logo

Payload Trends in Malicious OneNote Samples

ID: 3ec7d6ea-fc9c-53e6-857f-476af165d1af

STIX ID: report--3ec7d6ea-fc9c-53e6-857f-476af165d1af

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-05-16

Date Updated: 2026-04-28

Author: Ashkan Hosseini and Ashutosh Chitwadgi

...
...

This Palo Alto Networks analysis examines ~6,000 malicious Microsoft OneNote samples used as phishing vehicles that embed scripts and binaries (most commonly JavaScript and PowerShell) to deliver payloads; it describes how embedded objects are identified (GUID FileDataStoreObject), payload type and size distributions, prevalence of image-based lures, and provides an EXE/shellcode case study showing dynamic API resolution and a network callback, plus IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.