【笔记】EvilClippy学习笔记

前言

A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows.(Github

下载项目

1
2
git clone https://github.com/outflanknl/EvilClippy.git
cd EvilClippy

编译项目

MacOS

下载依赖

1
brew install mono

编译项目

1
mcs /reference:OpenMcdf.dll,System.IO.Compression.FileSystem.dll /out:EvilClippy.exe *.cs

Windows

1
"C:\Program Files\Microsoft Visual Studio\2022\Community\MSBuild\Current\Bin\amd64\csc.exe" /reference:OpenMcdf.dll,System.IO.Compression.FileSystem.dll /out:EvilClippy.exe *.cs

查看帮助

MacOS

1
mono EvilClippy.exe -h

Windows

1
EvilClippy.exe -h

合并VB代码到Office文件中

MacOS

-t 2016x86:指定目标Office版本

1
mono EvilClippy.exe -s <file>.vba <file>.doc

Windows

1
EvilClippy.exe -s <file>.vba <file>.doc

完成