VBA downloader reads URL from worksheet cell

OOXML_VBA_DYNAMIC_CELL_URL_SOURCE

← All detection heuristics · Office Macros

high OOXML_VBA_DYNAMIC_CELL_URL_SOURCE

What it means

OOXML VBA reads a worksheet cell as the URL for a download API, but the stored cell does not contain an extractable URI.

Why it fires

The macro has download behavior and the URL source is a worksheet cell rather than a literal string. If that cell is blank or contains non-URL text in the stored workbook, there is no external URI to list as an IOC. This finding explains the dynamic source so analysts know the absence of an extracted URL is due to workbook state, not because the downloader path was missed.

Other Office Macros heuristics

OLE_VBA_XOR_DECODED_SHELL OLE_VBA_DOCUMENT_BODY_DROP_EXEC OLE_VBA_SPLIT_KEYWORD_OBFUSCATION OLE_VBA_AUTOEXEC_NORMAL_TEMPLATE_VIRUS OLE_VBA_OBFUSCATED_AUTOEXEC_LOADER OLE_RAW_MACRO_NATIVE_MEMORY_CALLBACK_LOADER OOXML_VBA_CELL_URL_DROPPER OLE_VBA_REACHABLE_HTTP_DROP_EXEC OLE_VBA_HTTP_DROP_EXEC OLE_VBA_HTTP_RESPONSE_COMMAND_EXEC OLE_VBA_CELL_GETOBJECT_EXEC OLE_VBA_XLM_CALL_INJECTION OLE_VBA_NATIVE_MEMORY_CALLBACK_LOADER OLE_VBA_BITSTRANSFER_DROPPER OLE_VBA_USERFORM_CMD_DROPPER OOXML_VBA_DEFINED_NAME_NETWORK_CONSUMED OLE_VBA_HOSTS_FILE_HIJACK OLE_VBA_KEYLOGGER_SPYWARE OOXML_VBA_CELL_IMAGE_SOURCE OLE_VBA_BARE_IPV4_LITERAL