drop docm xlsm pptm or legacy doc xls ppt · extract vba macro code · identify suspicious patterns · surface autorun macros shell commands and obfuscation · runs locally
office files
drop macro-enabled office files
or click
MS-OVBA decompress via decompressVba() · CFB from vbaProject.bin
drop docm · xlsm · pptm · doc · xls · ppt with macros