skilly. Buy ad slot
All skills
Community / AGENT SKILL

analyzing-excel-4-macro-malware

meltedinhex/analyst-ai-pack
0 installs 22 GitHub stars
0

Analyzes legacy Excel 4.0 (XLM) macro malware by parsing extracted macro-sheet formulas for auto-executing names, obfuscation (FORMULA.FILL, CHAR concatenation), and download or execution primitives (EXEC, CALL, REGISTER). Activates for requests to analyze XLM macros, examine Excel 4.0 macro sheets, or deobfuscate legacy spreadsheet macros.

BEFORE YOU INSTALL

Understand the trade-offs.

SECURITY REVIEW

Not yet assessed

Review the original instructions and requested permissions before installing.

No security review is available for this catalog entry yet.

SKILL QUALITY

Not yet assessed

How clearly the skill guides your agent, how complete its workflow is, and how you can check the outcome.

No quality assessment is available for this catalog entry yet.

The full skill.

Original instructions from the publisher’s SKILL.md

# Analyzing Excel 4.0 Macro Malware

## When to Use

- You have an extracted Excel 4.0 (XLM) macro sheet (e.g., from a `.xls`/`.xlsm` dumped with
  oletools/XLMMacroDeobfuscator) and need to find auto-run cells and execution primitives.
- You are triaging maldocs that hide logic in legacy macro sheets rather than VBA.

**Do not use** Excel to open the document to "see" the macro — opening triggers the auto-run
cells. Work from the extracted formula text statically.

## Prerequisites

- The extracted XLM formula text (cell address → formula). Optional: `oletools` to extract it.

## Safety & Handling

- Never open the workbook in Excel; analyze the extracted formulas inertly. Defang URLs.

## Workflow

### Step 1: Find auto-executing entry points

```bash
python scripts/analyst.py analyze macros.txt
```

Flags defined-name triggers (`Auto_Open`, `Auto_Close`) and the cells they point to, plus
`=HALT()`/`=RETURN()` flow markers.

### Step 2: Identify execution and download primitives

Detects `EXEC(`, `CALL(`, `REGISTER(` (Win32 imports), and URLDownload-style `CALL` patterns that
fetch and run a payload.

### Step 3: Unwind obfuscation

Surfaces `CHAR()`/`&` string-building, `FORMULA.FILL`/`FORMULA` self-writing, and base/`MID`
slicing used to hide strings; reconstructs concatenated literals where possible.

### Step 4: Extract IOCs

Pull URLs/paths and defang them; record the execution method (regsvr32, rundll32, mshta).

## Validation

- Auto-run entry cells are identified, not just the presence of macros.
- Execution primitives (EXEC/CALL/REGISTER) are reported with their arguments.
- Reconstructed strings and URLs are defanged.

## Pitfalls

- Heavily obfuscated sheets that self-write cells at runtime — static reconstruction is partial.
- Macro sheets hidden as `Very Hidden` that simple viewers miss.
- Confusing benign legacy spreadsheets that legitimately use XLM.

## References

- See [`references/api-reference.md`](references/api-reference.md) for the analyzer.
- ATT&CK T1059.005 and the Excel 4.0 macro reference (linked in frontmatter).