剖析Office宏恶意代码
原名:analyzing-macro-malware-in-office-documents
分析嵌入在 Microsoft Office 文档中的恶意 VBA 宏。
- 分类
- 开发提效
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-18
- TRACE 评分
- 3.8 / 5
内容概览
- A suspicious Office document (.doc, .docm, .xls, .xlsm, .ppt) has been flagged by email security - Investigating phishing campaigns that deliver weaponized Office documents - Extracting VBA macro code to identify the payload download URL and execution method - Analyzing obfuscated VBA code to understand the full attack chain - Determining if a document uses DDE, ActiveX, or remote template injection instead of macros Do not use for analyzing non-macro Office threats (DDE, remote template injection); while this skill covers detection of these, specialized analysis may be needed. - Python 3.8+ with oletools installed (pip install oletools) - oledump.py from Didier Stevens (https://blog.didierstevens.com/programs/oledump-py/) - Isolated analysis VM without Microsoft Office installed (prevents accidental execution) - XLMDeobfuscator for Excel 4.0 macro analysis (pip install xlmdeobfuscator…