How to block Excel files which contain Excel 4.0 Macros
16805
Created On 08/03/20 05:47 AM - Last Modified 06/02/22 20:27 PM
Symptom
We observe that Excel 4.0 Macros (aka XLM Macros) are actively being used for some malicious activities. This document explains how to block those Excel files.
Resolution
In order to block the Excel files which contain Excel 4.0 Macros effectively, we have released the following Anti-Spyware signatures.
| Severity | Unique Threat ID | Name | Default Action | Minimum PAN-OS Version | First Release |
| Informational | 85935 | Possible Excel 4 Macro in Office File Detection | alert | 7.1.0 | 8288 |
| Informational | 85969 | Possible Excel 4 Macro in Office File Detection | alert | 7.1.0 | 8299 |
| Informational | 86506 | Possible Excel 4 Macro in Office File Detection | alert | 8.1.0 | 8519 |
Please note that we have released the signatures with Default Action "alert". Hence, it's necessary to change the configuration to use the signatures to block files.
Here's the example of the Anti-Spyware Profile with Action "reset-both".
For more information on how to configure Anti-Spyware exceptions, please visit this article:
How to Use Anti-Spyware, Vulnerability and Antivirus Exceptions to Block or Allow Threats
The signatures may be updated in the future. To see the latest status of the signatures, please visit our Threat Vault.
https://threatvault.paloaltonetworks.com/?query=85935&type=
https://threatvault.paloaltonetworks.com/?query=85969&type=
https://threatvault.paloaltonetworks.com/?query=86506&type=