Office Document Malware Analysis: VBA, P-Code, DDE, and Template Injection
Static decoding of macros, embedded objects, and external loaders from .doc, .docx, .xls, .xlsx, .rtf, and OneNote in one upload

Automatic multi-layer malware analysis for security teams
Attackers stack Base64, XOR, compression, and string tricks to burn your time.
KlaroSkope peels back every layer automatically. Paste a sample, get the payload and detection rules.
One free analysis. No signup needed.
Scripts, PDFs, Office documents, images, extensions. Every analysis delivers actionable intelligence
130+ decoding techniques handle Base64, XOR, GZIP, PowerShell, esoteric JavaScript (JSFuck, JJEncode, AAEncode), and more. Recursive decoding through 20+ layers.
12 techniques: LSB encoding, EXIF injection, PNG chunk abuse, IDAT payloads, polyglot files, EOF appended data, alpha channel encoding. Extracted payloads auto-fed to deobfuscation.
Chrome (.crx) and Firefox (.xpi) analysis. V3 manifest parsing, permission risk scoring, JS deobfuscation, and stego extraction from extension assets.
Structure analysis, JavaScript extraction, embedded file detection, form field inspection, phishing kit attribution, and risk verdicts. Embedded images auto-scanned for steganography.
VBA macro extraction, OLE2 and OOXML parsing, embedded object detection, and payload analysis. Supports macro-enabled formats (.docm, .xlsm, .pptm), templates, and add-ins.
URLs, IPs, domains, file paths, registry keys, hashes. Pulled automatically from decoded output across all analysis vectors.
Behavioral mapping to MITRE ATT&CK techniques. Know what the script was trying to do, not just what it contained.
Detection rule templates from decoded content. YARA for file/memory, Sigma for SIEM (Splunk, Elastic, Sentinel). Review and deploy.
Inline resolution pills show exactly what each decoder changed and where. Four rendering modes from deep resolver chains to payload-only views.
Paste scripts, upload images with hidden payloads, drop browser extensions, submit Office documents, or submit suspicious PDFs.
Script deobfuscation, steganography extraction, PDF threat analysis, Office macro analysis, extension forensics, IOC extraction, MITRE mapping. All automatic.
Export rules, grab IOCs, file the report. Back to threat hunting.
LLMs are powerful, but multi-layer deobfuscation breaks their accuracy model
Even 95% per-layer accuracy sounds great until you stack 21 layers. Deflate, Base64, char codes, XOR with rolling key. The more layers, the worse it gets.
Stacked LLM callsCompounding errors, compounding costs
KlaroSkopeConsistent results, first layer to last
Errors compound exponentially for LLMs. Deterministic execution stays consistent regardless of depth.
Read the full analysisYour time is better spent on threats, not unpacking scripts.
Try It FreeDeep dives into script obfuscation techniques and how to defeat them
No signup. No credit card. Paste something ugly and watch it decode.
Try It Free