{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,23]],"date-time":"2026-01-23T10:53:14Z","timestamp":1769165594040,"version":"3.49.0"},"reference-count":54,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,10,20]],"date-time":"2020-10-20T00:00:00Z","timestamp":1603152000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,10,20]],"date-time":"2020-10-20T00:00:00Z","timestamp":1603152000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,10,20]],"date-time":"2020-10-20T00:00:00Z","timestamp":1603152000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,10,20]]},"DOI":"10.1109\/isncc49221.2020.9297272","type":"proceedings-article","created":{"date-parts":[[2020,12,25]],"date-time":"2020-12-25T22:06:21Z","timestamp":1608933981000},"page":"1-6","source":"Crossref","is-referenced-by-count":8,"title":["P-Code Based Classification to Detect Malicious VBA Macro"],"prefix":"10.1109","author":[{"given":"Simon","family":"HUNEAULT-LEBLANC","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chamseddine","family":"TALHI","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2011.08.020"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1504\/IJESDF.2007.016865"},{"key":"ref33","article-title":"New malicious macro evasion tactics exposed in URSNIF spam mail","author":"banes","year":"2017"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/IACS.2018.8355435"},{"key":"ref31","article-title":"Generic VBA instrumentation for microsoft office documents","year":"2016"},{"key":"ref30","article-title":"Dynamically analyze offices macros by instrumenting VBE","year":"2015"},{"key":"ref37","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/2190-8532-1-1","article-title":"Detecting unknown malicious code by applying classification techniques on OpCode patterns","volume":"1","author":"shabtai","year":"2012","journal-title":"Security Informatics"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2018.00057"},{"key":"ref35","first-page":"41","article-title":"Applied Machine Learning: Defeating Modern Malicious Documents","author":"gaustad","year":"2017"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2016.2631905"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-73614-1_14"},{"key":"ref27","article-title":"Hybrid analysis","year":"2018"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.45"},{"key":"ref2","article-title":"20 years of macro malware: From harmless concept to targeted attacks","author":"micro","year":"2015"},{"key":"ref1","article-title":"pcodedmp.py - a VBA p-code disassembler","author":"bontchev","year":"2018"},{"key":"ref20","article-title":"The three faces of vba","author":"bontchev","year":"2005"},{"key":"ref22","article-title":"oletools - python tools to analyze OLE and MS office files","author":"lagadec","year":"2018"},{"key":"ref21","article-title":"VBA Stomping Advanced Maldoc Techniques","author":"roberts","year":"2018"},{"key":"ref24","article-title":"ViperMonkey","author":"lagadec","year":"2018"},{"key":"ref23","article-title":"Didier Stevens - oledump.py","author":"stevens","year":"2018"},{"key":"ref26","article-title":"JoeSandBox cloud basic","year":"2018"},{"key":"ref25","article-title":"How sure are you, that your VBA source code is safe?","year":"2018"},{"key":"ref50","author":"chowdhury","year":"2010","journal-title":"Introduction to Modern Information Retrieval"},{"key":"ref51","article-title":"Generalized fisher score for feature selection","author":"gu","year":"2012","journal-title":"CoRR"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2017.8258483"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.5220\/0006132202950302"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1948.tb01338.x"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(17)30049-1"},{"key":"ref11","article-title":"Multi-stage email word attack without macros","author":"pacag","year":"2018"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.2197\/ipsjjip.27.555"},{"key":"ref12","article-title":"office-exploit-case-study","year":"2018"},{"key":"ref13","article-title":"Analyze of a malicious word document with an embedded payload","year":"2014"},{"key":"ref14","article-title":"Gozi isfb remains active in 2018, leverages &#x201D;Dark Cloud\" botnet for distribution","author":"brumaghin","year":"2018"},{"key":"ref15","article-title":"De-obfuscating malicious vbscripts","author":"arntz","year":"2016"},{"key":"ref16","article-title":"Targeted attacks in the middle east","author":"rascagneres","year":"2018"},{"key":"ref17","article-title":"Introducing the office (2007) open XML file formats","author":"rice","year":"2006"},{"key":"ref18","article-title":"The truth about p-code","author":"bruyere","year":"2011"},{"key":"ref19","article-title":"VB P-code information by Mr. Silver","author":"silver","year":"2003"},{"key":"ref4","article-title":"Beware of doc! a look at malicious macros","year":"2015"},{"key":"ref3","article-title":"Panda banker: New banking trojan hits the market","author":"f","year":"2016"},{"key":"ref6","article-title":"Malicious document targets pyeongchang olympics","author":"sherstobitoff","year":"2018"},{"key":"ref5","article-title":"BlackEnergy APT attacks in ukraine employ spearphishing with word documents","year":"2016"},{"key":"ref8","article-title":"McAfee labs threats report september 2018","year":"2018"},{"key":"ref7","article-title":"McAfee labs threats report","year":"2018"},{"key":"ref49","article-title":"Example file-how did it come about?","author":"van zelm","year":"2019"},{"key":"ref9","article-title":"New version of azorult stealer improves loading features, spreads alongside ransomware in new campaign","year":"2018"},{"key":"ref46","article-title":"Virustotal developer hub","year":"2019"},{"key":"ref45","article-title":"Canadian center for cyber security","year":"2019"},{"key":"ref48","author":"code","year":"2019","journal-title":"Office \/ vba"},{"key":"ref47","year":"2018","journal-title":"Contextures"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-36938-5_46"},{"key":"ref41","first-page":"168","author":"mimura","year":"2019","journal-title":"International Workshop on Security"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2017.8258483"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/THS.2018.8574202"}],"event":{"name":"2020 International Symposium on Networks, Computers and Communications (ISNCC)","location":"Montreal, QC, Canada","start":{"date-parts":[[2020,10,20]]},"end":{"date-parts":[[2020,10,22]]}},"container-title":["2020 International Symposium on Networks, Computers and Communications (ISNCC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9297148\/9297168\/09297272.pdf?arnumber=9297272","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,28]],"date-time":"2022-06-28T21:55:03Z","timestamp":1656453303000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9297272\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,20]]},"references-count":54,"URL":"https:\/\/doi.org\/10.1109\/isncc49221.2020.9297272","relation":{},"subject":[],"published":{"date-parts":[[2020,10,20]]}}}