<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Office &#8211; Cerbero Blog</title>
	<atom:link href="https://blog.cerbero.io/tag/office/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.cerbero.io</link>
	<description></description>
	<lastBuildDate>Mon, 18 Oct 2021 11:59:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://blog.cerbero.io/wp-content/uploads/2023/09/cropped-pro_icon_512-32x32.png</url>
	<title>Office &#8211; Cerbero Blog</title>
	<link>https://blog.cerbero.io</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">184292133</site>	<item>
		<title>Obfuscated XLSB Malware Analysis</title>
		<link>https://blog.cerbero.io/obfuscated-xlsb-malware-analysis/</link>
					<comments>https://blog.cerbero.io/obfuscated-xlsb-malware-analysis/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Mon, 18 Oct 2021 11:59:49 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Suite Advanced]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[XLSB]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=2257</guid>

					<description><![CDATA[This analysis was originally posted as a thread on Twitter. SHA256: B17FA8AD0F315C1C6E28BAFC5A97969728402510E2D7DC31A7960BD48DE3FCB6 By previewing the spreadsheet in Cerbero Suite, we can see that the macros are obfuscated. An obfuscated formula looks like this: =ATAN(83483899833434.0)=ATAN(9.34889399761e+16)=ATAN(234889343300.0)=FORMULA.ARRAY(&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT24&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT27&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT29&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT30&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT31&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT33&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT34&#38;&#039;erj74^#MNDKJ3OODL &#8230; <a href="https://blog.cerbero.io/obfuscated-xlsb-malware-analysis/" class="more-link">Continue reading<span class="screen-reader-text"> "Obfuscated XLSB Malware Analysis"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/obfuscated-xlsb-malware-analysis/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2257</post-id>	</item>
		<item>
		<title>Video: Emotet MS Office Malware 150-Seconds Analysis</title>
		<link>https://blog.cerbero.io/emotet-ms-office-malware-150-seconds-analysis/</link>
					<comments>https://blog.cerbero.io/emotet-ms-office-malware-150-seconds-analysis/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Tue, 21 Sep 2021 12:22:50 +0000</pubDate>
				<category><![CDATA[Video]]></category>
		<category><![CDATA[Emotet]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[VBA]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=2220</guid>

					<description><![CDATA[This Microsoft Office document belongs to the Emotet malware campaign and as part of its obfuscation strategy uses the content of text boxes from its VBA code. In the upcoming Cerbero Suite 5.1 we have simplified the analysis of text controls by previewing their name in the format view. The script below deobfuscates the VBA &#8230; <a href="https://blog.cerbero.io/emotet-ms-office-malware-150-seconds-analysis/" class="more-link">Continue reading<span class="screen-reader-text"> "Video: Emotet MS Office Malware 150-Seconds Analysis"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/emotet-ms-office-malware-150-seconds-analysis/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2220</post-id>	</item>
		<item>
		<title>Video: 1.5-Minutes QakBot Excel Malware Analysis (2nd sample)</title>
		<link>https://blog.cerbero.io/video-1-5-minutes-qakbot-excel-malware-analysis-2nd-sample/</link>
					<comments>https://blog.cerbero.io/video-1-5-minutes-qakbot-excel-malware-analysis-2nd-sample/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Wed, 10 Mar 2021 09:00:04 +0000</pubDate>
				<category><![CDATA[Video]]></category>
		<category><![CDATA[Emulator]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[XLS]]></category>
		<guid isPermaLink="false">https://cerbero-blog.com/?p=1973</guid>

					<description><![CDATA[The script extends the Silicon Excel Emulator by implementing th &#8220;FORMULA&#8221; function: from Pro.SiliconSpreadsheet import * from Pro.UI import proContext class EmulatorHelper(SiliconExcelEmulatorHelper): def __init__(self): super(EmulatorHelper, self).__init__() def evaluateFunction(self, emu, ctx, opts, depth, e): function_name = e.toString() if function_name == "FORMULA": if emu.expectedArguments(e, 2, 2): ve = emu.argToValue(ctx, opts, depth, e, 0) v = emu.valueToSpreadsheetValue(ve) idxstr &#8230; <a href="https://blog.cerbero.io/video-1-5-minutes-qakbot-excel-malware-analysis-2nd-sample/" class="more-link">Continue reading<span class="screen-reader-text"> "Video: 1.5-Minutes QakBot Excel Malware Analysis (2nd sample)"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/video-1-5-minutes-qakbot-excel-malware-analysis-2nd-sample/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1973</post-id>	</item>
		<item>
		<title>Video: 2-Minutes QakBot Excel Malware Analysis</title>
		<link>https://blog.cerbero.io/video-2-minutes-qakbot-excel-malware-analysis/</link>
					<comments>https://blog.cerbero.io/video-2-minutes-qakbot-excel-malware-analysis/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Tue, 09 Mar 2021 13:38:38 +0000</pubDate>
				<category><![CDATA[Video]]></category>
		<category><![CDATA[Emulator]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[XLS]]></category>
		<guid isPermaLink="false">https://cerbero-blog.com/?p=1971</guid>

					<description><![CDATA[The script extends the Silicon Excel Emulator by implementing the &#8220;NOW&#8221; and &#8220;FORMULA.FILL&#8221; functions: from Pro.SiliconSpreadsheet import * from Pro.UI import proContext class EmulatorHelper(SiliconExcelEmulatorHelper): def __init__(self): super(EmulatorHelper, self).__init__() def evaluateFunction(self, emu, ctx, opts, depth, e): function_name = e.toString() if function_name == "FORMULA.FILL": if emu.expectedArguments(e, 2, 2): ve = emu.argToValue(ctx, opts, depth, e, 0) v = &#8230; <a href="https://blog.cerbero.io/video-2-minutes-qakbot-excel-malware-analysis/" class="more-link">Continue reading<span class="screen-reader-text"> "Video: 2-Minutes QakBot Excel Malware Analysis"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/video-2-minutes-qakbot-excel-malware-analysis/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1971</post-id>	</item>
		<item>
		<title>Microsoft Office DDE Detection</title>
		<link>https://blog.cerbero.io/microsoft-office-dde-detection/</link>
					<comments>https://blog.cerbero.io/microsoft-office-dde-detection/#comments</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Wed, 10 Jan 2018 14:21:58 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Suite Standard]]></category>
		<category><![CDATA[DDE]]></category>
		<category><![CDATA[Macro]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Office]]></category>
		<guid isPermaLink="false">http://cerbero-blog.com/?p=1701</guid>

					<description><![CDATA[In this article we&#8217;re not going to discuss how DDE works, there are plenty of excellent resources about this topic already (also here and here). Instead we&#8217;re going to see how to inspect DDE field codes in Profiler. In fact, the upcoming 2.9 version of Profiler comes with detection of DDE field codes. So let&#8217;s &#8230; <a href="https://blog.cerbero.io/microsoft-office-dde-detection/" class="more-link">Continue reading<span class="screen-reader-text"> "Microsoft Office DDE Detection"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/microsoft-office-dde-detection/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1701</post-id>	</item>
	</channel>
</rss>
