本文へ移動
cccskills
無料GitHub で公開

analyzing-excel-4-macro-malware

Analyzes legacy Excel 4.0 (XLM) macro malware by parsing extracted macro-sheet formulas for auto-executing names, obfuscation (FORMULA.FILL, CHAR concatenation), and download or execution primitives (EXEC, CALL, REGISTER). Activates for requests to analyze XLM macros, examine Excel 4.0 macro sheets, or deobfuscate legacy spreadsheet macros.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md2.9 KB
  • LICENSE340 B
  • references/api-reference.md1.4 KB
  • scripts/analyst.py2.7 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Analyzing Excel 4.0 Macro Malware

When to Use

  • You have an extracted Excel 4.0 (XLM) macro sheet (e.g., from a .xls/.xlsm dumped with oletools/XLMMacroDeobfuscator) and need to find auto-run cells and execution primitives.
  • You are triaging maldocs that hide logic in legacy macro sheets rather than VBA.

Do not use Excel to open the document to "see" the macro — opening triggers the auto-run cells. Work from the extracted formula text statically.

Prerequisites

  • The extracted XLM formula text (cell address → formula). Optional: oletools to extract it.

Safety & Handling

  • Never open the workbook in Excel; analyze the extracted formulas inertly. Defang URLs.

Workflow

Step 1: Find auto-executing entry points

python scripts/analyst.py analyze macros.txt

Flags defined-name triggers (Auto_Open, Auto_Close) and the cells they point to, plus =HALT()/=RETURN() flow markers.

Step 2: Identify execution and download primitives

Detects EXEC(, CALL(, REGISTER( (Win32 imports), and URLDownload-style CALL patterns that fetch and run a payload.

Step 3: Unwind obfuscation

Surfaces CHAR()/& string-building, FORMULA.FILL/FORMULA self-writing, and base/MID slicing used to hide strings; reconstructs concatenated literals where possible.

Step 4: Extract IOCs

Pull URLs/paths and defang them; record the execution method (regsvr32, rundll32, mshta).

Validation

  • Auto-run entry cells are identified, not just the presence of macros.
  • Execution primitives (EXEC/CALL/REGISTER) are reported with their arguments.
  • Reconstructed strings and URLs are defanged.

Pitfalls

  • Heavily obfuscated sheets that self-write cells at runtime — static reconstruction is partial.
  • Macro sheets hidden as Very Hidden that simple viewers miss.
  • Confusing benign legacy spreadsheets that legitimately use XLM.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する