[Custom #YARA ] #XLS #macro based #malware downloader using URLDownloadToFileA
Received numbers of sample submission of invoice themed XLS which are not getting detected on VT [https://virustotal.com] properly using any reputed Anti Virus engine. There is nothing abnormal happening except it is showing following screen when opened. Pretty unusual - huh ! So, after finding few sample which is