This plugin detects OLE macros and other exploits inside Office documents attached to emails, including documents inside zip files and encrypted documents.
The plugin checks attached Office documents for OLE macros using several detection methods:
.docm or .xlsm are treated as containing a macro, and other Office documents are scanned for embedded OLE macros.olemacro_extended_scan is enabled, all attachments are scanned so an Office document renamed to a different extension is still detected.The amount scanned is bounded by olemacro_num_mime (the maximum number of MIME parts), olemacro_num_zip (the maximum number of files inside a zip), and olemacro_max_file (the maximum attachment size in bytes).
| Area | Rule name | Description | Default scores |
|---|---|---|---|
| body | OLEMACRO |
Attachment has an Office Macro | 0.1 |
| body | OLEMACRO_MALICE |
Potentially malicious Office Macro | 7.0 |
| body | OLEMACRO_RENAME |
Has an Office doc that has been renamed | 4.0 |
| body | OLEMACRO_ZIP_PW |
Has an Office doc that is password protected in a zip | 5.0 |
| body | OLEMACRO_ENCRYPTED |
Has an Office doc that is encrypted | 6.0 |