We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
When interpreting defined names it is necessary to only consider the first byte of name field if the name is a built-in one.
Some malicious documents, use arbitrary label for built in defined names such as auto_open to evade analysis tools.
example: https://twitter.com/c0ntrol_z/status/1260205314193883136
ref: https://twitter.com/c0ntrol_z/status/1259967792998232073
The text was updated successfully, but these errors were encountered:
FIX - problem in handleing built-in defined names #1
2750e74
DissectMalware
No branches or pull requests
When interpreting defined names it is necessary to only consider the first byte of name field if the name is a built-in one.
Some malicious documents, use arbitrary label for built in defined names such as auto_open to evade analysis tools.
example: https://twitter.com/c0ntrol_z/status/1260205314193883136
ref: https://twitter.com/c0ntrol_z/status/1259967792998232073
The text was updated successfully, but these errors were encountered: