OneNote.EXE Execution of Malicious Embedded Scripts
Description
Detects the execution of malicious OneNote documents that contain embedded scripts. When a user clicks on a OneNote attachment and then on the malicious link inside the ".one" file, it exports and executes the malicious embedded script from specific directories.
Query · sigma
selection: ParentImage|endswith: \onenote.exe Image|endswith: - \cmd.exe - \cscript.exe - \mshta.exe - \powershell.exe - \pwsh.exe - \wscript.exe CommandLine|contains: - \exported\ - \onenoteofflinecache_files\ condition: selection
Known false positives
- Unlikely