[CentOS] Detecting empty office doc containing virus macro

Gary Stainburn

gary at ringways.co.uk
Wed Oct 28 11:55:52 UTC 2015


We are receiving LOTS of emails that contain empty XLS or DOC documents with 
embedded virus macros.  These are getting past SPAMASSASSIN, Clamav and 
Kaspersky.

I'm trying to write a filter for EXIM to block these emails but I need to know 
a good, quick, command-line to detect an empty doc with a macro.

Is there anything available that I can use??

I have managed to write a PERL script to detect empty xls xlsx, doc and docx 
files but I cannot detect whether they have any macros embedded

Gary



More information about the CentOS mailing list