| name | analyzing-macro-malware-in-office-documents |
| description | Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation to extract the attack chain. Activates for requests involving Office macro analysis, VBA malware investigation, maldoc analysis, or document-based threat examination. . Use when working with analyzing macro malware in office documents. |
| domain | cybersecurity |
| tags | ["malware","macro","Office","VBA","document-malware"] |
| subdomain | malware-analysis |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| atlas_techniques | ["AML.T0068","AML.T0067"] |
| d3fend_techniques | ["File Metadata Consistency Validation","Application Protocol Command Analysis","Identifier Analysis","Content Format Conversion","Message Analysis"] |
| nist_csf | ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"] |
Analyzing Macro Malware In Office Documents
Overview
Cybersecurity skill for analyzing macro malware in office documents. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"analyzing macro malware in office documents"
-
"Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Exce"
-
A suspicious Office document (.doc, .docm, .xls, .xlsm, .ppt) has been flagged by email security
-
Investigating phishing campaigns that deliver weaponized Office documents
-
Extracting VBA macro code to identify the payload download URL and execution method
-
Analyzing obfuscated VBA code to understand the full attack chain
-
Determining if a document uses DDE, ActiveX, or remote template injection instead of macros
Do not use for analyzing non-macro Office threats (DDE, remote template injection); while this skill covers detection of these, specialized analysis may be needed.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Python 3.8+ with oletools installed (
pip install oletools)
- oledump.py from Didier Stevens (https://blog.didierstevens.com/programs/oledump-py/)
- Isolated analysis VM without Microsoft Office installed (prevents accidental execution)
- XLMDeobfuscator for Excel 4.0 macro analysis (pip install xlmdeobfuscator)
- LibreOffice for safe document rendering (does not execute VBA macros by default)
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}