XOR-decoded script-launch network configuration

OLE_SLACK_XOR_SCRIPT_CONFIG

← All detection heuristics · Office / OLE

high OLE_SLACK_XOR_SCRIPT_CONFIG

What it means

Unallocated OLE bytes decode to a CScript command, JavaScript filename, and multiple URLs.

Why it fires

This rule handles exploit-era OLE documents whose XOR-hidden region contains a launch configuration rather than a complete script. Candidate keys must reveal the exact CScript /nologo command form, a JavaScript filename, at least two syntactically valid absolute URLs, and a mostly textual decoded region. The URLs retain their XOR provenance and the decoded configuration is carved for authenticated review.

Other Office / OLE heuristics

OLE_VBA_SCHTASKS_SCRIPT_PERSISTENCE OLE_VBA_UNC_EXECUTABLE_LAUNCH OLE_SLACK_XOR_SCRIPT_BACKDOOR OLE_VBA_EMITTED_SCRIPT OLE_SLACK_XOR_SCRIPT OLE_VBA_BASE64_NETWORK_IOC OLE_EICAR_DISPLAY_TEST OLE_BIFF_MAILTO_HYPERLINK OLE_BIFF_HLINK_NETWORK_URI OLE_BIFF_EXTERNAL_WORKBOOK_URI OLE_METADATA_UNC_PATH OLE_WORD_KGWEBURL