Auto-run macro launches an executable from a network share

OLE_VBA_UNC_EXECUTABLE_LAUNCH

← All detection heuristics · Office / OLE

critical OLE_VBA_UNC_EXECUTABLE_LAUNCH

What it means

Auto-executing VBA launches an executable UNC path through Shell, Run, or CreateProcess.

Why it fires

The macro combines an automatic document event with a direct process-launch sink whose target is an executable on an SMB share. This is an actionable execution chain rather than inactive metadata; the target is published as an smb:// IOC for network pivoting.

Other Office / OLE heuristics

OLE_VBA_SCHTASKS_SCRIPT_PERSISTENCE OLE_SLACK_XOR_SCRIPT_BACKDOOR OLE_VBA_EMITTED_SCRIPT OLE_SLACK_XOR_SCRIPT OLE_SLACK_XOR_SCRIPT_CONFIG OLE_VBA_BASE64_NETWORK_IOC OLE_EICAR_DISPLAY_TEST OLE_BIFF_MAILTO_HYPERLINK OLE_BIFF_HLINK_NETWORK_URI OLE_BIFF_EXTERNAL_WORKBOOK_URI OLE_METADATA_UNC_PATH OLE_WORD_KGWEBURL