rule exploit_ole_package_manager { meta: author = "David Cannings" description = "Office Package Manager, may load unsafe content including scripts" ref = "http://quicksand.io/" strings: // Parsers will open files without the full 'rtf' $header_rtf = "{\\rt" nocase $header_office = { D0 CF 11 E0 } $header_xml = "