MalwareBazaar Database
This page shows some basic information the YARA rule Suspicious_OneNote including corresponding malware samples.
Database Entry
| YARA Rule: | Suspicious_OneNote |
|---|---|
| Author: | marcin@ulikowski.pl |
| Description: | Detects OneNote documents with FileDataStoreObject structure containing: PE32, shortcut files (*.lnk), encoded JS, Windows Help File (*.chm), or batch script |
| Firstseen: | 2023-03-13 11:13:20 UTC |
| Lastseen: | 2024-09-02 12:01:38 UTC |
| Sightings: | 3 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|