New Attacks, Old Tricks: How OneNote Malware is Evolving
ID: fa4da82d-ba7c-5673-817e-074318c50387
STIX ID: report--fa4da82d-ba7c-5673-817e-074318c50387
Feed Name: TrustedSec blog
This report analyzes a OneNote-based malware sample that embeds HTA, WSF and VBScript artifacts which, when executed by a user, run PowerShell downloaders to fetch and execute additional payloads. The author presents static analysis of the extracted scripts and URIs, demonstrates how malicious files are hidden behind a faux UI element in OneNote, and recommends mitigations including user awareness, a Sysmon detection rule, disabling Windows Script Host, and enforcing signed PowerShell execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
