Re: Detecting empty office doc containing virus macro

2015-10-28 Thread Gary Stainburn
On Wednesday 28 October 2015 13:45:17 Ian Malone wrote: > Don't know how to answer your question, but if you know how to detect > empty documents then why not just assume they're malicious? Don't > think there's any common reason to send empty documents around. > I think that I'm going to go down

Re: Detecting empty office doc containing virus macro

2015-10-28 Thread Ian Malone
On 28 October 2015 at 11:56, Gary Stainburn wrote: > We are receiving LOTS of emails that contain empty XLS or DOC documents with > embedded virus macros. These are getting past SPAMASSASSIN, Clamav and > Kaspersky. > > I'm trying to write a filter for EXIM to block these emails but I need to kno

Detecting empty office doc containing virus macro

2015-10-28 Thread Gary Stainburn
We are receiving LOTS of emails that contain empty XLS or DOC documents with embedded virus macros. These are getting past SPAMASSASSIN, Clamav and Kaspersky. I'm trying to write a filter for EXIM to block these emails but I need to know a good, quick, command-line to detect an empty doc with