Commit caa1e066049d8ad1995c433e820bb7461b41c3f4
1 parent
c6db08ab
olevba: fixed small bug in suspicious keywords
Showing
1 changed file
with
2 additions
and
2 deletions
oletools/olevba.py
| ... | ... | @@ -189,7 +189,7 @@ SUSPICIOUS_KEYWORDS = { |
| 189 | 189 | #FileCopy: http://msdn.microsoft.com/en-us/library/office/gg264390%28v=office.15%29.aspx |
| 190 | 190 | #CopyFile: http://msdn.microsoft.com/en-us/library/office/gg264089%28v=office.15%29.aspx |
| 191 | 191 | 'May create a text file': |
| 192 | - ('CreateTextFile'), | |
| 192 | + ('CreateTextFile',), | |
| 193 | 193 | #CreateTextFile: http://msdn.microsoft.com/en-us/library/office/gg264617%28v=office.15%29.aspx |
| 194 | 194 | 'May run an executable file or a system command': |
| 195 | 195 | ('Shell', 'vbNormalFocus', 'vbHide', 'vbMinimizedFocus', 'vbMaximizedFocus', 'vbNormalNoFocus', 'vbMinimizedNoFocus'), |
| ... | ... | @@ -219,7 +219,7 @@ SUSPICIOUS_KEYWORDS = { |
| 219 | 219 | ('SendKeys', 'AppActivate'), |
| 220 | 220 | #SendKeys: http://msdn.microsoft.com/en-us/library/office/gg278655%28v=office.15%29.aspx |
| 221 | 221 | 'May attempt to obfuscate malicious function calls': |
| 222 | - ('CallByName'), | |
| 222 | + ('CallByName',), | |
| 223 | 223 | #CallByName: http://msdn.microsoft.com/en-us/library/office/gg278760%28v=office.15%29.aspx |
| 224 | 224 | 'May attempt to obfuscate specific strings': |
| 225 | 225 | ('Chr', 'ChrB', 'ChrW'), | ... | ... |