Macro workbook stores payload URL as Base64 cell text

OOXML_VBA_BASE64_CELL_URL

← All detection heuristics · Macro

high OOXML_VBA_BASE64_CELL_URL

What it means

A VBA-bearing workbook cell decodes from Base64 to an HTTP(S) payload URL.

Why it fires

The URL is accepted only after successful Base64 decoding and URL validation; this recovers indirect cell-staged C2/download configuration.

Other Macro heuristics

OLE_VBA_CELL_WMI_PROCESS_CREATE OLE_VBA_EMBEDDED_ARCHIVE_DROPPER OOXML_STAGED_CELL_PAYLOAD OLE_VBA_BASE64_CELL_URL