-
Notifications
You must be signed in to change notification settings - Fork 560
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
OLEVBA do not show xls macro while OLEID indicate it exist #740
Comments
I can see this problem was solved in version oletools-0.60.1.dev6. |
Sorry for python 3.8.8 it works with the latest version.
Python 3.8.8:
|
I see that on Python 3 you have XLMMacroDeobfuscator installed, so it works well. But on Python 2 it is not installed, so olevba falls back to plugin_biff instead, and it triggers an exception when parsing the macro. |
It seems that XLMMacroDeobfuscator doesn't support python 2, only >3.4. |
OK, good catch. Then I need to adapt the setup script for python 2. |
Affected tool:
olevba version 0.6 (latest)
Describe the bug
OLEVBA failed to show and detect the macro inside XLS file. While OleId do indicate that.
File/Malware sample to reproduce the bug
Link: https://bazaar.abuse.ch/sample/2eb56d46618b75f2cd45197602d9c8e8c2fe63fd61fe25780d11f5e13a45959f/
sha256: 2eb56d46618b75f2cd45197602d9c8e8c2fe63fd61fe25780d11f5e13a45959f
OleId:
![image](https://user-images.githubusercontent.com/8919490/154229031-e7bb2d5d-e830-4783-b60c-e7dd0aa46ef5.png)
OleId
How To Reproduce the bug
regular run of oleid and olevba.
Expected behavior
olevba macro detected.
Console output / Screenshots
If applicable, add screenshots to help explain your problem.
Use the option "-l debug" to add debugging information, if possible.
Version information:
Additional context
no need.
The text was updated successfully, but these errors were encountered: