Auto-exec VBA installs script persistence with schtasks
critical
OLE_VBA_SCHTASKS_SCRIPT_PERSISTENCE
An auto-running macro writes a script and creates a scheduled task for it.
Auto-executing VBA launches an executable UNC path through Shell, Run, or CreateProcess.
An XOR-hidden script performs network retrieval, host fingerprinting, remote command evaluation, and result posting.
Constant VBA Print/Write statements reconstruct a child script.
Unallocated OLE bytes decode with a single-byte XOR key to validated script content.
Unallocated OLE bytes decode to a CScript command, JavaScript filename, and multiple URLs.
VBA Base64 literals decode to network locations.
An auto-run VBA macro only reconstructs and displays the standard EICAR antivirus test string.
A legacy Excel HLINK record contains a mailto target.
A legacy Excel HLINK URL-Moniker contains an HTTP, HTTPS, or FTP target.
A legacy Excel SUPBOOK record references an HTTP, HTTPS, or FTP workbook location.
Legacy document or printer metadata contains UNC paths.
A Word 0Table/1Table KGWebUrl property contains an HTTP, HTTPS, or FTP target.