We look at two techniques for MS Office files to load and execute malicious code without Macros, namely VSTO Add-ins and External Templates. At the end I provide a checklist for analyzing office files to determine if they are clean.
Discord: / discord
Courses: https://malwareanalysis-for-hedgehogs...
Samples: https://samplepedia.cc/?q=&difficulty...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter: / struppigel
#malware #malwareanalysis #reverseengineering
00:00 Intro
01:26 Sample 1 - Local VSTO Add-in and ISO
07:49 Sample 2 - Remote VSTO Add-in
08:53 Sample 3 - External Templates
10:52 Binary Refinery for general Office file checks
16:15 Checklist for Office analysis