Malware
RMOT
According to Trellix, this is a first-stage, powershell-based malware dropped via Excel/VBS.
RMOT is a PowerShell malware family operated by DarkHotel.
Background
Trellix describes this as a first-stage, PowerShell-based malware delivered through Excel/VBS. It can gain an initial foothold and exfiltrate data, and among the observed targets are hotels in Macao.
Source: Malpedia (Fraunhofer FKIE).