216.73.216.226

Payload Trends in Malicious OneNote Samples

· Published 16/05/2024 17:25 · Modified 16/05/2024 19:43

Export JSON

Essential information

Published
16/05/2024 17:25
Modified
16/05/2024 19:43
Tags
2024-05-16 malicious malware onenote payload phishing shellcode
Related entities
200 observables, 13 techniques (mitre)

Description

This analysis examines the types of payloads that attackers embed within Microsoft files to deceive users into executing code. By analyzing approximately 6,000 samples, it reveals that attackers frequently employ images resembling buttons to lure victims into interacting with the files, triggering the execution of embedded payloads. The report highlights the prevalent use of scripting languages like JavaScript, PowerShell, and VBScript, as well as executable binaries, for delivering payloads. It emphasizes the significance of exercising caution when interacting with files, particularly those containing embedded objects or suspicious images.

External references