Explore advanced malware techniques in this 46-minute conference talk from Derbycon 2018. Delve into topics such as VBA stomping, Open XML, Object Linking and Embedding, and off-the-shelf frameworks. Learn about process creation, WMI, and reverse engineering techniques. Discover how macros are stored and how to open files with 7zip. Investigate tools like VBA Viper, Monkey Pcode Dump, and Yarra Signature. Gain insights into VBA Seismograph and participate in a Q&A session. Enhance your understanding of sophisticated malware methods and defense strategies.
Overview
Syllabus
Introduction
Meet the speakers
Open XML
Extensions can lie
XLS
Object Linking and Embedding
Offtheshelf Frameworks
Process Create
WMI
Taunted
Reverse
How macros are stored
Opening with 7zip
Search for string ABC
Zip tool
ABC doc
Compatibility
BB Stomp
La VBA
Viper Monkey
Pcode Dump
Yarra Signature
VBA Seismograph
Questions