Existing customers sign in via SSO · prospects can self-provision a trial above.
Paid plans are provisioned after a quick provider review · the Starter trial activates instantly.
This permanently removes {{ delTenantName }}, revokes all member access, and stops billing. This cannot be undone.
{{ decOutput }}
On open, the workbook executes an obfuscated VBA macro that spawns powershell.exe with a hidden window, pulls a second-stage payload from a hardcoded C2, and establishes persistence via a Run key. Process injection into explorer.exe was observed, followed by periodic beaconing.
ATT&CK TECHNIQUES OBSERVEDDomain registered 2 days ago via a bulletproof registrar resolves to a host serving a pixel-perfect clone of the Microsoft OneDrive sign-in page. The form posts credentials to an attacker-controlled endpoint over the redirect chain above. Recommend immediate block at the secure web gateway and a tenant-wide phishing advisory.