OneNote.EXE Execution of Malicious Embedded Scripts

 Original Source: [Sigma source]
Title: OneNote.EXE Execution of Malicious Embedded Scripts
Status: test
Description:Detects the execution of malicious OneNote documents that contain embedded scripts. When a user clicks on a OneNote attachment and then on the malicious link inside the ".one" file, it exports and executes the malicious embedded script from specific directories.
References:
  -https://bazaar.abuse.ch/browse/tag/one/
Author: @kostastsale
Date: 2023-02-02
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1218.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\onenote.exe'
    Image|endswith:
      -'\cmd.exe'
      -'\cscript.exe'
      -'\mshta.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\wscript.exe'

    CommandLine|contains:
      -'\exported\'
      -'\onenoteofflinecache_files\'

  condition:selection
Falsepositives:
  -Unlikely
Level: high