Field QUOTE with ASCII-integer payload

OOXML_FIELD_QUOTE_ASCII_PAYLOAD

← All detection heuristics · Office

critical OOXML_FIELD_QUOTE_ASCII_PAYLOAD

What it means

A Word field QUOTE expression contains a decimal-ASCII byte sequence. The decoded payload is emitted at field-update time and is typically used to assemble shell-command text that does not appear literally in the document bytes.

Why it fires

Word's QUOTE field accepts a list of decimal byte values and emits them as text when the field is evaluated. Threat actors use this to defeat content-based filters that look for literal 'cmd'/'powershell' strings in document bytes — the dangerous string only exists after Word evaluates the field. When a SET/REF field chain references the QUOTE output from a DDE field, the resulting command runs on document open (MITRE ATT&CK T1559.002). Severity escalates to CRITICAL when the decoded payload references a known-dangerous executable (cmd, powershell, mshta, etc.); MEDIUM otherwise (form has no legitimate use case but no immediately-visible dangerous target).

Other Office heuristics

OLE_VBA_AFFINE_MSI_DOWNLOADER OLE_VBA_AUTOEXEC_FRAGMENTED_SHELL OLE_VBA_DESTRUCTIVE_WORKBOOK_SHUTDOWN OLE_VBA_BIDIRECTIONAL_MACROCOPY_REPLICATION OOXML_BRAND_LINK_MISMATCH_LURE CVE_2016_7262 POLYGLOT_OOXML_REL_COMMAND OLE_RAW_PCODE_CROSS_DOCUMENT_REPLICATION OLE_VBA_CROSS_WORKBOOK_REPLICATION OOXML_XLM_DANGEROUS_FN OFFICE_DEFAULT_PASSWORD_VBA_DROP_EXEC OFFICE_EMBEDDED_SWF EMBEDDED_OFFICE_CHILD_STATIC_TRIAGE OFFICE_EMBEDDED_MACRO_OBJECT OLE_EMBEDDED_EXE OLE_VBA_EMBEDDED_PE_DROPPER OLE_ENCRYPTED_AND_MALFORMED CVE_2017_11882_EQUATION_NATIVE_CMD_RELATED CVE_2017_11882 OLE_EQUATION_OLE10NATIVE_DOWNLOADER OLE_MTEF_NATIVE_CODE_STUB OLE_EQUATION_OLE10NATIVE_SHELLCODE OOXML_XLM_MACRO_IN_WORKSHEET OLE_XLS5_LAROUX_MACRO_VIRUS