PULSE NAME
OneNote Spear-Phishing Campaign | Trustwave
WHITE jeffchandy 2023-03-10 Modified: 2023-04-09
171
IOCs
HIGH VOLUME
Trustwave SpiderLabs “noted” in Part 1 and Part 2 of our OneNote research that OneNote has been used as a malware delivery mechanism now we will shift gears and focus on several OneNote decoy notes SpiderLabs has discovered that deliver malware families like Qakbot, XWorm, Icedid, and AsyncRAT. While the malware payload can change, the techniques have generally been the same. The recent uptrend of the OneNote spear phishing campaign that SpiderLabs has observed since December 2022 has led us to additional investigations on this threat.
Indicators of Compromise (2 / 171 total)
All URL domain FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 13697ddb77c6cdfb0fba6bc2eae680b44cefd47d 2023-03-10
FileHash-SHA1 dd16fd294e7776277435bac34c4bdac60263281d 2023-03-10