Quickly Finding Encoded Payloads in Office Documents, (Sun, May 7th)

Malicious documents like this RevengeRAT ppam file found on MalwareBazaar contain VBA code that you can analyze with oledump.py.

Article Link: https://isc.sans.edu/diary/rss/29818