URL reconstructed from XLM cell array

OOXML_XLM_CELL_ARRAY_URL

← All detection heuristics · Office

critical OOXML_XLM_CELL_ARRAY_URL

What it means

Payload URL was reconstructed from numeric cell values across the worksheet, not present as a literal string.

Why it fires

XLM downloaders evade literal-bytes URL extraction by storing each character of the URL — or of an embedded HTA that contains the URL — as the numeric value of an individual cell. The macrosheet's formulas read the cells via CHAR()/&-concat and build the URL only at execution time, so the string is never contiguous in the workbook bytes. URLs surfaced here were recovered by walking the BIFF12 record stream of every worksheet and macrosheet part.

Other Office heuristics

OLE_VBA_AFFINE_MSI_DOWNLOADER OLE_VBA_AUTOEXEC_FRAGMENTED_SHELL OLE_VBA_DESTRUCTIVE_WORKBOOK_SHUTDOWN OLE_VBA_BIDIRECTIONAL_MACROCOPY_REPLICATION OOXML_BRAND_LINK_MISMATCH_LURE CVE_2016_7262 POLYGLOT_OOXML_REL_COMMAND OLE_RAW_PCODE_CROSS_DOCUMENT_REPLICATION OLE_VBA_CROSS_WORKBOOK_REPLICATION OOXML_XLM_DANGEROUS_FN OFFICE_DEFAULT_PASSWORD_VBA_DROP_EXEC OFFICE_EMBEDDED_SWF EMBEDDED_OFFICE_CHILD_STATIC_TRIAGE OFFICE_EMBEDDED_MACRO_OBJECT OLE_EMBEDDED_EXE OLE_VBA_EMBEDDED_PE_DROPPER OLE_ENCRYPTED_AND_MALFORMED CVE_2017_11882_EQUATION_NATIVE_CMD_RELATED CVE_2017_11882 OLE_EQUATION_OLE10NATIVE_DOWNLOADER OLE_MTEF_NATIVE_CODE_STUB OLE_EQUATION_OLE10NATIVE_SHELLCODE OOXML_XLM_MACRO_IN_WORKSHEET OLE_XLS5_LAROUX_MACRO_VIRUS