Office heuristics

278 detection rules

← All detection heuristics

Affine-decoded remote MSI downloader critical OLE_VBA_AFFINE_MSI_DOWNLOADER
Auto-exec VBA decodes an msiexec remote-install command and passes it to an execution sink.
Auto-exec VBA fragmented Shell command critical OLE_VBA_AUTOEXEC_FRAGMENTED_SHELL
An auto-running macro reconstructs an obfuscated command and passes it to Shell.
Auto-run macro erases workbook data and shuts down Windows critical OLE_VBA_DESTRUCTIVE_WORKBOOK_SHUTDOWN
An Excel auto-open routine clears cells, saves the workbook, and shuts down or forcibly closes Windows.
Bidirectional WordBasic macro replication critical OLE_VBA_BIDIRECTIONAL_MACROCOPY_REPLICATION
An auto-running WordBasic macro copies automatic macros in both directions while saving the document.
Branded Office lure links to unrelated infrastructure critical OOXML_BRAND_LINK_MISMATCH_LURE
Receipt or account-action text impersonates a brand but targets an unrelated redirector or object store.
An Excel cell formula resolves to an advised external DDE item whose service launches an executable.
Command-bearing relationship in prefixed OOXML critical POLYGLOT_OOXML_REL_COMMAND
An OOXML ZIP appended to another document contains a decoded command relationship target.
Compiled VBA cross-document replication critical OLE_RAW_PCODE_CROSS_DOCUMENT_REPLICATION
Compiled VBA/cache bytes expose an automatic event, project-code editing, and a foreign Office target.
Cross-workbook VBA replication critical OLE_VBA_CROSS_WORKBOOK_REPLICATION
An auto-running macro exports a VBA component and imports it into another workbook.
Dangerous XLM formula APIs critical OOXML_XLM_DANGEROUS_FN
Excel 4.0 macro sheet uses formula APIs that call directly into Win32.
Default-password Office VBA download-and-run payload critical OFFICE_DEFAULT_PASSWORD_VBA_DROP_EXEC
A transparently decrypted Office package contains a VBA download, write, and execution chain.
Embedded Adobe Flash (SWF) in Office document critical OFFICE_EMBEDDED_SWF
Office document contains an embedded SWF (Flash) object.
Embedded Office document static findings critical EMBEDDED_OFFICE_CHILD_STATIC_TRIAGE
A carved embedded OLE Office document matched exploit or payload heuristics.
Embedded Office object carries macros critical OFFICE_EMBEDDED_MACRO_OBJECT
An embedded OLE/OOXML object is itself an Office file that contains a VBA macro project or an Excel 4.0 (XLM) macro sheet.
Embedded PE executable critical OLE_EMBEDDED_EXE
MZ/PE header found inside the document.
Embedded PE reassembled from base64 VBA string fragments critical OLE_VBA_EMBEDDED_PE_DROPPER
VBA carries a base64-encoded EXE split across many string variables and rebuilds it at run time (ADODB.Stream drop-and-run).
Encrypted Office package with CFB FAT corruption critical OLE_ENCRYPTED_AND_MALFORMED
Encrypted-package shape co-occurs with FAT-chain corruption — the canonical combined evasion form.
Equation Editor command stager — CVE-2017-11882 family critical CVE_2017_11882_EQUATION_NATIVE_CMD_RELATED
Equation Native stream has invalid MTEF structure and embedded command-launch bytes.
Equation Editor exploit primitive or command-stager shape.
Equation Editor object carries Ole10Native downloader shellcode critical OLE_EQUATION_OLE10NATIVE_DOWNLOADER
Equation Editor OLE object contains Ole10Native shellcode with download and process APIs.
Equation Native stream begins with native-code stub critical OLE_MTEF_NATIVE_CODE_STUB
An oversized Equation Native stream begins with executable x86 control-transfer code.
Equation Ole10Native stream contains shellcode critical OLE_EQUATION_OLE10NATIVE_SHELLCODE
An Equation 3.0 object carries executable code in a large Ole10Native stream.
Excel 4.0 macro hidden in a regular worksheet part critical OOXML_XLM_MACRO_IN_WORKSHEET
Workbook has an Auto_Open defined name and stores XLM download/exec logic inside parts declared as normal worksheets.
Excel 5 Laroux/Larou-CV macro virus critical OLE_XLS5_LAROUX_MACRO_VIRUS
Legacy Excel workbook contains Laroux/Larou-CV auto-open replication markers.
Excel XLSTART workbook persistence critical OLE_VBA_XLSTART_WORKBOOK_PERSISTENCE
An auto-running macro saves a workbook into Excel's startup directory.
Field QUOTE with ASCII-integer payload critical OOXML_FIELD_QUOTE_ASCII_PAYLOAD
A Word field QUOTE expression contains a decimal-ASCII byte sequence. The decoded payload is emitted at field-update time and is typically used to assemble shell-command text that does not appear literally in the document bytes.
Global-template macro replication critical OLE_VBA_GLOBAL_TEMPLATE_REPLICATION
An auto-running macro copies code between a document and the Global/Normal template.
Hidden macro UI with document destruction critical OLE_VBA_MACRO_UI_HIDE_DOCUMENT_DESTRUCTION
An auto-running macro hides macro controls and deletes the document body.
LOLBin reference in VBA critical OLE_VBA_LOLBIN
VBA macro references a Living-off-the-Land binary (certutil, bitsadmin, mshta).
Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUS
Workbook contains self-identifying legacy Excel formula macro virus strings.
Legacy Windows startup-file tampering critical OLE_VBA_SYSTEM_STARTUP_FILE_TAMPER
A macro opens autoexec.bat, config.sys, or winstart.bat for writing.
Legacy Word document loads a remote attached template critical OLE_WORD_REMOTE_TEMPLATE
Word's binary SttbfAssoc table points the attached template at a remote URL or UNC path.
Legacy XLM macro-virus family marker critical OLE_XLM_LEGACY_MACRO_VIRUS
Workbook contains an XLM macro sheet plus legacy macro-virus family strings.
Legacy self-replicating Word macro virus critical OLE_VBA_LEGACY_SELF_REPLICATING_MACRO_VIRUS
Auto-running VBA copies macros through Global/Normal, hooks FileSaveAs, and hides macro-management commands.
MSHTML-style external object relationship critical OFFICE_MSHTML_EXTERNAL_OBJECT
OOXML external relationship targets HTML/CAB/MHTML/HTA-style content.
Malformed OLE auto-open stager with embedded ZIP payload critical OLE_RAW_MALFORMED_AUTOOPEN_STAGER
Malformed OLE bytes contain AutoOpen, embedded ZIP/theme content, VBA project metadata, and URL/CMD/Shell staging tokens.
Malformed VBA network-execution fallback critical OLE_MALFORMED_VBA_NETWORK_EXEC_FALLBACK
Raw streams retain auto-run, object creation, Shell, and network evidence after VBA parsing fails.
Malicious DDE command critical OOXML_DDE_MALICIOUS
A DDE field instruction launches a dangerous system executable (cmd.exe, PowerShell, mshta, etc.).
PowerPoint OLE Pictures stream is malformed and carries a PE-like payload.
PowerPoint OLE numbered Table stream is malformed and carries a PE-like payload.
PowerPoint Pictures stream contains malformed shape-container material and shellcode.
Word OLE object pointers are malformed and unreferenced sectors contain decoded shellcode.
Word FIB points to a malformed DOP/string-table region with exploit payload evidence.
Word document contains a corrupted table border/colour formatting record — the CVE-2006-6456 memory-corruption shape.
Word OLE document has malformed-record exploit structure with payload in OLE slack.
Numeric-host remote template critical OOXML_NUMERIC_HOST_REMOTE_TEMPLATE
An Office remote template hides an IPv4 address as a legacy numeric hostname.
OLE MTEF Shellcode Download URL critical OLE_MTEF_SHELLCODE_DOWNLOAD_URL
OLE Equation Editor payload evidence: OLE MTEF Shellcode Download URL.
OLE UserForm Obfuscated Powershell critical OLE_USERFORM_OBFUSCATED_POWERSHELL
OLE VBA UserForm payload evidence: OLE UserForm Obfuscated Powershell.
OLE VBA Cell Dropper URL critical OLE_VBA_CELL_DROPPER_URL
OLE VBA macro behavior: OLE VBA Cell Dropper URL.
OLE VBA Getobject CLSID Powershell Runner critical OLE_VBA_GETOBJECT_CLSID_POWERSHELL_RUNNER
OLE VBA macro behavior: OLE VBA Getobject CLSID Powershell Runner.
OLE VBA Property Shellcode Loader critical OLE_VBA_PROPERTY_SHELLCODE_LOADER
OLE VBA macro behavior: OLE VBA Property Shellcode Loader.
OLE VBA Shape Alttext Payload Loader critical OLE_VBA_SHAPE_ALTTEXT_PAYLOAD_LOADER
OLE VBA macro behavior: OLE VBA Shape Alttext Payload Loader.
OLE VBA Shellcode Callback Loader critical OLE_VBA_SHELLCODE_CALLBACK_LOADER
OLE VBA macro behavior: OLE VBA Shellcode Callback Loader.
OLE VBA WScript.Shell MSHTA Shortener critical OLE_VBA_WSHELL_MSHTA_SHORTENER
Auto-exec macro launches MSHTA from a shortened URL.
OLE Xls Hidden Cell Powershell Downloader critical OLE_XLS_HIDDEN_CELL_POWERSHELL_DOWNLOADER
Excel hidden-cell PowerShell downloader decoded from workbook data.
OOXML Encrypted Exploit Carrier Shape critical OOXML_ENCRYPTED_EXPLOIT_CARRIER_SHAPE
OOXML package anomaly: OOXML Encrypted Exploit Carrier Shape.
OOXML alt-text XSLT/JScript installer critical OOXML_XSLT_ALTTEXT_SCRIPT_INSTALLER
Auto-exec VBA loads image/shape AlternativeText into MSXML and executes an embedded XSLT script installer.
OOXML autoload OLE object target is missing critical OOXML_MISSING_AUTOLOAD_OLEOBJECT
Spreadsheet declares an auto-loaded OLE object, but the referenced embedded OLE part is absent.
Obfuscated VBA Shell command with URL critical OLE_VBA_OBFUSCATED_SHELL_URL
VBA macro builds a Shell command through decoder/string functions and includes a URL.
Obfuscated XLM Auto_Open execution chain critical OLE_XLM_OBFUSCATED_AUTOEXEC_CHAIN
XLM macro sheet auto-executes an obfuscated formula/RUN chain.
Ole10Native package archive contains PowerShell downloader LNK critical OFFICE_PACKAGE_ARCHIVE_LNK_DOWNLOADER
OLE Package payload is an archive containing a Windows shortcut that launches PowerShell to download a remote payload.
Ole10Native package archive contains executable member critical OFFICE_PACKAGE_ARCHIVE_RISKY_MEMBER
OLE Package payload is an archive containing a shortcut, script, installer, or other executable-capable member.
Ole10Native package payload is a download-and-execute script critical OFFICE_PACKAGE_SCRIPT_DROPPER
OLE Package payload contains a script that hosts a shell, fetches a remote resource, and executes it.
Potential Shell call in VBA critical OLE_VBA_SHELL
VBA macro calls Shell() function.
PowerPoint binary-format RCE payload — CVE-2011-1269 / MS11-036 family critical PPT_BINARY_MEMORY_CORRUPTION_PAYLOAD
Macro-free binary PowerPoint carries a native code payload (embedded PE / process-injection shellcode).
PowerShell reference in VBA critical OLE_VBA_PS
VBA macro references PowerShell.
Property-hidden URL scheduled-task stager critical OLE_VBA_PROPERTY_URL_SCHTASKS_STAGER
VBA reconstructs URLs from OOXML properties, writes downloaded scripts, and schedules them.
Raw OLE macro text shows DNS-driven hidden Shell stager critical OLE_RAW_MACRO_DNS_SHELL_STAGER
Raw OLE streams contain AutoOpen, DNS API use, temp/AppData staging, and hidden Shell execution.
Raw OLE macro text shows self-replication or security tampering critical OLE_RAW_MACRO_SELF_REPLICATION
Raw OLE streams contain macro text with auto-run, automation, CodeModule modification, and Outlook or macro-security behavior.
Remote scrobj scriptlet execution critical OLE_VBA_SCROBJ_REMOTE_SCRIPTLET
VBA invokes scrobj.dll DllInstall with a remote .sct URL.
Secured Office document links outside its service critical OOXML_SECURED_DOCUMENT_LINK_LURE
A secured/protected-document call to action targets unrelated infrastructure.
Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
An Excel externalLinks/ddeLink entry launches cmd, PowerShell, mshta, or another dangerous executable.
URL reconstructed from XLM cell array critical OOXML_XLM_CELL_ARRAY_URL
Payload URL was reconstructed from numeric cell values across the worksheet, not present as a literal string.
URLDownloadToFile in VBA critical OLE_VBA_DOWNLOAD
VBA macro references URLDownloadToFile API.
Unreferenced OOXML part contains shellcode critical OOXML_ORPHAN_PART_SHELLCODE
A package part not referenced by any relationship carries executable shellcode.
VBA ActiveX event launches decoded Excel4 macro critical OLE_VBA_ACTIVEX_XLM_STAGER
VBA ActiveX/UserForm event decodes worksheet-cell strings and executes them through ExecuteExcel4Macro.
VBA cell-assembled Shell command critical OLE_VBA_CELL_ASSEMBLED_SHELL_COMMAND
Auto-exec VBA reconstructs a command from worksheet cells and invokes Shell.
VBA email-worm self-replication (Outlook mass-mailer) critical OLE_VBA_EMAIL_WORM_SELF_REPLICATION
VBA macro drives Outlook to mass-mail itself — creates mail items, harvests recipients, and auto-attaches the carrier.
VBA macro-virus self-replication / AV tampering critical OLE_VBA_MACRO_VIRUS_REPLICATION
VBA macro rewrites VBA project code (self-replication) and/or disables Office macro-virus protection.
VBA p-code self-replication and hosts-file tampering critical OLE_VBA_PCODE_SELF_REPLICATING_HOSTS_TAMPER
Compiled VBA/cache streams show auto-run, VBA project self-modification, and hosts-file or startup add-in persistence.
VBA reconstructs MSHTA network stager from UserForm data critical OLE_VBA_USERFORM_FRAGMENTED_MSHTA_STAGER
Auto-exec VBA combines Tag properties and hidden container strings into an MSHTA command.
VBA reconstructs embedded bytes and executes them from ProgramData critical OLE_VBA_DOMDOCUMENT_EMBEDDED_DROP_EXEC
VBA auto-exec macro rebuilds embedded bytes with MSXML2.DOMDocument, writes them with ADODB.Stream, and launches them from ProgramData.
VBA scheduled-task command stager critical OLE_VBA_TASK_SCHEDULER_CELL_STAGER
Auto-exec VBA registers an executable action through the Task Scheduler COM service.
VBA writes script and launches it through Excel DDE cmd critical OLE_VBA_DDE_CMD_SCRIPT_DROPPER
VBA writes a script-like file and launches it via Excel DDEInitiate with cmd.
VBA-created hidden XLM execution chain critical OLE_VBA_DYNAMIC_HIDDEN_XLM_EXEC
VBA creates a hidden Excel 4 macro sheet, writes formulas, and runs it.
VBA-generated ScriptControl downloader critical OLE_VBA_SCRIPTCONTROL_DOWNLOAD_EXEC
Auto-exec VBA reconstructs and runs a VBScript download/write/execute chain through ScriptControl.
WScript.Shell usage critical OLE_VBA_WSCRIPT
VBA macro uses WScript.Shell object.
Workbook data connection runs a command critical OOXML_DATA_CONNECTION_COMMAND_EXEC
xl/connections.xml defines a data connection that executes a command (xp_cmdshell / OLEDB exec).
Worksheet cell formula runs a DDE shell command critical OOXML_SPREADSHEET_DDE_FORMULA_EXEC
An Excel worksheet cell formula uses DDE syntax to launch a shell/LOLBIN command.
XLM Auto_Open environment-evasion close gate critical OLE_XLM_ENVIRONMENT_EVASION_CLOSE
XLM Auto_Open macro runs host-environment checks before showing a fake error and closing.
XLM payload reassembled from CHAR()/split formulas critical OOXML_XLM_REASSEMBLED_PAYLOAD
WinAPI names, LOLBin commands, or a payload URL were reassembled from per-character CHAR()/string-fragment concatenation inside the macrosheet formulas.
Access database masquerading as Office document high ACCESS_MASQUERADE_DROPPER
Jet/Access database uses a document extension and contains macro/dropper strings.
ActiveX control high OOXML_ACTIVEX
Document contains ActiveX controls.
An Excel record-continuation (CONTINUE) block appears with no preceding record to continue — a position abused by several Excel parser CVEs.
Single non-CONTINUE record body > 8224 bytes (BIFF8 spec maximum).
BIFF record runs past Workbook stream end high OLE_BIFF_RECORD_TRUNCATED
Record's declared body size extends past the stream's last byte.
BIFF stream ends with unclosed BOF substream high OLE_BIFF_BOF_SUBSTREAM_UNCLOSED
A BOF substream reaches the end of the Workbook stream without a matching EOF.
BIFF workbook contains a defined-name record flood high OLE_BIFF_NAME_RECORD_FLOOD
Workbook contains thousands of BIFF NAME records.
CallByName call high OLE_VBA_CALLBYNAME
VBA macro uses CallByName for dynamic method invocation.
Cell formula links to a remote executable / macro workbook high OOXML_FORMULA_REMOTE_PAYLOAD_URL
An Excel cell formula points at a remote .exe/.scr/.hta/.js or macro-enabled workbook.
Composite Moniker in RTF OLE object high RTF_COMPOSITE_MONIKER_RELATED
RTF OLE object contains Composite Moniker CLSID without nearby scriptlet payload evidence.
CreateObject call high OLE_VBA_CREATEOBJ
VBA macro calls CreateObject.
DDEAUTO field (auto-execute) high OOXML_DDE_AUTO
A DDEAUTO field instruction was found — it attempts automatic execution or update when the document is opened.
Document review/signing lure links to an external site high OOXML_REVIEW_SIGN_EXTERNAL_LINK_LURE
An OOXML review, signing, or open-document CTA has an actionable external hyperlink.
EMF rclBounds has negative width or height high OFFICE_EMF_BOUNDS_NEGATIVE
EMF header's rclBounds rectangle has right < left or bottom < top.
EMF record extends past blob end or has invalid size high OFFICE_EMF_RECORD_TRUNCATED
EMR record's size field runs past available bytes, is < 8, or is not 4-byte aligned.
Encrypted Office package with non-block-aligned cipher high OFFICE_ENCRYPTED_PACKAGE_MALFORMED
EncryptedPackage cipher body is not a multiple of 16 bytes, violating the AES block-alignment requirement in [MS-OFFCRYPTO] §2.3.4.4.
IOC-less Equation payload contains position-independent process-manipulation shellcode.
Equation Editor exploit launches a local target high OLE_MTEF_SHELLCODE_EXECUTION_TARGET
Equation exploit payload exposes a command or local executable target without a recoverable URL.
Excel 4.0 (XLM) dangerous capability functions high OLE_XLM_DANGEROUS_FN_STATIC
XLM macro sheet references two or more dangerous capability functions (CALL/EXEC/REGISTER/FWRITE/FOPEN).
Excel 4.0 (XLM) macro / Auto_Open high OLE_XLM_AUTOOPEN
OLE workbook contains an Excel 4.0 macro sheet, optionally with Auto_Open/Close.
Excel 4.0 (XLM) macro sheet high OOXML_XLM_MACROSHEET
Spreadsheet contains an xl/macrosheets/sheet*.xml part.
XLM macro sheet references a payload module (.dll/.exe/.ocx/.scr) by a relative (..\) or environment-variable (%ENV%\) path.
External OLE object relationship high OOXML_EXTERNAL_OLE_OBJECT
OOXML oleObject relationship targets an external HTTP(S) URL.
External relationship high OOXML_EXTERNAL_REL
Document references an external target (URL) in its .rels file.
Flat OPC external template high OFFICE_FLAT_OPC_EXTERNAL_TEMPLATE
A Flat OPC/XML Office document automatically retrieves a remote template.
GetObject call high OLE_VBA_GETOBJ
VBA macro calls GetObject.
Legacy Flash object embedded in Office document high OFFICE_LEGACY_SWF_OBJECT
Office document embeds a ShockwaveFlash object with an old SWF version.
Legacy WordBasic macro-virus markers high OLE_LEGACY_WORDBASIC_MACRO_VIRUS
Legacy WordBasic auto-execution markers co-occur with macro-virus family or macro-management strings.
MTEF FONT typeface field exceeds 32 bytes high OLE_MTEF_FONT_NAME_OVERLONG
FONT record's NUL-terminated typeface name is longer than the 32-byte spec maximum.
MTEF MATRIX record has implausible dimensions high OLE_MTEF_MATRIX_ROWCOUNT
MATRIX record declares rows or columns > 64.
MTEF SIZE record has implausibly large value high OLE_MTEF_SIZE_RECORD_ANOMALY
SIZE record declares an explicit point size or delta far beyond normal equation text.
OLE DIFAT chain length or pointer is invalid high OLE_HEADER_DIFAT_ANOMALY
DIFAT extension chain loops, points beyond file end, or its declared length disagrees with the first-sector field.
OLE ObjectPool in file named RTF high OLE_OBJECTPOOL_CONTAINER_DISGUISED_RTF
OLE compound document is named with an .rtf extension and contains ObjectPool storage.
OLE VBA ActiveX XLM Cell Stager high OLE_VBA_ACTIVEX_XLM_CELL_STAGER
OLE VBA macro behavior: OLE VBA ActiveX XLM Cell Stager.
OLE VBA Base64 Shell Command Stager high OLE_VBA_BASE64_SHELL_COMMAND_STAGER
OLE VBA macro behavior: OLE VBA Base64 Shell Command Stager.
OLE VBA Obfuscated URL high OLE_VBA_OBFUSCATED_URL
OLE VBA macro behavior: OLE VBA Obfuscated URL.
OLE VBA URLDownload Reversed LOLBIN high OLE_VBA_URLDOWNLOAD_REVERSED_LOLBIN
OLE VBA macro behavior: OLE VBA URLDownload Reversed LOLBIN.
OLE VBA UserForm Hidden Command Stager high OLE_VBA_USERFORM_HIDDEN_COMMAND_STAGER
OLE VBA macro behavior: OLE VBA UserForm Hidden Command Stager.
OLE XLM AutoOpen Payload Lure high OLE_XLM_AUTOOPEN_PAYLOAD_LURE
OLE Excel 4.0 macro evidence: OLE XLM AutoOpen Payload Lure.
OLE XLM Cell Array URL high OLE_XLM_CELL_ARRAY_URL
OLE Excel 4.0 macro evidence: OLE XLM Cell Array URL.
OLE XLM Encrypted Macrosheet high OLE_XLM_ENCRYPTED_MACROSHEET
OLE Excel 4.0 macro evidence: OLE XLM Encrypted Macrosheet.
OLE XLM Obfuscated Defined Name Chain high OLE_XLM_OBFUSCATED_DEFINED_NAME_CHAIN
OLE Excel 4.0 macro evidence: OLE XLM Obfuscated Defined Name Chain.
OLE XLM Obfuscated Setname Chain high OLE_XLM_OBFUSCATED_SETNAME_CHAIN
OLE Excel 4.0 macro evidence: OLE XLM Obfuscated Setname Chain.
OLE appended executable-looking payload high OLE_APPENDED_PAYLOAD
Large high-entropy bytes beyond declared streams contain shellcode or loader markers.
CFB directory red/black-tree walk visits the same DirID twice.
OLE document contains hidden remote iframe URL high OLE_HIDDEN_IFRAME_REMOTE_URL
OLE/Word document bytes contain a hidden iframe that loads an external URL.
OLE metadata lists many Excel 4.0 macro sheets high OLE_XLM_DOCPROPS_MACROSHEET_INVENTORY
OLE workbook metadata lists many MacroN sheet titles with an Excel 4.0 macro-sheet marker.
OLE raw shellcode-like payload high OLE_RAW_SHELLCODE_PAYLOAD
Malformed OLE bytes contain PEB/API-resolver shellcode evidence.
A stream's sector chain revisits a sector or follows a pointer outside the FAT.
OLE streams share a sector high OLE_FAT_CROSSLINKED
Two different streams' sector chains include the same sector.
OOXML Clickable Image Form Lure high OOXML_CLICKABLE_IMAGE_FORM_LURE
OOXML package anomaly: OOXML Clickable Image Form Lure.
OOXML Clickable Image Suspicious Host Lure high OOXML_CLICKABLE_IMAGE_SUSPICIOUS_HOST_LURE
OOXML clickable image links to suspicious landing infrastructure.
OOXML Embedded Object URL high OOXML_EMBEDDED_OBJECT_URL
OOXML package anomaly: OOXML Embedded Object URL.
OOXML External Rel userinfo Doc Lure high OOXML_EXTERNAL_REL_USERINFO_DOC_LURE
OOXML package anomaly: OOXML External Rel userinfo Doc Lure.
OOXML Link Aggregator Doc Lure high OOXML_LINK_AGGREGATOR_DOC_LURE
OOXML package anomaly: OOXML Link Aggregator Doc Lure.
OOXML XLM Formula Concat URL high OOXML_XLM_FORMULA_CONCAT_URL
OOXML Excel 4.0 macro evidence: OOXML XLM Formula Concat URL.
OOXML XLM Payload URL high OOXML_XLM_PAYLOAD_URL
OOXML Excel 4.0 macro evidence: OOXML XLM Payload URL.
OOXML XML part contains a DOCTYPE declaration high OOXML_XML_DOCTYPE_PRESENT
Any XML part inside an OOXML package contains <!DOCTYPE.
OOXML XML part declares an external entity high OOXML_XML_EXTERNAL_ENTITY
An <!ENTITY ... SYSTEM ...> or PUBLIC declaration was found in an XML part.
OOXML external relationship uses an exotic scheme high OOXML_REL_EXTERNAL_NON_HYPERLINK
External `<Relationship>` of a non-hyperlink type uses an MSDT, search-ms, MHTML, scriptlet, or javascript: scheme.
OOXML internal relationship escapes the package root high OOXML_REL_TARGET_OUTSIDE_PACKAGE
Internal-mode `<Relationship>` Target uses `..` segments that resolve above the package root.
OOXML oleObject relationship points at a non-OLE target high OOXML_REL_TYPE_TARGET_MISMATCH
Relationship typed as `oleObject` resolves to an HTML/CAB/MHT/scriptlet/HTA target.
The OPC relationship graph is supposed to be a DAG; a cycle is encoder-impossible.
Office Default Password Encrypted OOXML high OFFICE_DEFAULT_PASSWORD_ENCRYPTED_OOXML
OOXML document is encrypted with a common default password.
Office EPRINT stream contains EMF object high OLE_EPRINT_EMF_OBJECT
ObjectPool EPRINT stream contains EMF data.
OLE Package displayName is benign-looking while fullPath/defFile ends in an executable extension.
OLE Package displayName, fullPath, or defFile has an executable/script-capable extension.
Ole10Native package path contains traversal or UNC root high OFFICE_PACKAGE_PATH_TRAVERSAL
OLE Package filename contains `..\` or `\\host\` traversal sequences.
VBA builds its stage-2 download URL char-by-char from string literals + Chr()/Asc()/StrReverse() (no numeric array); URLs recovered.
Payload URL decoded from a Chr() numeric-array loader high OLE_VBA_CHR_ARRAY_DROPPER_URL
VBA builds its stage-2 download URL from a numeric array decoded with Chr() and a linear offset (XMLHTTP/ADODB.Stream dropper); URLs recovered.
Payload URL decoded from an encoded PowerShell loader high OLE_VBA_ENCODED_PS_DROPPER_URL
VBA runs a PowerShell stage-2 loader whose download URL is hidden in a numeric char-code array (XOR/+/- decoded at runtime); URLs recovered.
Payload URL decrypted from a PowerShell SecureString loader high OLE_VBA_SECURESTRING_DROPPER_URL
VBA assembles a PowerShell command from Mid(StrReverse(...)) fragments and AES-decrypts a key-encrypted ConvertTo-SecureString stage-2 WebClient downloader; download URLs recovered.
Payload URL reassembled from cmd character-index dropper high OLE_VBA_CMD_CHARINDEX_DROPPER_URL
VBA reassembles a download command via a cmd.exe character-index loop and a multi-host PowerShell downloader; payload URLs recovered.
Small embedded PowerPoint stream has sparse OffArray-style records and no normal text atoms.
PowerPoint Pictures stream and document shellcode match a CVE-2006-0022-adjacent shape.
Remote template injection high OOXML_REMOTE_TEMPLATE
Document loads its template from a remote URL (attachedTemplate / template / frame).
URL Moniker in RTF OLE object high RTF_URL_MONIKER_RELATED
RTF OLE object contains URL Moniker evidence without a confirmed remote target.
VBA saves a copy of the workbook into Application.StartupPath (XLSTART) so it auto-loads on every Excel launch.
VBA reroutes Alt+F11 (Visual Basic editor) and/or Alt+F8 (macro list) through Application.OnKey to intercept attempts to view the macro code.
VBA infects other workbooks via an OnSheetActivate copy hook high OLE_VBA_WORKBOOK_INFECTION_SPREADER
VBA installs an Application.OnSheetActivate handler that copies a macro-bearing sheet into the active workbook, infecting every workbook the user opens.
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
Compiled VBA/cache stream pairs an auto-run token WITH a shell/download/object-execution token (the combination, not either alone).
_VBA_PROJECT stream is substantive but every module-like sibling source stream is empty or absent.
Word 6/95 legacy binary with executable payload high WORD6_LEGACY_BINARY_PAYLOAD
Legacy Word binary format carries executable payload markers.
Word field-chain (SET/REF) co-located with DDE high OOXML_FIELD_SET_REF_CHAINING
Word SET/REF field variables assemble a hidden DDE command from fragments, so the literal command never appears in the document's raw bytes — a known field-chaining obfuscation.
XLM Auto_Open with dangerous formula APIs high OLE_XLM_DANGEROUS_FN
XLM auto-exec macro uses formula APIs that can run code or write files.
XLM macro uses URL shortener high OLE_XLM_URL_SHORTENER
Excel 4.0 macro sheet contains a URL-shortener target.
A <w:altChunk> wires an aFChunk relationship to an RTF/HTML part that is absent from the package.
cmd.exe reference in VBA high OLE_VBA_CMD
VBA macro references cmd.exe.
BIFF BOF declares an unknown substream type medium OLE_BIFF_SUBSTREAM_TYPE_INVALID
An Excel sub-stream declares an unknown type (not workbook-globals, sheet, chart, macro, or VB-module), which older Excel may parse with the wrong record layout.
BIFF NAME record declares an overlong name medium OLE_BIFF_NAME_RECORD_OVERLONG
NAME record's character-count (cch) field exceeds the BIFF8 limit of 255.
BIFF record graph is unusually large medium OLE_BIFF_RECORD_COUNT_EXCESSIVE
Workbook contains an unusually large number of BIFF records.
BIFF stream has unbalanced BOF/EOF substreams medium OLE_BIFF_BOF_EOF_UNBALANCED
An Excel sub-stream's begin (BOF) and end (EOF) markers are unbalanced — readers that ignore the mismatch can reach attacker-controlled parser state.
CFB header with no readable streams medium OLE_PARSE_EMPTY_STREAMS
File has a valid OLE2/CFB header but olefile exposes zero directory streams.
EMF blob header is malformed or missing signature medium OFFICE_EMF_HEADER_INVALID
First record isn't EMR_HEADER (type 1) with the documented dSignature value.
EMF declares an implausibly large number of records medium OFFICE_EMF_HUGE_RECORD_COUNT
EMF header's nRecords field exceeds 100,000.
EMF record type outside spec range medium OFFICE_EMF_RECORD_TYPE_INVALID
EMR record's type field is outside 1..123 standard or 0x4000+ vendor extension.
Embedded OLE object medium OOXML_OLE_OBJECT
Document contains an embedded OLE object.
External workbook data link medium OOXML_EXTERNAL_REL_DATALINK
Workbook references another workbook via an externalLinkPath relationship (cell / dropdown / chart-source data link).
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXEC
A legacy Word 6/95 WordBasic auto-execution marker such as AutoOpen was found.
MTEF stream version byte outside valid set medium OLE_MTEF_HEADER_ANOMALY
MTEF version byte at the start of the Equation Native stream is not 2..6.
Multiple OLE Package CLSIDs nested in one container medium OFFICE_PACKAGE_NESTED_PACKAGE
Inner payload of an OLE Package contains the OLE Package CLSID itself, or multiple Package CLSIDs in one container.
OLE Equation OLE10Native Payload Anomaly medium OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
OLE Equation Editor payload evidence: OLE Equation OLE10Native Payload Anomaly.
OLE VBA Asc Chr Shift Shell medium OLE_VBA_ASC_CHR_SHIFT_SHELL
OLE VBA macro behavior: OLE VBA Asc Chr Shift Shell.
OLE VBA Cell Constants WScript.Shell Exec medium OLE_VBA_CELL_CONSTANTS_WSHELL_EXEC
OLE VBA macro behavior: OLE VBA Cell Constants WScript.Shell Exec.
OLE VBA Getobject CLSID Dangerous medium OLE_VBA_GETOBJECT_CLSID_DANGEROUS
OLE VBA macro behavior: OLE VBA Getobject CLSID Dangerous.
OLE VBA Getobject CLSID Evasion medium OLE_VBA_GETOBJECT_CLSID_EVASION
OLE VBA macro behavior: OLE VBA Getobject CLSID Evasion.
OLE VBA Reversed DocProp Config medium OLE_VBA_REVERSED_DOCPROP_CONFIG
OLE VBA macro behavior: OLE VBA Reversed DocProp Config.
OLE VBA WMI Process Create medium OLE_VBA_WMI_PROCESS_CREATE
OLE VBA macro behavior: OLE VBA WMI Process Create.
OLE XLM AutoOpen DefinedName medium OLE_XLM_AUTOOPEN_DEFINEDNAME
OLE Excel 4.0 macro evidence: OLE XLM AutoOpen DefinedName.
OLE XLM Environment Evasion Halt medium OLE_XLM_ENVIRONMENT_EVASION_HALT
OLE Excel 4.0 macro evidence: OLE XLM Environment Evasion Halt.
OLE stream allocation kind disagrees with size medium OLE_MINISTREAM_OUT_OF_RANGE
Stream below the MiniStream cutoff is allocated in the regular FAT, or vice versa.
OLE stream size disagrees with its sector chain medium OLE_STREAM_LEN_MISMATCH
Direntry size field claims more bytes than the FAT-walked sector chain can carry.
OOXML Bogus Custom Part medium OOXML_BOGUS_CUSTOM_PART
OOXML package anomaly: OOXML Bogus Custom Part.
OOXML External Rel Free Tld medium OOXML_EXTERNAL_REL_FREE_TLD
OOXML package anomaly: OOXML External Rel Free Tld.
OOXML VBA Project Renamed medium OOXML_VBA_PROJECT_RENAMED
OOXML VBA project anomaly: OOXML VBA Project Renamed.
OOXML VBA XLM Bridge Raw medium OOXML_VBA_XLM_BRIDGE_RAW
OOXML VBA project anomaly: OOXML VBA XLM Bridge Raw.
OOXML XLM AutoOpen DefinedName medium OOXML_XLM_AUTOOPEN_DEFINEDNAME
OOXML Excel 4.0 macro evidence: OOXML XLM AutoOpen DefinedName.
OOXML XLM Binary WinAPI Strings medium OOXML_XLM_BINARY_WINAPI_STRINGS
OOXML Excel 4.0 macro evidence: OOXML XLM Binary WinAPI Strings.
OOXML XLM Disguised Relationship medium OOXML_XLM_DISGUISED_RELATIONSHIP
OOXML Excel 4.0 macro evidence: OOXML XLM Disguised Relationship.
OOXML XLSB Intl Macrosheet In XLSX medium OOXML_XLSB_INTL_MACROSHEET_IN_XLSX
OOXML package anomaly: OOXML XLSB Intl Macrosheet In XLSX.
Processing instruction with a target outside the Office allowlist (xml, mso-*).
OOXML XML part has an oversize CDATA section medium OOXML_XML_CDATA_OVERSIZE
A single CDATA section exceeds 1 MB.
OOXML XML part has excessive element nesting medium OOXML_XML_DEPTH_EXCESSIVE
Element nesting depth exceeds 256 levels.
Two different Content-Types declared for the same extension or PartName.
OOXML altChunk HTML medium OOXML_ALTCHUNK_HTML
OOXML altChunk content injection: OOXML altChunk HTML.
OOXML altChunk Internal medium OOXML_ALTCHUNK_INTERNAL
OOXML altChunk content injection: OOXML altChunk Internal.
OOXML altChunk Opaque medium OOXML_ALTCHUNK_OPAQUE
OOXML altChunk content injection: OOXML altChunk Opaque.
OOXML altChunk RTF medium OOXML_ALTCHUNK_RTF
OOXML altChunk content injection: OOXML altChunk RTF.
OOXML altChunk RTF Autoupdate PE medium OOXML_ALTCHUNK_RTF_AUTOUPDATE_PE
OOXML altChunk content injection: OOXML altChunk RTF Autoupdate PE.
OOXML altChunk Remote medium OOXML_ALTCHUNK_REMOTE
OOXML altChunk content injection: OOXML altChunk Remote.
OOXML hyperlink to URL shortener medium OOXML_URL_SHORTENER_HYPERLINK
Document contains a clickable hyperlink to a URL-shortener service.
Internal `<Relationship>` Target resolves to a ZIP entry that does not exist in the package.
>5% of parts are not reachable by walking from the root .rels through internal relationships.
OOXML relationship Id collides within one .rels medium OOXML_REL_DUPLICATE_ID
Two `<Relationship>` entries inside the same `.rels` part share an Id.
Office document is password-encrypted medium OFFICE_ENCRYPTED_PACKAGE
OLE container holds an MS-OFFCRYPTO encrypted package (EncryptedPackage + EncryptionInfo streams).
Office document signature is cryptographically invalid medium OFFICE_DOC_SIGNATURE_INVALID
A whole-document signature's CMS failed verification.
Ole10Native inner payload size exceeds remaining bytes medium OFFICE_PACKAGE_SIZE_MISMATCH
Inner `payloadSize` field declares more bytes than remain in the Ole10Native stream.
Ole10Native outer length disagrees with stream size medium OFFICE_PACKAGE_HEADER_ANOMALY
The leading 4-byte length field of an `\x01Ole10Native` stream does not equal the stream byte count.
Password-encrypted legacy PowerPoint medium OFFICE_ENCRYPTED_LEGACY_PPT
Binary PowerPoint uses PPT97 CryptoAPI encryption, hiding slide and embedded-object records.
Remote image (web beacon / tracking pixel) medium OOXML_IMAGE_BEACON
Document contains an external image relationship targeting an http(s):// URL.
Spreadsheet DDE link medium OOXML_SPREADSHEET_DDE_LINK
An Excel externalLinks/ddeLink entry was found.
Standalone OOXML relationship XML medium OOXML_STANDALONE_RELS
File is raw OOXML .rels relationship XML rather than a valid OOXML ZIP package.
VBA Signed Untrusted medium VBA_SIGNED_UNTRUSTED
VBA project has an untrusted, invalid, or suspicious signature state.
VBA __SRP_ cache stream exceeds 8 MB medium OLE_VBA_PERFORMANCE_CACHE_OVERSIZE
A VBA performance-cache (__SRP_*) stream exceeds 8 MB.
VBA digital signature is cryptographically invalid medium OLE_VBA_SIGNATURE_INVALID
The VBA project's Authenticode signature failed verification.
VBA macros present medium OLE_VBA_MACROS
Document contains VBA macro code.
VBA project in OOXML medium OOXML_VBA
Document contains vbaProject.bin — VBA macros are present.
WRI Embedded Exe medium WRI_EMBEDDED_EXE
Windows Write document evidence: WRI Embedded Exe.
WRI Embedded OLE medium WRI_EMBEDDED_OLE
Windows Write document evidence: WRI Embedded OLE.
WRI Equation Object medium WRI_EQUATION_OBJECT
Windows Write document evidence: WRI Equation Object.
WRI Header Invalid medium WRI_HEADER_INVALID
Windows Write document evidence: WRI Header Invalid.
WRI OLE Package medium WRI_OLE_PACKAGE
Windows Write document evidence: WRI OLE Package.
WRI OLE Wrapped medium WRI_OLE_WRAPPED
Windows Write document evidence: WRI OLE Wrapped.
Workbook data connection pulls from a remote source medium OOXML_DATA_CONNECTION_REMOTE_SOURCE
xl/connections.xml defines a data connection whose source is a remote http(s) URL or UNC path.
AutoExec macro low OLE_VBA_AUTOEXEC
Macro with AutoExec trigger found.
AutoNew macro low OLE_VBA_AUTONEW
Macro with AutoNew trigger found.
AutoOpen macro low OLE_VBA_AUTOOPEN
Macro with AutoOpen trigger found.
Auto_Close macro low OLE_VBA_AUTOCLOSE
Macro with Auto_Close trigger found.
Auto_Open macro low OLE_VBA_AUTO
Macro with Auto_Open trigger found.
Call-to-action shape / download button low OOXML_DOWNLOAD_SHAPE
Document drawing contains a call-to-action phrase in a shape or text box.
DDE field low OOXML_DDE
A DDE field instruction was found in the document XML. The command does not reference a known-dangerous executable.
Document_Close macro low OLE_VBA_DOCCLOSE
Macro with Document_Close trigger found.
Document_New macro low OLE_VBA_DOCNEW
Macro with Document_New trigger found.
Document_Open macro low OLE_VBA_DOCOPEN
Macro with Document_Open event handler found.
Environ() call low OLE_VBA_ENVIRON
VBA macro uses Environ() to access environment variables.
Equation Editor OLE object low OLE_EQUATION_EDITOR
Equation Editor OLE CLSID found in the document.
External hyperlinks (summary) low OOXML_EXTERNAL_HYPERLINKS
Document contains one or more external hyperlinks.
Hidden worksheet low OOXML_HIDDEN_SHEET
Excel workbook contains hidden or veryHidden worksheets.
Malformed OOXML package with recoverable local headers low OOXML_MALFORMED_ZIP_LOCAL_HEADERS
OOXML ZIP central directory is invalid, but local headers expose Office parts.
OLE dirents share an unrecognised CLSID low OLE_DIRENT_CLSID_DUPLICATE
Multiple direntries share a non-null, unrecognised CLSID (>= 4 occurrences).
Ole10Native tempPath leaks an AppData or Temp path low OFFICE_PACKAGE_TEMP_PATH_LEAK
Package's tempPath references an `AppData\` or `Temp\` folder of the author's machine.
Workbook_Open macro low OLE_VBA_WBOPEN
Macro with Workbook_Open event handler found.
AV-disinfected VBA project remnant info OLE_VBA_DISINFECTED_REMNANT
A reachable VBA project contains repeated AVP replacement comments and no substantive behavior.
Cell formula contains an embedded URL info OOXML_FORMULA_EMBEDDED_URL
An Excel cell formula contains an embedded http(s)/ftp URL.
Macro capabilities only — no corroborating evidence info MACRO_CAPABILITY_UNCORROBORATED
The macro carries risky capabilities but nothing indicates they are used maliciously; the verdict is capped below malicious.
OLE file bytes greatly exceed the sum of declared stream sizes.
Office document is digitally signed info OFFICE_DOC_SIGNED
The document/package carries a whole-document digital signature.
Office document signed with a self-signed certificate info OFFICE_DOC_SIGNATURE_SELF_SIGNED
The document signing certificate is self-signed (issuer == subject).
Orphaned AV-disinfected VBA storage info OLE_VBA_ORPHANED_DISINFECTED_REMNANT
Unreachable OLE sectors contain repeated AVP-disinfection remnants from a deleted macro project.
Remotely stored Office Script link info OOXML_OFFICE_SCRIPT_LINK
A workbook drawing object is bound to an Office Script sharing link.
URL in OOXML QR image info OOXML_QR_URL
An OOXML image contains a QR code resolving to an HTTP(S) URL.
Unsupported Office format for VBA extraction info OFFICE_FORMAT_UNSUPPORTED
olevba could not extract VBA macros from the document; VBA source extraction was skipped.
VBA Signed Trusted info VBA_SIGNED_TRUSTED
VBA project is signed by a trusted or valid certificate.
VBA macro rewrites its own project code info OLE_VBA_SELF_MODIFYING_PROJECT
VBA macro edits its own VBA project code, with no external template or workbook target.
VBA project is digitally signed info OLE_VBA_SIGNED
The VBA macro project carries an Authenticode digital signature.
VBA project signed with a self-signed certificate info OLE_VBA_SIGNATURE_SELF_SIGNED
The VBA project signing certificate is self-signed (issuer == subject).
WRI Legacy Format info WRI_LEGACY_FORMAT
Windows Write document evidence: WRI Legacy Format.