Jan. 25, 2023, 5:45 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

I published the following diary on isc.sans.edu: “A First Malicious OneNote Document“:


Attackers are always trying to find new ways to deliver malware to victims. They recently started sending Microsoft OneNote files in massive phishing campaigns. OneNote files (ending the extension “.one”) are handled automatically by computers that have the Microsoft Office suite installed. Yesterday, my honeypot caught a first sample. This is a good opportunity to have a look at these files. The file, called “delivery-note.one”, was …

attackers campaigns caught computers document edu extension files find honeypot isc malicious malware microsoft microsoft office microsoft office suite microsoft onenote office onenote opportunity phishing sans sans.edu sans isc

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Senior InfoSec Manager - Risk and Compliance

@ Federal Reserve System | Remote - Virginia

Security Analyst

@ Fortra | Mexico

Incident Responder

@ Babcock | Chester, GB, CH1 6ER

Vulnerability, Access & Inclusion Lead

@ Monzo | Cardiff, London or Remote (UK)

Information Security Analyst

@ Unissant | MD, USA