Pafishmacro
Pafish Macro is a Macro enabled Office Document to detect malware analysis systems and sandboxes. It uses evasion & detection techniques implemented by malicious documents.
Install / Use
/learn @joesecurity/PafishmacroREADME
Pafish Macro
(Paranoid Fish)
Pafish Macro is a Macro enabled Office Document to detect malware analysis systems and sandboxes. It uses evasion & detection techniques implemented by recent malicious documents found in the public.
The VBS / VBA code is open source, you can study the code of all evasion tricks.
Code is licensed under GNU/GPL version 3.
You can download the pafish macro document here.

Target
The goal of this project is find and collect evasion tricks seen in recent Office malware samples. The code enables to understand evasions and helps to improve malware analysis systems and sandboxes.
This project is based on famous Pafish by Alberto Ortega
Author
Joe Security (@joe4security - webpage)
Related Skills
node-connect
344.4kDiagnose OpenClaw node connection and pairing failures for Android, iOS, and macOS companion apps
frontend-design
99.2kCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.
openai-whisper-api
344.4kTranscribe audio via OpenAI Audio Transcriptions API (Whisper).
qqbot-media
344.4kQQBot 富媒体收发能力。使用 <qqmedia> 标签,系统根据文件扩展名自动识别类型(图片/语音/视频/文件)。
