MalwareBazaar Database

This page shows some basic information the YARA rule Suspicious_OneNote including corresponding malware samples.

Database Entry


YARA Rule:Suspicious_OneNote
Author:marcin@ulikowski.pl
Description:Detects OneNote documents with FileDataStoreObject structure containing: PE32, shortcut files (*.lnk), encoded JS, Windows Help File (*.chm), or batch script
Firstseen:2023-03-13 11:13:20 UTC
Lastseen:2024-09-02 12:01:38 UTC
Sightings:3

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter