剖析Office宏恶意代码

原名:analyzing-macro-malware-in-office-documents

分析嵌入在 Microsoft Office 文档中的恶意 VBA 宏。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-18
TRACE 评分
3.8 / 5

内容概览

- A suspicious Office document (.doc, .docm, .xls, .xlsm, .ppt) has been flagged by email security - Investigating phishing campaigns that deliver weaponized Office documents - Extracting VBA macro code to identify the payload download URL and execution method - Analyzing obfuscated VBA code to understand the full attack chain - Determining if a document uses DDE, ActiveX, or remote template injection instead of macros Do not use for analyzing non-macro Office threats (DDE, remote template injection); while this skill covers detection of these, specialized analysis may be needed. - Python 3.8+ with oletools installed (pip install oletools) - oledump.py from Didier Stevens (https://blog.didierstevens.com/programs/oledump-py/) - Isolated analysis VM without Microsoft Office installed (prevents accidental execution) - XLMDeobfuscator for Excel 4.0 macro analysis (pip install xlmdeobfuscator…

查看 SKILL 详情