OLEVBMacro

This plugin detects OLE macros and other exploits inside Office documents attached to emails, including documents inside zip files and encrypted documents.

How it works

The plugin checks attached Office documents for OLE macros using several detection methods:

  • Macro-capable file extensions - attachments with extensions such as .docm or .xlsm are treated as containing a macro, and other Office documents are scanned for embedded OLE macros.
  • Files inside zips - password-protected Office documents inside a zip, as well as encrypted Office documents, are detected.
  • Renamed documents - when olemacro_extended_scan is enabled, all attachments are scanned so an Office document renamed to a different extension is still detected.

The amount scanned is bounded by olemacro_num_mime (the maximum number of MIME parts), olemacro_num_zip (the maximum number of files inside a zip), and olemacro_max_file (the maximum attachment size in bytes).

Rules

Area Rule name Description Default scores
body OLEMACRO Attachment has an Office Macro 0.1
body OLEMACRO_MALICE Potentially malicious Office Macro 7.0
body OLEMACRO_RENAME Has an Office doc that has been renamed 4.0
body OLEMACRO_ZIP_PW Has an Office doc that is password protected in a zip 5.0
body OLEMACRO_ENCRYPTED Has an Office doc that is encrypted 6.0

Related Pages