Auto-exec macro runs a Base64 cell command through WMI

OLE_VBA_CELL_WMI_PROCESS_CREATE

← All detection heuristics · Macro

critical OLE_VBA_CELL_WMI_PROCESS_CREATE

What it means

VBA decodes a command and Win32_Process moniker from worksheet cells and executes the command through WMI.

Why it fires

The detector requires an Office auto-execution entry, Base64 decoding of Range/Cells values, a decoded winmgmts:Win32_Process moniker, and a decoded network-bearing PowerShell command reaching .Create. It reports the URL and output path, records remote/local extension mismatches, and carves the decoded command for authenticated preview.

Other Macro heuristics

OLE_VBA_EMBEDDED_ARCHIVE_DROPPER OOXML_STAGED_CELL_PAYLOAD OOXML_VBA_BASE64_CELL_URL OLE_VBA_BASE64_CELL_URL