Experts analyzed an Office document containing a payload that is able to bypass Microsoft AppLocker and Anti-Malware Scan Interface (AMSI) Cybaze-Yoroi ZLAB team encountered an interesting Office document with some peculiarities. The payload includes techniques suitable to bypass modern Microsoft security mechanisms. Unlike most malwares, this one uses a different technique to automatically start the macro code at the document opening time. This technique, include part of the payload into a Word Label object or cells, allows to hide more code directly into the attack vector.”]
Source: https://securityaffairs.co/wordpress/82634/hacking/applocker-amsi-evasion.html

