<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Excel &#8211; Cerbero Blog</title>
	<atom:link href="https://blog.cerbero.io/tag/excel/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.cerbero.io</link>
	<description></description>
	<lastBuildDate>Wed, 04 Oct 2023 06:15:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://blog.cerbero.io/wp-content/uploads/2023/09/cropped-pro_icon_512-32x32.png</url>
	<title>Excel &#8211; Cerbero Blog</title>
	<link>https://blog.cerbero.io</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">184292133</site>	<item>
		<title>ActiveMime Format Package</title>
		<link>https://blog.cerbero.io/activemime-format-package/</link>
					<comments>https://blog.cerbero.io/activemime-format-package/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Wed, 04 Oct 2023 06:15:04 +0000</pubDate>
				<category><![CDATA[Package]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[VBA]]></category>
		<category><![CDATA[Word]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=2810</guid>

					<description><![CDATA[We have added support for the Microsoft Office ActiveMime format. This format can be used to encapsulate Office documents and hide their contents during analysis. You can download the package from Cerbero Store.]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/activemime-format-package/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2810</post-id>	</item>
		<item>
		<title>Video: Blitz XLS Malware Payload Extraction</title>
		<link>https://blog.cerbero.io/video-blitz-xls-malware-payload-extraction/</link>
					<comments>https://blog.cerbero.io/video-blitz-xls-malware-payload-extraction/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Tue, 02 Aug 2022 20:02:08 +0000</pubDate>
				<category><![CDATA[Video]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Payload]]></category>
		<category><![CDATA[VBA]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=2457</guid>

					<description><![CDATA[The malware sample analyzed in this video uses VBA code to extract a payload contained in Excel spreadsheet cells. SHA256: F00252AB17546CD922B9BDA75942BEBFED4F6CDA4AE3E02DC390B40599CE1740 The following is the Python code which mimics the VBA extraction code. from Pro.SiliconSpreadsheet import * from Pro.UI import proContext v = proContext().getCurrentAnalysisView() if v.isValid(): view = SiliconSpreadsheetWorkspaceView(v) ws = view.getSpreadsheetWorkspace() sheet = ws.sheetFromName(&#34;Final &#8230; <a href="https://blog.cerbero.io/video-blitz-xls-malware-payload-extraction/" class="more-link">Continue reading<span class="screen-reader-text"> "Video: Blitz XLS Malware Payload Extraction"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/video-blitz-xls-malware-payload-extraction/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2457</post-id>	</item>
		<item>
		<title>Obfuscated XLSB Malware Analysis</title>
		<link>https://blog.cerbero.io/obfuscated-xlsb-malware-analysis/</link>
					<comments>https://blog.cerbero.io/obfuscated-xlsb-malware-analysis/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Mon, 18 Oct 2021 11:59:49 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Suite Advanced]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[XLSB]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=2257</guid>

					<description><![CDATA[This analysis was originally posted as a thread on Twitter. SHA256: B17FA8AD0F315C1C6E28BAFC5A97969728402510E2D7DC31A7960BD48DE3FCB6 By previewing the spreadsheet in Cerbero Suite, we can see that the macros are obfuscated. An obfuscated formula looks like this: =ATAN(83483899833434.0)=ATAN(9.34889399761e+16)=ATAN(234889343300.0)=FORMULA.ARRAY(&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT24&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT27&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT29&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT30&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT31&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT33&#38;&#039;erj74^#MNDKJ3OODL _ WEKJKJERKE &#039;!AT34&#38;&#039;erj74^#MNDKJ3OODL &#8230; <a href="https://blog.cerbero.io/obfuscated-xlsb-malware-analysis/" class="more-link">Continue reading<span class="screen-reader-text"> "Obfuscated XLSB Malware Analysis"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/obfuscated-xlsb-malware-analysis/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2257</post-id>	</item>
		<item>
		<title>Video: 20-Seconds Excel Malware Analysis</title>
		<link>https://blog.cerbero.io/video-20-seconds-excel-malware-analysis/</link>
					<comments>https://blog.cerbero.io/video-20-seconds-excel-malware-analysis/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Mon, 04 Oct 2021 12:30:03 +0000</pubDate>
				<category><![CDATA[Video]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[MSCrypto]]></category>
		<guid isPermaLink="false">https://blog.cerbero.io/?p=2228</guid>

					<description><![CDATA[This sample is encrypted and contains bogus code. SHA256: 5B630BA4CB34C23C897084259AD3A00BF31A1E03B080AE7DE5D58B5E0F1EBF08 Source: InQuest. In many cases following the code flow of Excel malware is not necessary: using the formula view and our Silicon Excel Emulator is often enough.]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/video-20-seconds-excel-malware-analysis/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2228</post-id>	</item>
		<item>
		<title>Video: 1.5-Minutes QakBot Excel Malware Analysis (2nd sample)</title>
		<link>https://blog.cerbero.io/video-1-5-minutes-qakbot-excel-malware-analysis-2nd-sample/</link>
					<comments>https://blog.cerbero.io/video-1-5-minutes-qakbot-excel-malware-analysis-2nd-sample/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Wed, 10 Mar 2021 09:00:04 +0000</pubDate>
				<category><![CDATA[Video]]></category>
		<category><![CDATA[Emulator]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[XLS]]></category>
		<guid isPermaLink="false">https://cerbero-blog.com/?p=1973</guid>

					<description><![CDATA[The script extends the Silicon Excel Emulator by implementing th &#8220;FORMULA&#8221; function: from Pro.SiliconSpreadsheet import * from Pro.UI import proContext class EmulatorHelper(SiliconExcelEmulatorHelper): def __init__(self): super(EmulatorHelper, self).__init__() def evaluateFunction(self, emu, ctx, opts, depth, e): function_name = e.toString() if function_name == "FORMULA": if emu.expectedArguments(e, 2, 2): ve = emu.argToValue(ctx, opts, depth, e, 0) v = emu.valueToSpreadsheetValue(ve) idxstr &#8230; <a href="https://blog.cerbero.io/video-1-5-minutes-qakbot-excel-malware-analysis-2nd-sample/" class="more-link">Continue reading<span class="screen-reader-text"> "Video: 1.5-Minutes QakBot Excel Malware Analysis (2nd sample)"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/video-1-5-minutes-qakbot-excel-malware-analysis-2nd-sample/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1973</post-id>	</item>
		<item>
		<title>Video: 2-Minutes QakBot Excel Malware Analysis</title>
		<link>https://blog.cerbero.io/video-2-minutes-qakbot-excel-malware-analysis/</link>
					<comments>https://blog.cerbero.io/video-2-minutes-qakbot-excel-malware-analysis/#respond</comments>
		
		<dc:creator><![CDATA[Erik Pistelli]]></dc:creator>
		<pubDate>Tue, 09 Mar 2021 13:38:38 +0000</pubDate>
				<category><![CDATA[Video]]></category>
		<category><![CDATA[Emulator]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[XLS]]></category>
		<guid isPermaLink="false">https://cerbero-blog.com/?p=1971</guid>

					<description><![CDATA[The script extends the Silicon Excel Emulator by implementing the &#8220;NOW&#8221; and &#8220;FORMULA.FILL&#8221; functions: from Pro.SiliconSpreadsheet import * from Pro.UI import proContext class EmulatorHelper(SiliconExcelEmulatorHelper): def __init__(self): super(EmulatorHelper, self).__init__() def evaluateFunction(self, emu, ctx, opts, depth, e): function_name = e.toString() if function_name == "FORMULA.FILL": if emu.expectedArguments(e, 2, 2): ve = emu.argToValue(ctx, opts, depth, e, 0) v = &#8230; <a href="https://blog.cerbero.io/video-2-minutes-qakbot-excel-malware-analysis/" class="more-link">Continue reading<span class="screen-reader-text"> "Video: 2-Minutes QakBot Excel Malware Analysis"</span></a>]]></description>
		
					<wfw:commentRss>https://blog.cerbero.io/video-2-minutes-qakbot-excel-malware-analysis/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1971</post-id>	</item>
	</channel>
</rss>
