The Rising Trend of OneNote Documents for Malware delivery
ID: 8a331a78-fb12-5a19-b001-591d55cf04b0
STIX ID: report--8a331a78-fb12-5a19-b001-591d55cf04b0
Feed Name: McAfee Labs Blog
Threat Score
This report analyzes malicious OneNote documents used in phishing campaigns to distribute Qakbot and other malware families. It details OneNote file structure (FileDataStoreObject), an automated extraction method for embedded artifacts, two Qakbot campaign infection chains (HTA- and batch-based droppers that download DLL payloads executed via rundll32/mshta/powershell), runtime behavior, and provides associated IOCs and a malicious domain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
