-
Notifications
You must be signed in to change notification settings - Fork 569
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
XLM4 is not detected #741
Comments
Hi @randubin, this looks similar to #728: could you please update oletools with the following command and tell me if it works?
This will install XLMMacroDeobfuscator, which is now used to detect and extract XLM macros. By default XLMMacroDeobfuscator is not installed by pip. You can also install it separately (see https://github.com/DissectMalware/XLMMacroDeobfuscator). |
Thanks for the fast response!. What is [full]? I tried to update from git or from pip and got the same result. [Made sure that I have the latest version for XLMMacroDeobfuscator pip install -U https://github.com/DissectMalware/XLMMacroDeobfuscator/archive/master.zip
|
Affected tool:
olevba,oleid
Describe the bug
XLM4 exists in the file, but oletools do not detect it.
File/Malware sample to reproduce the bug

https://bazaar.abuse.ch/sample/306433cdeddadf922a7849ab12431fbdb1f1f7f23dc4de1c2e378dcf9a05ca8a/
How To Reproduce the bug
Tested on pyton 3.8 oletools 0.60.1.dev6
Expected behavior
XLM 4 detected.
Console output / Screenshots
Version information:
The text was updated successfully, but these errors were encountered: