| name | analyzing-excel-4-macro-malware |
| description | Analyzes legacy Excel 4.0 (XLM) macro malware by parsing extracted macro-sheet formulas for auto-executing names, obfuscation (FORMULA.FILL, CHAR concatenation), and download or execution primitives (EXEC, CALL, REGISTER). Activates for requests to analyze XLM macros, examine Excel 4.0 macro sheets, or deobfuscate legacy spreadsheet macros. |
| domain | cybersecurity |
| subdomain | malware-analysis |
| tags | ["malware-analysis","xlm","excel4","macros","document-malware"] |
| version | 1.0.0 |
| author | analyst-ai-pack |
| license | Apache-2.0 |
| mitre_attack | ["T1059.005","T1204.002","T1027"] |
| d3fend | ["D3-FCR","D3-DA"] |
| references | ["MITRE ATT&CK T1059.005 Visual Basic / macros — https://attack.mitre.org/techniques/T1059/005/","Microsoft Excel 4.0 macro functions reference — https://learn.microsoft.com/office/"] |
Analyzing Excel 4.0 Macro Malware
When to Use
- You have an extracted Excel 4.0 (XLM) macro sheet (e.g., from a
.xls/.xlsm dumped with
oletools/XLMMacroDeobfuscator) and need to find auto-run cells and execution primitives.
- You are triaging maldocs that hide logic in legacy macro sheets rather than VBA.
Do not use Excel to open the document to "see" the macro — opening triggers the auto-run
cells. Work from the extracted formula text statically.
Prerequisites
- The extracted XLM formula text (cell address → formula). Optional:
oletools to extract it.
Safety & Handling
- Never open the workbook in Excel; analyze the extracted formulas inertly. Defang URLs.
Workflow
Step 1: Find auto-executing entry points
python scripts/analyst.py analyze macros.txt
Flags defined-name triggers (Auto_Open, Auto_Close) and the cells they point to, plus
=HALT()/=RETURN() flow markers.
Step 2: Identify execution and download primitives
Detects EXEC(, CALL(, REGISTER( (Win32 imports), and URLDownload-style CALL patterns that
fetch and run a payload.
Step 3: Unwind obfuscation
Surfaces CHAR()/& string-building, FORMULA.FILL/FORMULA self-writing, and base/MID
slicing used to hide strings; reconstructs concatenated literals where possible.
Step 4: Extract IOCs
Pull URLs/paths and defang them; record the execution method (regsvr32, rundll32, mshta).
Validation
- Auto-run entry cells are identified, not just the presence of macros.
- Execution primitives (EXEC/CALL/REGISTER) are reported with their arguments.
- Reconstructed strings and URLs are defanged.
Pitfalls
- Heavily obfuscated sheets that self-write cells at runtime — static reconstruction is partial.
- Macro sheets hidden as
Very Hidden that simple viewers miss.
- Confusing benign legacy spreadsheets that legitimately use XLM.
References