offline
    2
    Rep
    2
    Likes

    Junkie

Posts: 348
Threads: 2
Joined: Jun 30, 2015
Credits: 0
Eight years registered
#9

thanks!


  • 0

#10

NotACop
NotACop
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 5
Threads: 0
Joined: Aug 07, 2015
Credits: 0
Eight years registered
#10

will refud it


  • 0


 Users browsing this thread: