VBA Malware Analysis – PPTX, DOCM, PPAM, XLSM | oletools, oledump, Static Analysis | Red Team & Blue Team Lab
In this hands-on malware analysis session, we perform deep static analysis on real malicious Office files — Word, Excel, PowerPoint, and PPAM add-ins — using industry-standard tools used by SOC analysts and malware researchers.
What's covered:
🔬 Static Analysis — olevba, oledump, oleid, mraptor, olebrowse
📄 DOCM Analysis — extracting & decoding VBA macros step by step
📊 XLSM / XLS Analysis — hidden sheets, encoded payloads, stream analysis
📽️ PPTX Analysis — unzipping, relationship files, embedded CMD & EXE detection
📎 PPAM Analysis — PowerPoint add-in malware investigation
🔐 Base64 & Hex Decoding — deobfuscating encoded payloads
🐍 Python Scripts — hd.py, reverse_string.py, ascii_value.py, unhidden.py
🧰 Tools — pestudio, hex editor, oledump, pecheck, base64dump
All samples used are from public malware repositories for educational research only. Tested in isolated lab environments.
📂 Notes, Scripts & Malware Samples — GitHub:
👉 https://github.com/manikandantn68/VBA...
Author: Manikandan
Contact: 9787091093
🔔 Subscribe for more malware analysis & cybersecurity research
👍 Like if this helped your learning
💬 Drop your questions in the comments
Hashtags
#malwareanalysis #vbamalware #officemalware #excelmalware #wordmalware #pptxmalware #ppammalware #xlsmmalware #docmmalware #macromalware #officemacro #vbamacro #excelmacro #oletools #olevba #oledump #mraptor #oleid #olebrowse #pestudio #hexeditor #base64decode #deobfuscation #staticanalysis #dynamicanalysis #malwarelab #malwaresample #malwareresearch #malwaretutorial #malwarebehavior #threatanalysis #threathunting #threatintelligence #ioc #indicatorsofcompromise #reverseengineering #binaryanalysis #codeanalysis #forensics #digitalforensics #malwarereversing #sandboxanalysis #joesandbox #hybridanalysis #filescan #vmray #triagesandbox #cybersecurity #ethicalhacking #redteam #blueteam #offensivesecurity #defensivesecurity #infosec #informationsecurity #securityresearch #securitytools #pentesting #penetrationtesting #socanalyst #incidentresponse #siem #osint #vba #vbatutorial #vbacode #vbascript #vbasecurity #vbaanalysis #vbaforbeginners #learnvba #excelvba #excelanalysis #excelforensics #excelmalwareanalysis #wordforensics #pptforensics #pptxanalysis #ppamanalysis #xlsmanalysis #docmanalysis #officeforensics #officesecurity #microsoftofficesecurity #windowssecurity #windowsinternals #powershell #powershelllogging #amsibypass #amsi #defenseevasion