A forum for reverse engineering, OS internals and malware analysis 

All off-topic discussion goes here.
 #4161  by ssj100
 Wed Dec 29, 2010 1:57 am
I have a POC which opens "cmd.exe" and "regedit.exe" within the memory of Microsoft Office. Anyone have malicious malware samples of this (or similar)?

Some information here:
http://ssj100.fullsubject.com/t319-exce ... sting#2640
 #4175  by ssj100
 Wed Dec 29, 2010 10:35 am
Sorry, but I don't know what that means. It's probably easier if someone could directly upload and attach a working live malware that uses this technique. Otherwise, don't worry about it, and thanks for trying.